AariaSec
Local · hash-only · free forever, no account
Beyond guardrails — behavioral, never signatures

Catch the moment
an AI agent turns.

Think Antivirus, for AI agents. Your AI agents are everywhere — browser, docs, inbox — and every one acts with your access. AariaSec learns each one's normal, so the instant one steps out of line, you know. Locally. Privately.

✓ One line to connect✓ Prompts never stored✓ macOS · Windows · Linux
Patent-pending behavioral engine
100% on your device — no cloud
Prompts never stored — SHA-256 only
Verifiable builds — checksum every download
OWASP Agentic Top 10 — all 10 risks mapped
Try it — no install, no signup

Watch a guardrail miss it. Then watch us catch it.

A real slice of the AariaSec console, running on sample data right here in your browser. Run a session, and see the content firewall wave it through while behavior gives it away.

app.aariasec.local — demo · sample data

Launch the interactive demo

Click through discovery, the live catch, session replay, and enterprise onboarding — in about two minutes.

Catch an agentSession replayFleet onboardingCost layer
How it works

Live in three steps

No agents to rewrite, no cloud to configure. Point your AI traffic through AariaSec and it does the rest.

1

Connect

Install the app and route an agent with one line — HTTPS_PROXY. Discovery finds the rest of your AI apps automatically.

2

Baseline

AariaSec learns each agent's normal — tools, egress, timing, token rhythm — recognized from day one, fully baselined in about three days.

3

Catch

When an agent drifts or is hijacked, a Red/Blue/White panel returns a clear verdict and risk score (0–100) — and can contain it, automatically.

Why it's different

Behavioral, not block-lists

Most tools scan the words an agent sends. AariaSec watches how it behaves — so an agent that's been tricked, and still has all your access, gets caught. Signatures miss that. Behavior doesn't.

It learns each agent's normal

Tool cadence, egress targets, token rhythm — measured continuously, scored against its own normal, not a generic rule set.

⚖︎

A verdict you can defend

An independent AI panel argues both sides of every alert and returns a clear verdict with a risk score — not a black-box flag you're asked to trust.

Catches drift, not just attacks

Agents don't only get hacked — they wander. AariaSec watches for the slow drift away from normal, not just one-off injection attempts.

🌐

Herd immunity for your fleet

When one deployment flags a bad agent, every other recognizes it on day one — collective defense, while only anonymous hashes ever leave a device.

$

See what your agents actually cost

An estimated per-agent token spend — including browser and web-app AI that never shows up on any bill. A sudden cost spike is often the first sign an agent has gone off-script.

🔒

Local & private by design

Runs entirely on your device. Prompts and responses are never stored at all — only their SHA-256 fingerprints, with a tamper-evident audit trail to prove it.

Connect once. Monitored from then on.

1

Connect

One environment variable routes agent traffic through AariaSec — no SDK.

2

Baseline

Known agents are trusted on day 0; unknown ones learn over a short window.

3

Detect

Behavior that breaks the baseline triggers a Red/Blue/White debate.

4

Verdict

A clear verdict, a risk score, and the full debate transcript — evidence you can replay.

For teams & enterprises

Fleet-grade control. Your data never leaves.

The free app secures the machine it runs on. Enterprise runs it across your whole fleet from one console — a single pane of glass that never takes your data to anyone's cloud. Prompts and behavioral data stay on each endpoint; the console only ever sees health, versions, and the anonymous hashes you consent to share.

🛰️

Central fleet management

See every enrolled install's health, version, and drift in one place. Push policy and staged version rollouts to a group, promote canary → broad, and roll back centrally — all without touching an endpoint.

🔑

SSO, SCIM & custom roles

SAML / OIDC single sign-on (MFA enforced by your IdP), SCIM user & group provisioning that maps directory groups to roles, and org-defined custom roles with least-privilege permission sets.

🗄️

Fits your SOC stack

Stream detections to Splunk, open tickets in Jira / ServiceNow, and bulk-export events & alerts to your own warehouse. Metadata only — never prompt or response content.

🛡️

Decentralized data, by design

Each install's management identity is kept cryptographically separate from the anonymous threat-intelligence it contributes. Enterprise-grade fleet manageability, with a privacy guarantee most EDR platforms can't make.

Watch how it works

Five short walkthroughs

Five clips, under four minutes total — see it work, then why it matters.

Straight answers

The questions a security team asks first

Does AariaSec read or store my prompts?
No. Every prompt and response is SHA-256 hashed at the moment of capture — the raw text is never written to disk, logs, or any database. AariaSec keeps behavioral fingerprints and metadata only, which is why it can run on sensitive workloads.
What does it actually watch, if not the content?
Behavior: which tools an agent calls, where it sends data, its timing and token rhythm, and how that compares to its own learned baseline. A tricked agent that still has your access looks wrong behaviorally long before any keyword filter would notice — that's the gap AariaSec closes.
Where does my data go?
Nowhere. Detection runs entirely on your device or server. Nothing is sent out unless you explicitly opt into anonymous, hash-only collective defense — and even then, only fingerprints leave, never content.
A proxy on all my traffic — doesn't that mean you can see everything?
It runs entirely on your machine and binds to localhost only — nothing of yours is sent to AariaSec. Your agents' requests still go to their normal destinations; AariaSec sits in the middle just long enough to compute a SHA-256 fingerprint, then drops the raw content. The TLS certificate authority is generated on your device and its private key never leaves the machine. Nothing is written to disk or sent out.
Will it block my agents automatically?
Only if you turn that on. AariaSec ships in observe / alert-only mode — it watches and scores, and takes no action on its own. Automatic containment is opt-in and per-agent, and any block is reversible — you release an agent whenever you choose. Run it as a pure detection layer for as long as you like, or let it contain a confirmed-bad agent once you trust its verdicts.
How do I know it actually detects anything?
Because we published the test. PRAMANA is an open benchmark that scores monitoring systems — not agents — on a corpus of behavioural traces containing no prompt text. Our results are on it next to the baselines, and we do not win every column: a forty-line longitudinal detector beats us on season v2, and we score zero on sybil coordination where it scores one. See the research section.
Which agents and LLMs does it support?
Any agent that reaches an LLM over the network — OpenAI, Anthropic, Google, Mistral, local Ollama, and the newer gateways/routers (OpenRouter, Azure OpenAI, Bedrock). Connecting an agent is one line (an environment variable); discovery finds the rest automatically.
Do I have to replace my existing content filter?
No — AariaSec works alongside it. If you already run a content filter or AI firewall (Lakera, Meta Prompt Guard, a WAF), keep it: AariaSec ingests its verdict and correlates it with agent behavior, so a content flag plus behavioral drift becomes a high-confidence catch, while a content flag on otherwise-normal behavior is a likely false positive to tune. Only the verdict is read — never your content, and nothing is sent out to score. AariaSec is the behavioral layer beneath your filter, not a rip-and-replace.
Isn't this what sandboxing or containers are for?
Containment and monitoring answer different questions. A sandbox limits what an agent can do; it doesn't tell you what it did, or whether that was the thing you asked for. The failure we're built for isn't an agent escaping its container — it's an agent using the access you deliberately gave it, because someone planted instructions in a document it read. A coding agent with repo access that gets prompt-injected doesn't need to escape anything; it already has the keys. Sandboxing assumes the code is the threat, which is the right model for untrusted code. Agents invert it: the code is fine, the instructions are hostile. You want both — but if the sandbox is your only control, you find out what your agent did when someone else tells you.
How is this different from a network firewall or policy engine for agents?
A policy engine decides in microseconds, which means it decides from a table someone wrote in advance. That is genuinely useful, and it is why a firewall is fast — but it can only stop what you already knew to describe. AariaSec works the other way round: there is nothing to declare, because each agent's own history is the specification. We score how far today's behavior sits from that agent's established baseline, using the single-subject method from Applied Behavior Analysis rather than a population average. That catches what nobody thought to write down, and it is why we take seconds to adjudicate an ambiguous case instead of microseconds to match a rule.
How is it deployed?
A native app on macOS, Windows, and Linux — desktop, laptop, or server. No Docker required, no cloud dependency. An enterprise fleet enrolls with a single join code; every host keeps its own identity and you keep central control of policy and versions.
Is this real — who's behind it?
AariaSec is built by security engineers around a patent-pending behavioral engine (USPTO provisional filed March 25, 2026). Every build is verifiable — each download ships a .sha256 sidecar you can check before you run it.
Coverage you can verify

Do you see all your AI traffic?

Most tools assume they cover everything. AariaSec measures it — and shows you the gap. New AI gateways and routers (OpenRouter, LiteLLM, Azure OpenAI, Bedrock) quietly move agent traffic off the paths other tools watch. We detect them, flag any app pointed at an unmonitored one, and let you bring it under watch in one click.

AI traffic monitored92%
Monitored — routed & inspected2 endpoints not yet monitored
Unmonitored gateway detected — api.openrouter.ai
Agent routed off-path — Custom LLM proxy
Open research

We publish what we find — including where we fail.

Two public artifacts, free to anyone. One documents how AI agents actually break in the wild. The other measures whether a monitoring system would catch it — ours included, scored in public alongside everyone else's.

Field Notes · VRITTANTA

How AI agents fail in the wild

A curated library of real-world incidents — prompt-injection campaigns, agent breaches, espionage patterns — each mapped to the behavioural rules that catch it and the controls we recommend. 25 incidents tracked and growing. No login, free on every tier.

Benchmark · PRAMANA

Can your monitoring actually detect anything?

Every other agent benchmark scores the agent — whether it can be jailbroken. PRAMANA scores the detector. It exists because our architecture never stores prompt content, so the corpus is publishable where a content-reading vendor's never could be.

We do not top our own leaderboard. A forty-line longitudinal baseline beats us on season v2, and we score zero on sybil coordination where it scores one. Those are real gaps, published deliberately — a benchmark that only embarrasses other people is marketing.

Free

$0
Full behavioral detection. No account, no time limit.
  • Unlimited agents on your machine
  • Fingerprinting, risk scoring, debate-panel verdicts
  • Runs 100% locally · prompts never stored
Download free →

Enterprise

Talk to us
Everything in Free, across your fleet.
  • Multi-host fleet — one-code onboarding
  • Central policy, staged rollouts, seat control
  • Priority support · your data still never leaves
Book a demo →
Get AariaSec

Download & start free

Detecting your platform…

Verify your download. Every build ships a .sha256 sidecar — run shasum -a 256 -c <file>.sha256 (macOS/Linux) or Get-FileHash <file> (Windows).