Runtime detection & evidence for AI agents

One record of what your AI agents actually do.

Gateway claims, SDK events, cloud activity, kernel-observed file access – one sealed record per agent session, from the promise in the reply to the syscall on the host. The flight recorder for your AI agents.

Early access – design partner programme Self-hosted in your environment Audit chain verified Intact on a live deployment
The say/do gap

What the agent said. What the kernel saw.

Every agent action leaves up to three accounts of itself: the claim in the model's reply, the tool call your application executed, and the syscall the kernel actually served. Most teams only ever see the first one.

RAXE records all three and lines them up on one timeline per agent session. When the accounts disagree, that gap is your finding – with the evidence already attached.

Gateway Claim Kernel Reality Verify: Intact
The platform

See it. Catch it. Prove it.

Three jobs, one pipeline: record every surface your agents act on, judge each event with five named signals, and seal the result as evidence that survives an audit.

Act 01 · See

One console for every agent surface.

RAXE Lineage Lens – the RAXE console – gives you one triage queue across all four surfaces. No tab-hopping between a proxy log, an app log, and a cloud console to reconstruct what one session did.

Coding agents

Claude Code and OpenCode watched live on developer machines; Codex sessions via ingest.

In-app SDK

Your application through RAXE Sensor [sdk] – every tool call your app executed.

Gateway LLM traffic

Requests and replies through one proxy – the agent's claims, recorded as claims.

AWS cloud activity

Live CloudTrail detection plus AgentCore telemetry – correlated to agent sessions, not exact attribution.

Pinned to the session

What the agent claimed at RAXE Gateway. What your application saw through RAXE Sensor [sdk]. What the host sensor observed at the kernel. One continuous timeline per agent session, with every recorded event linked to the exact session that produced it – so when something needs explaining, you start from the session, not from a grep across timestamps.

Where the claim leg is recorded – explore RAXE Gateway →
Act 02 · Catch

Five signals. One explainable verdict.

Detection here is not one model's opinion. Five named signals score every event, and the verdict shows its working: threat probability, per-family scores, an out-of-distribution signal, and the nearest known attack patterns. Fast rules answer in single-digit milliseconds; the full multi-signal verdict lands in ~150 ms – all local.

13 threat families 41 techniques 10 harm types

The kernel doesn't take the agent's word for it

A kernel-level eBPF host sensor catches in-process file and secret access – an agent reading /etc/passwd, for example – activity that is invisible to proxies and logs, pinned to the exact agent session.

01

ATLAS + ASI-mapped rules

Open, auditable detection signatures, every one mapped to MITRE ATLAS and OWASP ASI (the Agentic Security Initiative).

02

ML text scorer

Scores prompts and responses across the full taxonomy – running locally, inside your boundary.

03

Structured tool-call risk analysis

Inspects tool-call arguments, detecting injection attacks – SQL injection, shell injection, path traversal – and credential leakage inside the parameters agents pass to tools.

04

Agent behaviour graph

Connects a session's events into one behaviour graph, so the verdict reflects the pattern of the whole session – not a single message in isolation.

05

Advisory LLM judge (opt-in)

A heavyweight second opinion on borderline text. Evidence, never authority – it never changes the decision, and it is off unless you turn it on.

The full detection stack, signal by signal – explore detection intelligence →
Act 03 · Prove

Evidence that survives the audit.

Detection you can't defend is just an opinion. Everything RAXE records is sealed by default, revealed only on purpose, and chained so tampering shows.

Sealed by default

Sensitive fields stay sealed until an analyst supplies a purpose and clicks Reveal. The reveal writes its own audit row – actor, field, outcome – so looking at the evidence is itself on the record.

Tamper-evident audit ledger

Every audit row carries the hash of the row before it. Rewrite history anywhere in the chain and the break is visible everywhere after it.

Verify on demand

One action walks the entire chain and returns a verdict: Intact. That is the word you hand to an auditor.

row …f31 row …c22 row …a19 Verify chain: Intact Schematic
The diligence answers, question by question – Trust & Evidence →
2× 12/12 hardened acceptance runs on fresh deploys 7/7 persona review pass Audit chain verified Intact – recorded on a live deployment
Coding agents

The most privileged agents you run sit on developer machines.

Coding agents read your source, hold your credentials, and shell out with your permissions. RAXE watches them where they run – and tells you exactly how confident it is about who did what.

Live Explicit

Claude Code

Watched live. Every event carries EXPLICIT session attribution – the record proves which session did it.

Live Explicit

OpenCode

Watched live with EXPLICIT session attribution, the same way – one plugin, the same timeline, the same console.

Ingest Inferred

Codex

Sessions arrive via ingest, and attribution is honestly labelled INFERRED. We don't claim a live hook we don't have.

The attribution label is part of the evidence. If RAXE can't prove which session did something, the record says so – plainly.

What they actually touch, at the kernel – explore RAXE Sensor →
AWS CloudTrail + AgentCore

Your agents don't stop at the laptop. Neither does the record.

Which agent role read that secret? CloudTrail knows. Now you do. Your agents assume IAM roles, read secrets and call AWS services under identities your SOC rarely watches. RAXE reads your live CloudTrail and raises detections as agent activity lands – an agent role reading a secret becomes a data-exfiltration alert in the console, on the same timeline as gateway claims and kernel-observed file access. Bedrock AgentCore telemetry joins that timeline too.

  • Self-hosted in your environment, watching your own AWS accounts – no vendor cloud receives your CloudTrail
  • Correlation, not exact attribution
  • Demo views use clearly-labelled sample data
  • Early access – design partner programme
Deployment

Self-hosted. Observe-first. Your boundary.

Runs in your environment

Self-hosted in your VPC or on-prem. Prompts and detections stay inside your boundary – there is no vendor scanning cloud. That includes cloud coverage: the collector reads CloudTrail from inside your environment, watching your own AWS accounts.

Validated paths

Docker Compose and systemd deployments, plus a Python SDK for in-app coverage – validated end-to-end on fresh deploys. Kubernetes DaemonSet and sidecar are on the roadmap.

Observe-first rollout

RAXE deploys observing and logging. Every would-block decision is logged with the evidence to back it, so you see exactly what a stricter posture would have done. Today it lets you see it. Next, it lets you stop it.

Operational metadata telemetry is documented on the trust page.

See how it deploys →
Early access – design partner programme

See what your agents actually do.

Thirty minutes, live on a real deployment: the timeline, the catch, the reveal, and the chain verified Intact.

Book a 30-min walkthrough → Watch the 4-min walkthrough Talk to an Engineer