A security product that watches AI agents has to hold itself to a harder standard: read-only observation, minimal data, scoped access, and claims that never exceed the evidence.
The PyroTrace Sensor records flow metadata — source identity, destination, bytes — at the kernel via eBPF. What was said inside the connection remains unverified by design.
PyroTrace stores reach models, flow metadata, and classification labels — not your data. Secrets are inventoried as metadata only, never read.
IAM role chains, assume-role paths, and model-layer permissions are first-class evidence, re-derived from live policy documents on every scan.
Evidence is encrypted in transit and at rest, and processed inside controlled service boundaries built for enterprise review.
Every finding links to the observations that produced it — source, timestamp, and derivation — so your team can verify our claims, not trust them.
Reach models and observed usage refresh continuously, so first-seen paths and new grants surface as they appear.
Review sensor deployment, IAM scope, data flows, retention, and evidence handling with your security team.