WEBVTT

1
00:00:00.000 --> 00:00:06.469
An A.I. agent in your organisation just
accessed your secrets. Nobody noticed.

2
00:00:06.469 --> 00:00:07.477
Nobody will.

3
00:00:07.477 --> 00:00:13.857
Your engineers ship at the speed of a
prompt. Claude Code, OpenCode, Codex,

4
00:00:13.857 --> 00:00:19.989
your own S.D.K. web apps, agents on
A.W.S. or Azure. Every one of them can

5
00:00:19.989 --> 00:00:26.618
read a secret, run a script, access tools
and data, and execute tools. The moment

6
00:00:26.618 --> 00:00:32.999
the action ends, it evaporates. Five
different runtimes, five blind spots, and

7
00:00:32.999 --> 00:00:37.059
no single record of what any of them
actually did.

8
00:00:37.059 --> 00:00:43.420
So here is what changes that. RAXE is
runtime security for your A.I. agents. It

9
00:00:43.420 --> 00:00:49.379
watches every agent across your stack.
Coding agents, S.D.K.s, gateways, the

10
00:00:49.379 --> 00:00:55.499
kernel execution of agents itself. It
records what each one actually did, and

11
00:00:55.499 --> 00:01:00.975
seals it as provable evidence. Here is
what that means for your team.

12
00:01:00.975 --> 00:01:07.220
Start with your SOC analyst. Instead
of five dashboards, one central console.

13
00:01:07.220 --> 00:01:12.754
And it opens on the honest headline.
Final block, zero. Would-block, is

14
00:01:12.754 --> 00:01:18.999
counted right beside it. Because RAXE
runs in observe and log mode today, and

15
00:01:18.999 --> 00:01:25.244
never breaks your agents or interferes.
Every surface lands in one triage queue,

16
00:01:25.244 --> 00:01:31.410
and when a threat fires, your analyst
sees the exact rule that caught it. Not a

17
00:01:31.410 --> 00:01:32.833
black-box score.

18
00:01:32.833 --> 00:01:39.122
For the platform owner, the blind spot
is where A.I. enters. And it is already

19
00:01:39.122 --> 00:01:45.008
covered. Every coding agent your
engineers run. Claude Code, OpenCode, and

20
00:01:45.008 --> 00:01:50.894
Codex. Each with its own session and
lineage. Claude Code and OpenCode tie

21
00:01:50.894 --> 00:01:56.942
back to the exact agent with explicit
attribution. Codex, we label inferred,

22
00:01:56.942 --> 00:02:03.231
because we only claim what the evidence
earns. Your A.W.S. Bedrock lane is here

23
00:02:03.231 --> 00:02:06.456
too, replayed from a labelled fixture.

24
00:02:06.456 --> 00:02:13.007
And you stop correlating by hand. One
agent's actions resolve under a single

25
00:02:13.007 --> 00:02:19.558
lineage. The gateway that saw what it
claimed. The S.D.K. inside the app. And

26
00:02:19.558 --> 00:02:26.022
the host kernel itself. All three, one
continuous story you own, end to end.

27
00:02:26.022 --> 00:02:29.815
Next, we zoom into what that kernel
caught.

28
00:02:29.815 --> 00:02:36.425
Here is the moment that matters, the one
your analyst and your CISO both need.

29
00:02:36.425 --> 00:02:42.219
The host kernel, real e.B.P.F., caught
the agent reading the /etc/passwd

30
00:02:42.219 --> 00:02:48.503
file, in-process. Something no
proxy or log would ever see, pinned to

31
00:02:48.503 --> 00:02:54.623
the exact agent. The evidence sits
sealed. You can see that it happened, not

32
00:02:54.623 --> 00:03:00.743
what. Until the analyst clicks reveal,
and the act of looking writes its own

33
00:03:00.743 --> 00:03:06.782
audit row into the audit log. Actor,
field, outcome granted, an audit ID.

34
00:03:06.782 --> 00:03:11.705
RAXE watches your agents, and it watches
its own watchers.

35
00:03:11.705 --> 00:03:17.550
For your A.I. and detection engineers,
none of this is a black box. Every

36
00:03:17.550 --> 00:03:23.636
verdict opens up. The binary threat
head's probability. The per-family heads.

37
00:03:23.636 --> 00:03:30.041
An out-of-distribution energy score. The
nearest known-attack prototypes. And for

38
00:03:30.041 --> 00:03:36.127
the borderline calls, a heavyweight
second opinion. A separate model gives an

39
00:03:36.127 --> 00:03:41.972
advisory read. Threat, or benign. It is
evidence for the analyst. It never

40
00:03:41.972 --> 00:03:45.095
changes the decision. Advisory, only.

41
00:03:45.095 --> 00:03:51.182
And for the CISO, the A.I. risk story
finally has a paper trail. Every reveal

42
00:03:51.182 --> 00:03:57.424
and every denial is hash-linked into one
tamper-evident ledger. And you can verify

43
00:03:57.424 --> 00:04:02.741
the whole chain on demand: intact.
Aligned to MITRE ATLAS and OWASP

44
00:04:02.741 --> 00:04:08.674
ASI, the A.I.-specific frameworks. Not
classical attack, which is the wrong

45
00:04:08.674 --> 00:04:14.530
frame for agent threats. This is not a
screenshot someone could doctor. It is

46
00:04:14.530 --> 00:04:19.693
board-grade, audit-ready evidence you can
hand up with confidence.

47
00:04:19.693 --> 00:04:25.606
RAXE gives you the true, sealed,
provable story of everything your A.I.

48
00:04:25.606 --> 00:04:31.930
agents did. Across every agent, in one
place. Today, it lets you see it. Next,

49
00:04:31.930 --> 00:04:38.418
it lets you stop it. We watch everything
now, so you can enforce with confidence

50
00:04:38.418 --> 00:04:42.031
later. Trust starts with the truth.
