2026 Futuriom 50: Highlights →Explore

Early Access
Shadow AI Discovery · Now Available
Network-Native AI Security · Built for Security Teams

AgentGuard

Network-native AI security.
Built for security teams.

Every other AI security tool requires your application team to adopt something before you can enforce anything. AgentGuard is different. It operates transparently at the network layer — enforcing policy at the VPC boundary where every AI interaction traverses, with no SDK, no proxy configuration, and no developer compliance required.

Blast radius is determined by architecture — not by how fast you detect. Security teams own adoption. Day one.

Design Partner Access · Not a Beta

Early access means direct access to the product team throughout your deployment.

We want to understand your environment, your specific containment requirements, and where the product falls short for your use case. What you tell us shapes what ships at GA.

A dedicated point of contact on the Aviatrix product team
A recurring check-in cadence that works for your team
Early input into the roadmap — including Deep AI Observability and Advanced AI Guardrails shipping Q3 2026

Early Access · Shadow AI Discovery

First discovery in 15 minutes.

Connect your cloud account. Aviatrix surfaces every AI agent, MCP server, and LLM endpoint in your environment — including shadow AI your application team doesn't know about.

144:1
Machine-to-human identity ratio
$670K
Avg shadow AI breach premium

No spam. Reviewed within 1 business day.

Every AI workload. Sanctioned or not.

Network-native discovery sees shadow AI that code-based tools miss entirely

Blast radius bounded by architecture

A compromised agent reaches only what it was explicitly permitted to reach

Security teams deploy this. Not developers.

No application changes, no SDK, no developer compliance required

One fabric from discovery to guardrails

Every capability runs on the Aviatrix platform you already operate

Four Capabilities · Progressive Adoption

Start where you are.
Advance when ready.

Shadow AI Discovery is in early access. Network Enforcement is available today via Zero Trust for AI Workloads. Deep AI Observability and Advanced AI Guardrails ship Q3 2026. Each capability delivers standalone value on the same Aviatrix fabric — no rip-and-replace, no new infrastructure.

I
Early Access Now
Shadow AI Discovery

Find every AI workload. In 15 minutes.

Network flow + DNS + Cloud Asset Inventory. No gateway, no SDK, no code changes.

Connect a cloud account. Aviatrix analyzes VPC Flow Logs, DNS logs, and Cloud Asset Inventory to surface every AI workload — including shadow AI your team doesn't know about. Every workload is risk-scored by blast radius and ready for policy targeting on the same fabric.
Time to value: Minutes
Discovers
  • AI agents across EKS/AKS/GKE pods, Lambda, Azure Functions, Cloud Run, and VMs
  • MCP servers and tools, mapped to the agents invoking them
  • LLM providers in use — OpenAI, Anthropic, Bedrock, Vertex, Cohere, Mistral, and more
  • Blast radius score per workload with guided remediation
II
Available Today
Network Enforcement

Govern the blast radius. Before the breach.

Default-deny AI egress via Zero Trust for AI Workloads. AI-aware SmartGroups. Available today.

Every workload AgentGuard discovers is immediately targetable via Zero Trust for AI Workloads on the same fabric. AI-aware SmartGroups target ai_agent resource types directly — not IP ranges. A compromised agent cannot reach a destination that was not explicitly permitted.
Core capabilities
  • Zero-trust egress for MCP servers — default-deny, destinations declared as policy-as-code
  • Managed WebGroups — allow or deny LLM provider by name, auto-updated by Aviatrix
  • URL-path scoping — differentiate github.com/acme-corp/* from github.com/* at policy level
  • Full audit trail — every AI flow logged for compliance and forensics
III
Announced · Q3 2026
Deep AI Observability & Advanced AI Guardrails

Inspect what agents say and do.

Inline protocol parsing, prompt injection blocking, DLP — transparent, no SDK. Q3 2026.

Two capabilities on the same fabric. Deep AI Observability — inline LLM protocol parsing with OTEL GenAI span export enriched with VPC and SmartGroup context. Advanced AI Guardrails — inline routing to 20+ guardrail providers. Start in async visibility mode, move to enforcement when ready.
Capabilities
  • Prompt injection on user inputs and MCP tool responses — catches indirect injection
  • DLP on tool_call arguments — PII, credentials, regulated data patterns
  • OTEL GenAI spans to Langfuse, Datadog, Splunk, or any OTEL collector
  • 20+ guardrail providers — including best-in-class AI security and content safety platforms
The Customer Journey

Find it. Route it. Govern it.

Stage 1 · Shadow AI Discovery · Early Access

See every AI workload. In 15 minutes.

Connect a cloud account. Aviatrix analyzes VPC Flow Logs, DNS logs, and Cloud Asset Inventory via the WAPA pipeline to find every workload calling every major LLM provider — plus every Bedrock Agent and Azure AI Foundry project. No gateway deployed. No code changes. No agents on hosts. AgentGuard then analyzes the inventory and tells you exactly where enforcement should go — which workloads are highest risk, which providers are unauthorized, where a gateway needs to be deployed.

144:1
Machine-to-human identity ratio — most ungoverned
$670K
Avg shadow AI breach cost premium

Shadow AI · High risk

dev-service-4

→ api.openai.com (unsanctioned)

MCP server · Overly broad

github-mcp-01

→ api.github.com + 12 others

Sanctioned · Low risk

prod-rag-pipeline

→ bedrock.aws.com only

Threat Model Coverage

The post-LLM attack surface.
Where real damage happens.

Exfiltration

Agents uploading to Dropbox, WeTransfer, Pastebin, or out-of-org S3

Blocked by AI workload URL categories and zero-trust egress policy. Default-deny prevents any unauthorized external destination.

Supply Chain

Runtime package installs from npm, PyPI, Docker Hub

URL-path scoping blocks package registries for agent workloads by default. Compromised dependencies cannot pull additional payloads.

Prompt Injection

Indirect injection via poisoned MCP tool responses

Network containment governs every path the agent can act on after injection — limiting blast radius before the alert fires. Inline prompt injection detection ships Q3 2026.

Lateral Movement

MCP servers with overly broad access to backend databases and SaaS

East-west segmentation enforces that agent SmartGroups can only connect to approved MCP server SmartGroups. Instance metadata endpoint blocked by default.

Credential Theft

AWS keys, SSH keys, JWTs encoded into outbound traffic

Network containment prevents exfiltration by blocking unauthorized egress paths entirely. DLP scanning of tool_call arguments for credential patterns ships with Advanced AI Guardrails, Q3 2026.

Shadow AI

Ungoverned agents bypassing every code-based control

Tier 1 discovery surfaces shadow AI that code-based solutions miss. Tier 2 containment enforces on every connection that traverses the network — sanctioned or not.

Ecosystem
AWS BedrockAzure AI FoundryObotLangfuseDatadogSplunkGitHub ActionsBedrock Guardrails
How AgentGuard Compares

Security teams ship this.
No developer required.

Dimension
AgentGuard
Requires Developer AdoptionSingle-Cloud, Model-Layer Only
Who owns adoption
Security team
Application teamApplication team
Deployment model
Transparent, no code changes
Requires SDK or proxy integrationSingle-cloud, per-model
Shadow AI coverage
Full visibility and enforcement
Only instrumented applicationsOnly their own service
Multi-cloud
AWS, Azure, GCP, on-prem
Framework-dependentSingle cloud
Network context
Full — IP, VPC, workload identity, L4/L7
Application context onlyLimited
Inspection points
LLM response, MCP invocation, tool traffic *
Application-layer onlyModel-layer only
Existing infrastructure
Leverages deployed Aviatrix platform
New product to deployNew product per cloud
*

LLM response inspection available today via Network Enforcement. MCP invocation and tool traffic inspection ship with Deep AI Observability and Advanced AI Guardrails, Q3 2026.

Early Access · Now Open

Blast radius bounded
by architecture.
Not detection speed.

Security teams shouldn't have to wait on developers to get compliant before they can enforce anything. AgentGuard inverts that. Deploy containment, guardrails, and deep observability on every AI workload — sanctioned or shadow — without a single code change.