When an agent calls a tool, sends an email, or fetches a credential — there's no human in the loop. No firewall watches the prompt. No audit log exists. The agent is trusted by default.
Without a host allow-list, an agent can exfiltrate data by calling arbitrary HTTP endpoints — including attacker-controlled URLs injected via prompt.
When an agent holds credentials, API keys, tokens, and other critical assets, a single tool-argument attack can exfiltrate them. Never audited, never scoped, never rotated.
Most deployments have no turn-level audit trail. A security incident means digging through unstructured logs — if any exist — with no rail context.
Critical assets out of the agent. Everything else, watched.
Independent layer the agent can't touch. Every prompt, tool call, and decision — attributed per tenant.
Catch pilot errors. Auto-generate policy profiles per workflow. Anomalies before incidents.
ZModal sits at the proxy, not in your agent code. Whatever framework, topology, or model you run, the same protection applies — no rewrites.
Drop-in HTTP shim — no SDK rewrites, no prompt changes.
Serial, parallel, or mesh — the same protection applies no matter how your agents coordinate.
Bring your own models for the workflow and the safety rails — configured per agentic workflow.
Every alert is a policy-based enforcement decision — applied uniformly to natural-language prompts and structured API/tool calls. These aren't synthetic demo scenarios; every code was fired in our live demo against a real agentic workflow.
Agent attempted an outbound request to a host outside the task's allow-list. Blocked at HTTP CONNECT — no LLM call, no data transfer, no tool executed.
Per-agent intent policy deemed the user's prompt out-of-scope for this agent's registered intent domain. Request blocked before reaching the LLM — same policy applies whether the input arrives as natural language or a structured API call.
Tool attempted to call a URL that has no credential binding. Blocked before credential lookup — prevents both data exfiltration and credential leakage.
All rails pass. Agent executes multi-tool research workflow — Serper search, website scrape, synthesis. Every turn recorded in the BI dashboard with full rail context.
The dashboard runs on Apache Superset with ZModal's custom Workflow Explorer — a three-level drill-down from workflow list (L0) to task overview (L1) to per-turn event DAG (L2).
ZModal deploys on your infrastructure. Pricing scales with agents and users — not API calls or data volume.
All tiers deploy on your infrastructure. ZModal never has access to your agent traffic, credentials, or data.
We're asking for three things — a real agentic workload to run against the live stack, a security review of the deploy, and a 30-minute follow-up to walk the BI dashboard with your team.