Zero-trust for AI agents

AI agents need
critical assets.

ZModal protects them.

Just-in-time provisioning Intent-aware firewall Framework-agnostic Tamper-proof audit Live BI dashboard
ZModal Enterprise Dashboard — Workflow Explorer
Same-day deployThe stack your customer runs — no demo-only shortcuts.
No SDK changesAgent code is untouched. Guardrails are invisible to it.
🔑
Credential swapAgent never sees the real API key. Real key never leaves the proxy.
Replay-grade auditEvery prompt, rail decision, tool call — recorded with full context.
The problem

Traditional security models weren't built for agents.

When an agent calls a tool, sends an email, or fetches a credential — there's no human in the loop. No firewall watches the prompt. No audit log exists. The agent is trusted by default.

Uncontrolled egress

Agents call anything, any host

Without a host allow-list, an agent can exfiltrate data by calling arbitrary HTTP endpoints — including attacker-controlled URLs injected via prompt.

Critical-asset exposure

Critical assets live in agent memory

When an agent holds credentials, API keys, tokens, and other critical assets, a single tool-argument attack can exfiltrate them. Never audited, never scoped, never rotated.

Zero observability

No record of what the agent did

Most deployments have no turn-level audit trail. A security incident means digging through unstructured logs — if any exist — with no rail context.

How ZModal works

Prevent · Record · Detect.

Critical assets out of the agent. Everything else, watched.

01 Prevent

Critical assets never live in agent memory.

Hide & just-in-time provision

Credential swap
  • Stops theft & sprawl
  • No starvation, no shadow agents
  • Every employee can build

Intent-aware agentic firewall

Host firewall
  • Mission & budget enforced
  • Drift caught before egress

Critical assets stay off the agent

  • Agent never holds real credentials
  • No serialization into agent state
02 Record

Tamper-proof audit.

Independent layer the agent can't touch. Every prompt, tool call, and decision — attributed per tenant.

Audit hook · Workflow Explorer
03 Detect

Live reasoning-layer monitoring.

Catch pilot errors. Auto-generate policy profiles per workflow. Anomalies before incidents.

Layered guardrails

Intent classifier Safety rail Moderation
Live BI · alert codes · policy tuning
Works with your stack

Framework-agnostic by design.

ZModal sits at the proxy, not in your agent code. Whatever framework, topology, or model you run, the same protection applies — no rewrites.

Agentic frameworks
CrewAI LangGraph Hermes

Drop-in HTTP shim — no SDK rewrites, no prompt changes.

Orchestration topologies
Serial Parallel Mesh

Serial, parallel, or mesh — the same protection applies no matter how your agents coordinate.

Any model, any rail
OpenAI Anthropic Llama Qwen + more

Bring your own models for the workflow and the safety rails — configured per agentic workflow.

What ZModal catches

Real alert codes. Real blockers.

Every alert is a policy-based enforcement decision — applied uniformly to natural-language prompts and structured API/tool calls. These aren't synthetic demo scenarios; every code was fired in our live demo against a real agentic workflow.

A3 Host not in allow-list

Agent attempted an outbound request to a host outside the task's allow-list. Blocked at HTTP CONNECT — no LLM call, no data transfer, no tool executed.

→ blocked at HTTP CONNECT · no LLM call made · zero bytes exfiltrated
iL Intent classifier rejected locally

Per-agent intent policy deemed the user's prompt out-of-scope for this agent's registered intent domain. Request blocked before reaching the LLM — same policy applies whether the input arrives as natural language or a structured API call.

→ blocked at guardrail · sanitised error returned to agent · workflow halted cleanly
C1 URL not in credential allow-list

Tool attempted to call a URL that has no credential binding. Blocked before credential lookup — prevents both data exfiltration and credential leakage.

→ credential never retrieved · tool never reached target URL
PASS Happy-path agent run

All rails pass. Agent executes multi-tool research workflow — Serper search, website scrape, synthesis. Every turn recorded in the BI dashboard with full rail context.

→ all 6 rails PASS · credential swapped silently · 98.5k safety tokens logged
Live BI dashboard

Every turn visible. Every rail accountable.

The dashboard runs on Apache Superset with ZModal's custom Workflow Explorer — a three-level drill-down from workflow list (L0) to task overview (L1) to per-turn event DAG (L2).

ZModal Enterprise Dashboard — Workflow Explorer
Pricing

Simple, transparent tiers.

ZModal deploys on your infrastructure. Pricing scales with agents and users — not API calls or data volume.

Design Partner
Free
Limited seats · apply to qualify
  • Full production stack on your infrastructure
  • All six guardrail rails — host firewall, intent, safety, moderation, credential swap, audit
  • Live BI dashboard with Workflow Explorer
  • Direct access to founding team
  • Requires a real agentic workload
  • Up to 5 monitored agents
Apply to join →
Enterprise
Contact us
Per-agent licensing · volume discounts
  • Everything in Design Partner
  • Unlimited monitored agents
  • Multi-tenant isolation · per-user X.509 certificates
  • SSO / SAML / LDAP integration
  • Vault-backed secrets (roadmap)
  • Dedicated support + SLA
Talk to us →

All tiers deploy on your infrastructure. ZModal never has access to your agent traffic, credentials, or data.

Design partner program

We're looking for a real workload to protect.

We're asking for three things — a real agentic workload to run against the live stack, a security review of the deploy, and a 30-minute follow-up to walk the BI dashboard with your team.

Email Us
Or send a message