Introducing Zorro Security / A new perspective on AI security ↗
zorroSECURITYSign in Build with us ↗

THE ZORRO PLATFORM

One loop.
It has to close.

Four modules can be drawn. A loop has to close. Here is every link, what is actually behind it, and where it breaks today.

THE CONTEXT CHAINInteractive architecture · no customer data

Ownership · Authentication · Delegation

Who is behind the action?

Start with the person or service identity, its owner and the permissions it actually holds.

Explore this layer ↗

Platform in development. This interactive map explains the architecture; it does not represent a connected environment. Live capabilities and source coverage are reported in the workspace.

A drawing can skip a link.
A loop cannot.

A module page can describe a capability whose upstream link has no input and whose downstream link has no effector. So each link states its own status.

THE LOOP

01 ingest02 graph03 enrich04 analyze05 profile06 remediate

We own the middle. Graph, enrich and analyze are built, and the remediation lifecycle is stricter than the category’s: a model may propose, only a person approves, and closure is re-observed rather than declared. We are missing both ends. Nothing is ingested agentlessly today, and execution has exactly one effector. A loop broken at both ends does not close, so this page says where it breaks instead of drawing it shut.

01

Ingestmissing

Registry, SDK, sealed credentials, sync-run recording, tenant isolation and a fail-closed provider contract are built. The upstream API clients are not.

All ten connector kinds resolve to one stub. Without a credential it reports NOT CONNECTED; with one it reports UNAVAILABLE and makes no upstream call. The GitHub webhook and the edge are the only live inbound paths, and this is the binding constraint on everything downstream.

02

Graphreal

Event-to-graph projection, batch projector upserts, direct SQL entity reads and path queries over one workforce graph.

Only ever as populated as ingest allows. Today that is GitHub and edge telemetry.

03

Enrichpartial

Metadata-only classification that reads zero bytes of file content, AI entity classification, entitlement resolution.

Real functions over a thin graph. There is no sensitivity signal from enterprise drives, because none are ingested.

04

Analyzereal

Exposure scanning for oversharing, public links, external domains, stale shares and AI-reachable assets; identity posture detection; rollout simulation; path queries; time-based detectors on a scheduled sweep.

The engines are genuinely built, and they are answering about an under-fed graph. They say so themselves: the rollout simulator returns insufficient_data rather than safe_to_deploy when the graph is empty.

05

Profilepartial

Per-entity AI exposure profiles and identity profiles, with reach, principals and MCP surface resolved from the graph.

Profiles exist as contracts and as code. Behavioral baselines and peer comparison do not.

06

Remediatesplit

Propose, approve, execute, verify. A model may propose; a model subject can never approve. Closure is re-observed against the revocation log and checked for a newer record that re-authorized the session, and it records claimed or unverifiable rather than ever overstating verified.

One effector. Execute revokes a session and nothing else. Marking a data finding for re-observation is not revoking a share, and marking an entitlement recommendation applied is not changing an entitlement. There is no revoke-share, disable-account or kill-token effector, because there is no connector to act through.

THE ASSISTANT LAYER, OVER ALL OF IT

Investigate
REAL
ACL-scoped search over the sources the caller is allowed to read. Answers carry dated workforce-graph evidence paths, ids and timestamps, so the answer and its provenance arrive together.
Outreach
MISSING
No Slack, Teams, email or ticketing sender exists in the control plane. Slack is a connector kind and nothing more. An owner-guided one-step fix has no transport today.
Agent building
MISSING
The scheduled sweep is real and runs a fixed detector set. Nothing generates a scheduled agent from a plain-English objective, and we will not imply otherwise.
Time to risk reduction
MISSING
The metric has no implementation anywhere in the codebase. A number with no computation behind it is not a number, so the product does not render one.

From the big picture
to the detail that matters.

One investigation should keep its context as you move between an agent, a resource and a decision. Each surface names the links it serves and has its own page.

The moment that matters
is before the action.

The loop above is the workforce plane, and it runs after the fact. This is the execution plane, and it runs inside the agent loop. Four steps, one property: authority only ever goes down. The cloud is never on the path of a tool call.

01

Derive the origin sets.

Allowed hosts, packages, paths and commands are read from the repository’s committed HEAD: lockfiles, remotes, scripts. Widening them takes a commit, which is a human act.

02

Attenuate on ingress.

When untrusted content arrives, whether a PR title, a fetched page or a tool result, the session’s authority is lowered at that moment, not when a model interprets it.

03

Decide by membership.

Before a tool runs, the action’s parameters are checked against the origin sets. It is a finite membership test with no model, no score and no threshold. p50 decision latency is measured in microseconds.

04

Sign the answer.

Every allow and every denial emits evidence. A session can be sealed into a signed record of what was authorized, what ran, what it touched and where it went.

BUILT TODAY

  • Edge hook for five harnesses
  • Monotone authority ledger
  • Origin sets derived from HEAD
  • Lookalike detection on egress
  • MCP proxy with tool-definition pins
  • Credential broker (macOS measured)
  • Kernel sensor (Linux eBPF)
  • Signed session attestation
  • Remote revocation / kill switch
  • GitHub ingestion by webhook
  • Connector framework, no upstream clients

At the edge, what is not built is said just as plainly: the kernel view is Linux only today and the macOS and Windows collectors report UNAVAILABLE rather than guessing, the credential broker is measured on macOS, and no detection rate is claimed before a benchmark run. See the security page.

START WITH ONE QUESTION

Define your first
use case.

Pick a documented incident that matches your
risk and map it to a capability.

Build with Zorro ↗See the use cases ↓