[ 000 ] THE PROTOCOL

SecureEveryAgentAction.

Six detectors. One runtime. Claude-graded verdicts. OTONOMI inspects every agent tool-call, prompt, and MCP config for injection, secret leakage, and tool poisoning — blocking the dangerous ones before they execute. We are not a filter. We are a firewall for autonomous AI.

Protect Your Agents
POWERED BY CLAUDE SONNET 4.5///OWASP LLM TOP 10///MITRE ATLAS ALIGNED///MCP PROTOCOL INSPECTION///CLOUDFLARE WORKERS EDGE///PROMPT-INJECTION DEFENSE///POWERED BY CLAUDE SONNET 4.5///OWASP LLM TOP 10///MITRE ATLAS ALIGNED///MCP PROTOCOL INSPECTION///CLOUDFLARE WORKERS EDGE///PROMPT-INJECTION DEFENSE///
[ 001 ] / DOCTRINE
O

Guardrails are a suggestion.
This is enforcement.

Most guardrails stop at a warning. A warning is not a control.
01_THESIS

An agent’s behavior is not fixed — it shifts with every input, every tool, every retrieved document. An agent you don’t inspect at runtime is a breach accruing one tool-call at a time. OTONOMI is engineered on continuous, in-line detection.

02_METHOD

Six detectors execute in parallel against every prompt, tool-call, and MCP config. Injection, credential leaks, tool poisoning, excessive agency — graded by Claude Sonnet 4.5 with an allow/block verdict and payload-level evidence. Hard science. Hard blocking.

  • Prompt InjectionBlocked
  • Leaked SecretsRedacted
  • Rogue Tool-CallsDenied
Moise Kenge
FOUNDER & CTO · SECURITY+ · OSINT
[ 002 ] / DETECTORS

Six Detectors.
One Runtime.

Every request runs the full pipeline in parallel against the agent’s activity. Explore the terminal to view detector specifications.

DETECTOR_INDEX_OS_V2
SELECT DETECTOR01 / 06
SPECIFICATION SHEET ONLINE
DECRYPTING...
DET-01 // ACTIVE

CREDENTIAL LEAK

High-entropy regex matching against 40+ token patterns — OpenAI & Anthropic keys, AWS secrets, Stripe, database URLs — across prompts, tool-call arguments, and MCP server env blocks. Catches secrets the moment an agent tries to move them.

PATTERNS
40+ TOKENS
SURFACE
PROMPT + TOOL-CALL
LATENCY
<5ms
[ 003 ] / ARCHITECTURE

Six Layers.
Zero Friction.

ARCH-01 / DETECTION ENGINE[ 6 DETECTORS ]

THE RUNTIME

Six detectors run in parallel against every agent request. Severity grading by threat class. Zero shared state between calls. Crash-isolated so a single broken signature never takes the gateway down.

ARCH-02 / DATABASE[ POSTGRES + RLS ]

DATA LAYER

Supabase with row-level security on every table. Findings encrypted at rest. Full audit trail on every scan.

ARCH-03 / AI LAYER[ CLAUDE SONNET ]

THE VERDICT

Claude grades ambiguous payloads and writes the allow/block rationale. Streams to the console. Caches identical queries.

EXPLORE SYSTEM DIAGRAM
ARCH-07 / INSPECTION API[ <50MS EDGE ]

INLINE VERDICTS

A drop-in endpoint your agent calls before it acts. Regex-first, model-escalated, LLM-judged only when ambiguous — sub-50ms at the edge, so protection never becomes latency.

Data.
[ 004 ] / IMPACT

Benchmark coverage. Measured against the OWASP LLM Top 10 and public injection corpora.

THREATS / AGENT
0.0AVG

Average distinct threats surfaced per agent on first inspection.

FALSE POSITIVE RATE
-0%

False-positive reduction versus regex-only guardrail baselines.

BLOCKED PRE-EXECUTION
0%

Share of malicious payloads stopped before the agent acted.

[ 005 ] / GET STARTED

Three tiers.
One standard of detection.

TIER-FREE

THE WATCH

10K CALLS / MO

Drop the SDK into one agent. 10,000 inspections a month. Full 6-detector runtime with AI verdicts. Ideal for solo builders and side projects.

FREE
START FREE
TIER-TEAM // MOST POPULAR

THE STANDARD

1M CALLS / MO

Protect every agent you run. Real-time inspection on every call. Priority edge routing. Built for teams shipping AI to production.

  • Real-Time Inspection API
  • Slack + Webhook Alerts
  • Full Audit Trail + Export
$ 49 / MO
START 14-DAY TRIAL
TIER-ENTERPRISE

THE FORTRESS

ORG-WIDE

SSO, audit logs, SOC2 reports, custom detector tuning, self-hosted deployment, and a direct line to security engineering. Reserved for compliance-bound teams.

$ 499+ / MO
TALK TO US
URGENT NOTIFICATION
Founding-user program open to the first 100 teams. 63 spots remaining.
RESERVE SPOT
OTONOMI — Runtime Security for AI Agents