Introducing Zorro Security / A new perspective on AI security ↗
zorroSECURITYSign in Build with us ↗

SECURITY

The decision,
before the action.

Zorro is an execution governance layer for AI agents. It does not scan content and report a score. It decides, at the moment an agent acts, whether the source that caused the action had the authority to cause it, and signs the answer.

Authority, not attribution.
Membership, not a score.

Causality inside a transformer is not observable from outside it, so Zorro never asks which context item caused an action. It asks a decidable question: is this action’s parameter a member of a finite, human-authored set?

THE QUESTION

What authority does this action require, and does the session still hold it?

A denial and every allow emit evidence with real provenance. An unlogged allow is an unauditable allow.

THE PROPERTY

Monotone. Authority only goes down.

Untrusted content attenuates the session the moment it arrives, not when a model reads it. Encoding, obfuscation and paraphrasing change nothing, because the attenuation already happened. Nothing in the context can raise authority back; only a human grant can.

THE TEST

Every clause is a finite check.

Capability in grant · not expired · pins intact · parameters within origins. No scanning, no matching, no model. O(grants × parameters), both small. p50 latency in microseconds, p99 in milliseconds.

CAPABILITIES

ReadWorkspaceWriteWorkspaceCodeExecutionNetworkEgressReadSecretInstallPackageModifyAgentConfig

ModifyAgentConfig is the meta-capability: writes to the agent’s own control surface. It is always-human and can never be inside a grant. CVE-2025-53773, CVE-2025-59536 and CVE-2026-48124 are all this capability.

What the guarantee
does not cover.

Said plainly so an unqualified soundness claim does not die in diligence.

One decision at the edge.
Layers beneath and above it.

The real-time decision happens only at the edge. The cloud is never on the path of a tool call; if it is down, enforcement continues.

00

The hook

Decides every tool call across five harnesses, with p50 latency in microseconds and no network on the hot path.

01

The kernel sensor

Sees the subprocesses a hook cannot, like the postinstall that opens a socket, and attributes them to the agent session. Linux only today; the macOS and Windows collectors report UNAVAILABLE rather than guessing.

02

The MCP proxy

Pins every tool definition before it is forwarded, closing tool poisoning and grant rug-pulls.

03

The credential broker

Keeps raw secrets out of the agent’s environment behind ephemeral, scoped tokens.

04

Signed proof

Seals each session into a DSSE / in-toto attestation: agent, model, MCP inventory, findings. Unobserved fields read UNAVAILABLE.

05

The control plane

Attack-path graph, detectors that may only lower authority, and remediation that a person approves.

What holds up, and
what we refuse to invent.

The full accounting. Unmeasured is UNAVAILABLE, never zero. The two largest entries are structural rather than statistical: nothing is ingested agentlessly at the front of the loop, and execution has exactly one effector at the back. See the loop, link by link ↗

MEASURED

Decision latency
111–640 µs p50
p99 in milliseconds, machine-load dependent. Produced by caveat-bench on recorded sessions.
Comment and Control replay
7 of 7 refused
CVSS 9.4 attack class: 7 of 7 exfiltration steps refused, 5 of 5 legitimate review steps allowed. demo_comment_and_control.sh.
Credential broker
0 of 9 leaked
0 of 9 leak vectors succeeded under the broker vs 6 of 8 without it; 4 of 4 legitimate API calls forwarded. Measured on macOS (demo_credential_broker.sh).
Code quality gate
0 issues
cargo clippy -D warnings clean, golangci-lint 0 issues, demos pass against real binaries.

NOT MEASURED / NOT CONNECTED

ADR-Bench / AgentDojo
Not measured. The replay harness and ASR/utility calculation exist; no corpus has been run, so no detection or prevention rate is claimed.
Prompts per session
Not at target. 36.66 mean / 25 p50 on a frozen transcript set, against a target of ≤ 2. The active engineering priority.
Agentless ingestion
Not connected, and it is the front of the loop. The connector framework is real — registry, SDK, credential sealing, sync-run recording, tenant isolation — but no upstream API client is written, so nothing is read from an identity provider, a drive or a SaaS application today. Without a credential a connector reports NOT CONNECTED; with one it reports UNAVAILABLE and makes no upstream call. The only live enterprise ingestion is GitHub, by webhook. Every engine downstream is as populated as this link allows, which is why the rollout simulator answers insufficient_data rather than safe_to_deploy on an empty graph.
Remediation effectors
One, and it is the back of the loop. The lifecycle is real and stricter than the category’s: a model may propose, a model subject can never approve, execution is separate, and closure is re-observed against the revocation log, checked for a newer record that re-authorized the session, and recorded as claimed or unverifiable rather than ever overstated as verified. But execution revokes a session and nothing else. Marking a data finding for re-observation is not revoking a share; marking an entitlement recommendation applied is not changing an entitlement. There is no revoke-share, disable-account or kill-token effector, because there is no connector to act through. We close one action with proof where the category closes many without.
Outreach and workflow
Not built. No Slack, Teams, email or ticketing sender exists in the control plane; Slack appears as a connector kind and nothing more. An owner-guided one-step fix has no transport today.
Time to risk reduction
Not computed. The metric has no implementation anywhere in the codebase, so no surface renders one. A number with nothing behind it is not a number.
Kernel sensor
Linux only today (Aya / eBPF / BPF-LSM), and it is the only collector delivering a kernel view. The macOS Endpoint Security crate exists but cannot start without the Apple-granted entitlement, TCC approval and root; without them it prints endpoint security UNAVAILABLE rather than claiming an observation. The Windows ETW crate reads the KernelProcess session and parses each record header; full exec and file-open extraction waits on a Windows host verifying the provider schemas. Three-platform sensor coverage does not ship.
Credential broker on Linux
Untested. Measured only on macOS; /proc/<pid>/environ handling exists in code.
Sandbox conclave
Not demonstrated end-to-end; the command exists and reports UNAVAILABLE without Docker.
SOC 2 Type II / ISO 42001
A blueprint, not an audit. The observation window is 3–6 months and cannot be accelerated.

Four kinds of product.
One place the decision can live.

This is our dated review of the competitive landscape, sourced in the strategy documents. “Lacks X” is a positioning hypothesis, not a categorical claim; the incumbents do their jobs well.

Identity & data graph, agentless

Veza, Cyera

IdP, drives and SaaS metadata · after the fact

Their breadth of agentless enterprise ingestion is real, and we do not have it today. What it does not do is decide inside the agent loop. Mapping who holds what is not the same as deciding, at the moment an agent acts, whether the source that caused the action had the authority to cause it.

Detection over agent telemetry

Uber ADR, Norton AI Agent Protection

transcripts, hook logs, rules · after, or on a score

Detection is close to solved; blocking before the action is not. ADR reports 67% detection at zero false positives on ADR-Bench, after the fact.

Registry & supply-chain gates

JFrog, Snyk

what enters the machine · before install, not in the loop

A registry gate sees the package, not the injected instruction that later makes the agent run the wrong command.

Server-side sandboxes

Kosmoy Action Capsule, Cisco DefenseClaw

containment of a running agent · beside the agent

Isolation is real and valuable. It runs beside the agent, not inside its loop, and it has no instruction provenance or signed record of the loop itself.

THE MARKET IS CONSOLIDATING ON THE LAYER

Incumbents spent the year buying the runtime and containment point: Palo Alto (Protect AI, ~$634.5M secondary; Koi, $231M primary), Cisco (Robust Intelligence; Astrix, ~$400M secondary), Check Point (Lakera), Proofpoint (Acuvity), SentinelOne (Prompt, $250M primary). The market map itself names three gaps no vendor has filled.

THREE GAPS, ATTRIBUTED TO THE MARKET MAP (2026-04-05, SECONDARY)

An agent behavioral baseline

Derived, not learned. “Normal” is decidable from the committed HEAD: lockfiles, remotes, scripts. Anything outside the derived origin sets asks. No training data, no score to tune.

Cross-layer correlation

A byproduct, not a product. One identifier spans identity → MCP pins → hook and kernel → signed policy → attestation, because the enforcement point is the observation point.

Agent-to-agent trust

The primitive is built. Inter-agent Ed25519 verification exists as a library (not yet wired into the live hook path) and the MCP proxy pins every tool definition. The same primitive extends to an agent-to-agent protocol.

Sources and access dates are in the strategy’s market evidence file. This page states positioning, not measured rates.

EVIDENCE AT THE CORE

Trust what you
can verify.

Ask us for the command that produced any number above. If a number isn’t here, it hasn’t been measured.

Talk about a pilot ↗