RAXE vs alternatives

How RAXE compares –
and what we don't do yet.

RAXE is runtime detection & evidence for AI agents. Most tools in this space watch one surface: the prompt, the proxy, the log stream, or the cloud control plane. RAXE records what agents actually do – gateway claims, SDK events, cloud activity, kernel-observed file access – and seals it as evidence you can verify. Below: four honest comparisons, no checkmark matrix, and a plain list of the things we don't do yet.

Gateway Claim Kernel Reality Verify: Intact
Comparison 01

RAXE vs prompt firewalls

Prompt firewalls inspect text at one choke point. Useful – but agents do more than talk. They run tools, touch files, and call cloud APIs, and none of that shows up in the prompt.

Dimension
Prompt firewalls
RAXE
What it sees
Prompt and response text at a single inspection point.
Gateway claims, SDK tool calls, AWS cloud activity, and kernel-observed file access – one continuous timeline per agent session.
The say/do gap
Trusts the text. If the agent says it read the README, that is the record.
Puts the gateway claim next to kernel reality: the agent said README; the kernel recorded /etc/passwd.
Tool calls
Visible only where they surface in prompt text.
Inspects tool-call arguments directly, detecting injection attacks, credential leakage, and path traversal.
Evidence
Logs; retention and integrity vary by vendor.
Sealed-by-default evidence, audited reveal, and a hash-chained ledger – verify the whole chain on demand → Intact.
When a prompt firewall is enough: a single chat endpoint, no tools, no file or cloud access. RAXE starts to matter the day your agents get hands.
Comparison 02

RAXE vs LLM gateways

LLM gateways route, meter, and rate-limit traffic. That is a different job – and a traffic-only view can never tell you what happened on the host after the response arrived.

Dimension
LLM gateways
RAXE
The job
Route and govern LLM traffic: keys, quotas, failover, cost.
Detect and evidence what agents actually do, across every surface they touch.
Coverage
Traffic that passes through the proxy. Anything local to the host is invisible.
Cross-source lineage: what the agent claimed at the gateway, what the app saw through the SDK, what the host sensor observed at the kernel.
Detection
Varies; often policy routing and keyword filters.
Five named signals: ATLAS + ASI-mapped rules, an ML text scorer, structured tool-call risk analysis, an agent behaviour graph, and an optional advisory LLM judge.
Latency, honestly
Adds a network hop to every call.
Fast rules answer in single-digit milliseconds; the full multi-signal verdict in ~150 ms – all local.
Keep your gateway. RAXE is not a router. It reads the traffic story alongside the kernel story – the two compose rather than compete.
Comparison 03

RAXE vs SIEM-only logging

Your logs show what agents report about themselves. That is self-testimony, not observation – and agents under attack report exactly what the attacker wants them to.

Dimension
SIEM-only logging
RAXE
Source of truth
What applications and agents self-report to the log stream.
What the gateway, SDK, cloud trail, and kernel independently observed.
Agent attribution
Generic host and app telemetry; no agent-session concept.
Pinned to the exact agent session: Claude Code and OpenCode watched live with EXPLICIT attribution; Codex via ingest, honestly labelled INFERRED.
Verdicts
Raw events; you write and maintain the correlation rules.
Explainable verdicts out of the box: threat probability, per-family scores, out-of-distribution signal, nearest known attack patterns.
Tamper evidence
Depends on your pipeline configuration.
Hash-chained audit ledger by default; verify the whole chain on demand → Intact.
Keep the SIEM. RAXE adds agent-native evidence next to it; it does not replace your log pipeline.
Comparison 04

RAXE vs cloud-posture tools (GuardDuty & CSPM)

Posture tools grade your cloud configuration and flag control-plane anomalies. Different job: your agents assume IAM roles, read secrets, and call AWS services at runtime, under identities your SOC rarely watches – and posture tools have no concept of an agent session.

Dimension
GuardDuty & CSPM
RAXE
The job
Posture: score configurations and detect account-level anomalies.
Runtime: detect agent activity as it lands in CloudTrail – and put it on the same timeline as gateway claims and kernel-observed file access.
What it sees
Control-plane anomalies and misconfigurations; no concept of an agent session.
Live CloudTrail detection of agent activity: an agent role reading a secret becomes a data-exfiltration alert in the console, correlated to the agent session.
Where it runs
Managed service in the provider's plane.
Self-hosted in your environment, watching your own AWS accounts – your CloudTrail never routes through RAXE.
Attribution, honestly
Account- and resource-level findings.
Findings are correlated to agent sessions and labelled as correlation, not exact attribution. Early access – design partner programme; demo views use clearly-labelled sample data. How the AWS lane works →
Keep GuardDuty. RAXE adds the agent-session lens next to it – runtime agent activity, not account posture.
The other half of the page

What RAXE does not do yet

The part most vendor pages leave out. If any of these is a hard requirement today, we would rather you know now than after a proof of concept.

Capability
Status today
Where it's going
Stopping a malicious action in-line
Not yet. RAXE deploys observe-and-log: every would-block decision is recorded with the evidence behind it.
Today it lets you see it. Next, it lets you stop it.
Codex live hooks
Not yet. Codex sessions arrive via ingest, and attribution is labelled INFERRED – we do not pretend otherwise.
Claude Code and OpenCode are watched live with EXPLICIT attribution today.
Kubernetes packaging
Not yet. Validated deployment paths today: Docker Compose, systemd, and the Python SDK.
K8s DaemonSet / sidecar packaging is on the roadmap.
Multi-tenant deployments
Not supported. One RAXE deployment serves one organisation, self-hosted in your environment.
Tell us about your topology – it shapes the roadmap.
Exact AWS attribution
CloudTrail detection correlates cloud activity to agent sessions – correlation, not exact attribution. Demos use clearly-labelled sample data.
AgentCore telemetry deepens the correlation.
A completed SOC 2 Type II audit
In progress. We do not claim a completed SOC 2 Type II audit.
Early access – design partner programme

See the say/do gap on your own agents.

Bring your own agents – we'll show you what they're actually doing, live on your stack, in a 30-minute walkthrough.

See how it deploys → · Talk to an Engineer →