
SECURITY FOR THE AI WORKFORCE
AI moves fast.
Stay one
move ahead.
Agents now work beside your people, with their permissions, against your code, data and secrets. Zorro decides each action before it runs and signs the answer, so you can prove what happened.
Risk doesn't live in silos.
Neither should security.
An agent inherits a permission. A tool reaches a file. A routine action crosses a boundary. The connection is where the story starts.
Ownership · Authentication · Delegation
Who is behind the action?
Start with the person or service identity, its owner and the permissions it actually holds.
AI & AGENTS
Know your AI
Bring agents, models and the tools they use into focus.
DATA EXPOSURE
Follow the data
Understand the access paths leading to sensitive information.
IDENTITY & ACCESS
See every identity
Connect people and machine identities to their real authority.
THREAT CENTER
Act with context
Move from a signal to its evidence and a deliberate response.
05 / THE ASSISTANT
Ask in plain language.
Read the evidence behind the answer.
The investigator answers over the sources you are allowed to read, dates what it found and shows the path through the graph that produced it. A model may propose a remediation. A person approves it. Closure is re-observed, not assumed.
Meet the assistant ↗NOT A SCANNER
Detection admits a miss rate.
Authority doesn't.
A scanner asks whether content is malicious and reports how often it is wrong. Zorro asks a different question: what authority does this action require, and does the session still hold it? Untrusted content can only narrow that authority. An injected instruction can make an agent ask more. It can never make it allow more.
How we're different ↗Monotone by construction.
Authority drops the moment untrusted content arrives, not when a model reads it. Encoding doesn't matter.
A membership test, not a score.
Allowed hosts, packages and commands come from the repository's own committed history. No threshold to tune.
Signed, so you can prove it.
Every allow and every denial emits evidence. A session can be sealed into a signed record of what ran, what it touched, and where it went.
Numbers that hold up
to a diligence call.
Three results, measured against real binaries. The fourth cell is the number we refuse to invent.
Read the full ledger ↗DECISION LATENCY
111–640 µs
p50 on recorded sessions (caveat-bench), p99 in milliseconds, machine-load dependent.
COMMENT AND CONTROL REPLAY
7 of 7
exfiltration steps refused, 5 of 5 legitimate review steps allowed.
CREDENTIAL BROKER
0 of 9
leak vectors that succeeded under the broker, vs 6 of 8 without it (measured on macOS).
BENCHMARK RATE
Unmeasured
No detection or prevention rate is claimed before it's measured on ADR-Bench and AgentDojo. The harness exists; the number doesn't yet.
Every use case starts
with a real incident.
Each scenario below is tied to a documented breach. The capability answers the pattern behind it.
All use cases ↗APPSEC · CI/CD
Your review agent
runs on every PR.
One PR title later, the runner's token is in a review comment. Keep untrusted content from becoming instruction.
Read the use case ↗SUPPLY CHAIN
An MCP server you
never vetted.
Tool descriptions and extensions are instructions the model reads and you don't. Pin definitions before they reach the agent.
Read the use case ↗ZERO-CLICK EXFILTRATION
An email. A PDF.
A calendar invite.
Objects your agents process for you are the new attack surface. Decide what each one can steer the agent to do.
Read the use case ↗BUILT FOR WHAT COMES NEXT
The next move
is yours.
Help shape security for a workforce
that's already changing.