# RAXE > Runtime detection & evidence for AI agents. Self-hosted visibility across coding agents, > SDKs, gateways, cloud and kernel activity – recorded, sealed as evidence, and verifiable > on demand. Early access (design partner programme). # Last updated: 2026-07-09 ## What RAXE is RAXE records what AI agents actually do – not just what they report. It correlates three views of every agent action into one timeline: what the agent claimed at the RAXE Gateway, what the application saw through the RAXE Sensor SDK, and what the host sensor observed at the kernel (eBPF). Sensitive evidence is sealed by default; revealing it writes its own audit row; the whole evidence ledger is hash-chained and can be verified on demand. RAXE deploys observe-first (observe-and-log). It detects and flags threats with full evidence today; blocking/enforcement is the roadmap, not a shipped capability. Deployment is self-hosted and single-tenant, in the customer's own environment (VPC or on-premises). The product is in early access via a design partner programme. ## Key capabilities (validated) - Kernel-level eBPF host sensor: catches in-process file and secret access (e.g. an agent reading /etc/passwd) that proxies and log files cannot see, pinned to the exact agent session. - One console (RAXE Lineage Lens) for every agent surface: coding agents, in-app SDK calls, gateway LLM traffic, and AWS cloud activity – one triage queue. - Coding-agent coverage: watches Claude Code and OpenCode live with explicit session attribution; Codex sessions supported via ingest with attribution labelled inferred. - AWS lane: live CloudTrail detection of agent activity (e.g. an agent role reading a secret flagged as data exfiltration); AgentCore telemetry. Demo environments use clearly-labelled sample data. - Detection stack (five signals): MITRE ATLAS + OWASP ASI-mapped rules; an ML text scorer; structured tool-call risk analysis (SQL injection, shell injection, path traversal in tool arguments); an agent behaviour graph; and an optional advisory LLM judge (a second opinion that never changes the decision). - Explainable verdicts: threat probability, per-family scores, out-of-distribution signal, nearest known attack patterns. - Evidence integrity: sealed-by-default evidence, audited reveal, tamper-evident hash-chained audit ledger with on-demand verification ("Intact"). - Latency: fast rules answer in single-digit milliseconds; the full multi-signal verdict in roughly 150 ms – all local. - Taxonomy: 13 threat families, 41 techniques, 10 harm types, mapped to MITRE ATLAS and OWASP ASI (Agentic Security Initiative). ## What RAXE does not do (yet) - No blocking/enforcement in production today: RAXE runs observe-and-log; would-block decisions are logged with evidence. Enforcement is on the roadmap. - Single-tenant only (no multi-tenant deployment). - Kubernetes DaemonSet/sidecar deployment is roadmap; validated paths are Docker Compose, systemd host sensor, and the Python SDK. - SOC 2 Type II: programme in progress; RAXE does not claim a completed audit. ## Links - Website: https://raxe.ai - Product Overview: https://raxe.ai/platform - Product Walkthrough (4-min video): https://raxe.ai/platform/walkthrough - Deploy (observe-first install path): https://raxe.ai/deploy - RAXE Gateway: https://raxe.ai/gateway - RAXE Sensor: https://raxe.ai/sensor - RAXE Intelligence: https://raxe.ai/intelligence - Integrations: https://raxe.ai/integrations - Solutions: https://raxe.ai/solutions - How RAXE Compares: https://raxe.ai/compare - Trust & Evidence: https://raxe.ai/trust - Enterprise: https://raxe.ai/enterprise - Pricing (early access): https://raxe.ai/pricing - Developers: https://raxe.ai/developers - Browser Detection Lab (browser-only classifier demo): https://raxe.ai/live-demo - RAXE Labs (research): https://raxe.ai/labs - Threat Intelligence reports: https://raxe.ai/labs/threat-intelligence - Security Advisories: https://raxe.ai/labs/advisories - Research Radar: https://raxe.ai/labs/radar - Cold Validation: https://raxe.ai/labs/cold-validation - Advisory Services: https://raxe.ai/services - Documentation: https://docs.raxe.ai - GitHub: https://github.com/raxe-ai/raxe-ce ## Contact - Book a 30-minute walkthrough: https://calendar.app.google/tpt3UKF3L2yQ53eX8 - Talk to an engineer: https://raxe.ai/contact