PyroTrace logo
PyroTraceA product of Pyro Security
ProductSecurityAboutGet a demo
PyroTrace logoPyroTrace

PyroTrace independently verifies what your production AI agents can reach, what they actually touch, and which of it is sensitive.

Product
PlatformData ReachAgent MapChangelog
Compliance
SecurityGDPR
Company
AboutContactDocsStatus
Legal
LegalPrivacyTermsCookies

© 2026 Pyro Security, Inc. All rights reserved.

The Evidence Layer for Agentic AI

Independently verify — and then reduce — the effective access and sensitive-data reach of every AI agent and MCP server you run.

Get a demo→How it works
Reach
What each agent is granted
Used
What it demonstrably touched
Sensitive
What it should never reach
DashboardLive posture
AI Security Score
72
2 agents flagged
1 shadow MCP server
Resource-Reach Utilization
6.4%
3 of 47 reachable touched
Sensitive Reach
1
PII-classified, observed
Unused Grants
118
never used in any observed run
Inventory Coverage
92%
agents with evidence backing

Posture you can defend, in six numbers.

Every metric traces back to evidence — what was granted, what was observed, and what the data classification says about it.

AI Security Score

One posture number for your agent fleet, derived from reach, usage, and sensitivity — not from alert volume.

Resource-Reach Utilization

The share of modeled reachable resources each agent actually touched. Low utilization marks least-privilege candidates.

Sensitive Reach

Resources holding PII, PHI, or payment data that an agent can reach — flagged before anything touches them.

Shadow Access & Egress

Observed activity outside the modeled reach set, including external endpoints no policy predicted.

Unused Grants

Permissions no observed run has exercised, prioritized for least-privilege review.

Inventory Coverage

How much of your agent fleet is evidence-backed, so you know what the numbers do and don't cover.

Run starts
orchestrator prompt received
Gateway
MCP tool call
payments-tools · get_customer()
MCP gateway
AWS API call
s3:GetObject · orders-prod
CloudTrail
Resource touched
2.1 MB egress · PII-classified
Sensor

Every edge states how it was derived.

Every agent, every MCP server, and the identity behind it.

Agents are discovered and ranked by risk with the non-human identity behind each one. Inventory entries are admitted on an evidence ladder — registry facts, structural facts, operator declarations, observed behavior. A name is never evidence.

Open any observed run as a Run Story: the causal chain from prompt to tool call to cloud API to resource touched — orchestrator-to-subagent delegation, denied reads, and credential hops included.

The flagship question: what can it reach, and what did it use?

Agent Resource-Reach Utilization is the share of reachable resources an agent actually touched. Low utilization with high sensitive reach identifies a practical least-privilege opportunity: review access with no observed use.

One click exports the per-agent evidence — reach, usage, and sensitivity — in the shape your auditor asked for.

PII
47
Reachable · granted
3
Touched · observed
1
Sensitive · classified

Your agent fleet, as a live map.

Agent-rooted, metro-map edges, semantic color: green is observed normal, yellow is first-seen, red is risky, blue is internet egress. Only sensor-observed traffic animates.

checkout-agentrole/agent-checkoutsupport-agentrole/agent-supportmcp-gatewaypayments-toolss3://orders-prodrds/customerssecrets/paymentsPIIbedrock/claudeapi.vendor.io+41
ObservedFirst-seenRiskyInternetGranted, unused

Findings that speak your auditor’s language.

Issues are derived from the reach-and-usage join — not from signatures — and each carries its framework mapping and evidence.

OWASP LLM Top 10

Excessive agency and insecure tool integrations, grounded in observed reach

MITRE ATLAS

Agent-relevant techniques mapped to the evidence that triggered them

NIST AI RMF

Measure and Manage functions backed by exportable, evidence-linked reports

Built around the same evidence graph.

Intelligence Map

An AI-rooted graph: pick an agent or MCP server and see who can access it, its open issues, and everything within its reach.

Detections

Changes worth attention — first-seen paths, shared credentials, unauthenticated MCP servers — each with evidence.

Identities

The non-human identities behind every agent, plus the workforce principals who can assume them.

Health

Sensor, collector, and integration health, so you always know how fresh your evidence is.

PyroTrace Sensorkernel · eBPFAWS CloudTrailcontrol planeMCP gatewaytool callsLLM telemetryOTel GenAI · sidecarSIEM importSplunk · SentinelEDRhost activityEvidenceledger

AWS today. Observed from the kernel.

The PyroTrace Sensor observes workload traffic at the kernel (eBPF, read-only). CloudTrail, MCP gateway, LLM telemetry, SIEM, and EDR imports corroborate it. Reach is modeled from live IAM policy — including the model layer: who can invoke, fine-tune, or read artifacts from Bedrock and SageMaker models.

Claims stay evidence-bounded: we record that agent-attributed traffic reached a classified resource, with bytes out. Payload content remains unverified, by design.

See your agents' real reach.

A guided walkthrough of the agent inventory, Data Reach, Agent Map, and the evidence behind each exposure finding.

Get a demo →Security & trust