Six detectors. One runtime. Claude-graded verdicts. OTONOMI inspects every agent tool-call, prompt, and MCP config for injection, secret leakage, and tool poisoning — blocking the dangerous ones before they execute. We are not a filter. We are a firewall for autonomous AI.
An agent’s behavior is not fixed — it shifts with every input, every tool, every retrieved document. An agent you don’t inspect at runtime is a breach accruing one tool-call at a time. OTONOMI is engineered on continuous, in-line detection.
Six detectors execute in parallel against every prompt, tool-call, and MCP config. Injection, credential leaks, tool poisoning, excessive agency — graded by Claude Sonnet 4.5 with an allow/block verdict and payload-level evidence. Hard science. Hard blocking.
Every request runs the full pipeline in parallel against the agent’s activity. Explore the terminal to view detector specifications.
High-entropy regex matching against 40+ token patterns — OpenAI & Anthropic keys, AWS secrets, Stripe, database URLs — across prompts, tool-call arguments, and MCP server env blocks. Catches secrets the moment an agent tries to move them.
Six detectors run in parallel against every agent request. Severity grading by threat class. Zero shared state between calls. Crash-isolated so a single broken signature never takes the gateway down.
Supabase with row-level security on every table. Findings encrypted at rest. Full audit trail on every scan.
Claude grades ambiguous payloads and writes the allow/block rationale. Streams to the console. Caches identical queries.
A drop-in endpoint your agent calls before it acts. Regex-first, model-escalated, LLM-judged only when ambiguous — sub-50ms at the edge, so protection never becomes latency.
Average distinct threats surfaced per agent on first inspection.
False-positive reduction versus regex-only guardrail baselines.
Share of malicious payloads stopped before the agent acted.
Drop the SDK into one agent. 10,000 inspections a month. Full 6-detector runtime with AI verdicts. Ideal for solo builders and side projects.
Protect every agent you run. Real-time inspection on every call. Priority edge routing. Built for teams shipping AI to production.
SSO, audit logs, SOC2 reports, custom detector tuning, self-hosted deployment, and a direct line to security engineering. Reserved for compliance-bound teams.