One record of what your AI agents actually do.
Gateway claims, SDK events, cloud activity, kernel-observed file access – one sealed record per agent session, from the promise in the reply to the syscall on the host. The flight recorder for your AI agents.
What the agent said. What the kernel saw.
Every agent action leaves up to three accounts of itself: the claim in the model's reply, the tool call your application executed, and the syscall the kernel actually served. Most teams only ever see the first one.
RAXE records all three and lines them up on one timeline per agent session. When the accounts disagree, that gap is your finding – with the evidence already attached.
See it. Catch it. Prove it.
Three jobs, one pipeline: record every surface your agents act on, judge each event with five named signals, and seal the result as evidence that survives an audit.
One console for every agent surface.
RAXE Lineage Lens – the RAXE console – gives you one triage queue across all four surfaces. No tab-hopping between a proxy log, an app log, and a cloud console to reconstruct what one session did.
Coding agents
Claude Code and OpenCode watched live on developer machines; Codex sessions via ingest.
In-app SDK
Your application through RAXE Sensor [sdk] – every tool call your app executed.
Gateway LLM traffic
Requests and replies through one proxy – the agent's claims, recorded as claims.
AWS cloud activity
Live CloudTrail detection plus AgentCore telemetry – correlated to agent sessions, not exact attribution.
Pinned to the session
What the agent claimed at RAXE Gateway. What your application saw through RAXE
Sensor [sdk]. What the host sensor observed at the kernel. One
continuous timeline per agent session, with every recorded event linked to the
exact session that produced it – so when something needs explaining, you
start from the session, not from a grep across timestamps.
Five signals. One explainable verdict.
Detection here is not one model's opinion. Five named signals score every event, and the verdict shows its working: threat probability, per-family scores, an out-of-distribution signal, and the nearest known attack patterns. Fast rules answer in single-digit milliseconds; the full multi-signal verdict lands in ~150 ms – all local.
The kernel doesn't take the agent's word for it
A kernel-level eBPF host sensor catches in-process file and secret access –
an agent reading /etc/passwd, for example – activity that is
invisible to proxies and logs, pinned to the exact agent session.
ATLAS + ASI-mapped rules
Open, auditable detection signatures, every one mapped to MITRE ATLAS and OWASP ASI (the Agentic Security Initiative).
ML text scorer
Scores prompts and responses across the full taxonomy – running locally, inside your boundary.
Structured tool-call risk analysis
Inspects tool-call arguments, detecting injection attacks – SQL injection, shell injection, path traversal – and credential leakage inside the parameters agents pass to tools.
Agent behaviour graph
Connects a session's events into one behaviour graph, so the verdict reflects the pattern of the whole session – not a single message in isolation.
Advisory LLM judge (opt-in)
A heavyweight second opinion on borderline text. Evidence, never authority – it never changes the decision, and it is off unless you turn it on.
Evidence that survives the audit.
Detection you can't defend is just an opinion. Everything RAXE records is sealed by default, revealed only on purpose, and chained so tampering shows.
Sealed by default
Sensitive fields stay sealed until an analyst supplies a purpose and clicks Reveal. The reveal writes its own audit row – actor, field, outcome – so looking at the evidence is itself on the record.
Tamper-evident audit ledger
Every audit row carries the hash of the row before it. Rewrite history anywhere in the chain and the break is visible everywhere after it.
Verify on demand
One action walks the entire chain and returns a verdict: Intact. That is the word you hand to an auditor.
The most privileged agents you run sit on developer machines.
Coding agents read your source, hold your credentials, and shell out with your permissions. RAXE watches them where they run – and tells you exactly how confident it is about who did what.
Claude Code
Watched live. Every event carries EXPLICIT session attribution – the record proves which session did it.
OpenCode
Watched live with EXPLICIT session attribution, the same way – one plugin, the same timeline, the same console.
Codex
Sessions arrive via ingest, and attribution is honestly labelled INFERRED. We don't claim a live hook we don't have.
The attribution label is part of the evidence. If RAXE can't prove which session did something, the record says so – plainly.
Your agents don't stop at the laptop. Neither does the record.
Which agent role read that secret? CloudTrail knows. Now you do. Your agents assume IAM roles, read secrets and call AWS services under identities your SOC rarely watches. RAXE reads your live CloudTrail and raises detections as agent activity lands – an agent role reading a secret becomes a data-exfiltration alert in the console, on the same timeline as gateway claims and kernel-observed file access. Bedrock AgentCore telemetry joins that timeline too.
- Self-hosted in your environment, watching your own AWS accounts – no vendor cloud receives your CloudTrail
- Correlation, not exact attribution
- Demo views use clearly-labelled sample data
- Early access – design partner programme
Self-hosted. Observe-first. Your boundary.
Runs in your environment
Self-hosted in your VPC or on-prem. Prompts and detections stay inside your boundary – there is no vendor scanning cloud.† That includes cloud coverage: the collector reads CloudTrail from inside your environment, watching your own AWS accounts.
Validated paths
Docker Compose and systemd deployments, plus a Python SDK for in-app coverage – validated end-to-end on fresh deploys. Kubernetes DaemonSet and sidecar are on the roadmap.
Observe-first rollout
RAXE deploys observing and logging. Every would-block decision is logged with the evidence to back it, so you see exactly what a stricter posture would have done. Today it lets you see it. Next, it lets you stop it.
† Operational metadata telemetry is documented on the trust page.
Every layer has its own page.
RAXE Gateway
The claim layer. LLM traffic through one proxy – requests scored, agent claims recorded and linked to the session.
Explore the gateway → ProductRAXE Sensor
Kernel reality. The eBPF host sensor and the in-app SDK – what agents actually touch, pinned to the session.
Explore the sensor → DetectionDetection intelligence
The five-signal stack, the full threat taxonomy, and open signatures mapped to ATLAS + ASI.
Explore detection → CoverageIntegrations
Claude Code, OpenCode, Codex ingest, LLM providers and AWS – where RAXE meets the stack you already run.
See integrations → Use casesSolutions
The say/do gap by scenario – coding agents, in-app assistants, and cloud-side agent activity.
See solutions → BuildDevelopers
The Python SDK, quickstarts, and the fastest route from install to your first recorded agent session.
Start building → CloudAgents on AWS
Live CloudTrail detection of agent activity, plus AgentCore telemetry – watched from inside your own account. Correlation, not exact attribution.
See agents on AWS → Watch4-min walkthrough
One agent session, end to end: the claim, the catch, the audited reveal, and the chain verified Intact.
Watch it →See what your agents actually do.
Thirty minutes, live on a real deployment: the timeline, the catch, the reveal, and the chain verified Intact.