Cyron AI Security · Agent boundary protection · On-Premise
AI agent security for MCP and A2A, on your own infrastructure.
Cyron AI Security sits at the boundary between your AI agents and the tools and agents they call. It inspects tool lists, tool calls, tool responses and agent-to-agent messages, blocks the threat classes you name, and turns every detection into evidence classified to OWASP's LLM and Agentic Top 10 lists. It runs fully air-gapped.
Your API security sees an authorised call. Cyron sees the instruction behind it.
AI agents no longer only answer questions. They call internal tools, read records and message other agents. To a firewall, a gateway or an API security product, that is an authorised application making authorised calls. The attack is in what the agent was told: a directive hidden in a tool description, a tool that changed after approval, an instruction planted in a tool's response, a delegation replayed between agents. Cyron AI Security reads that layer.
A poisoned tool description
A hidden instruction tells the agent to read a key file and pass it along. Every call that follows is authorised; Cyron flags the description itself.
A rug-pull
A tool you approved last month quietly changes; Cyron flags the change.
A secret in a tool argument
An agent is steered into sending an AWS access key to a tool; Cyron catches it and, when you choose, blocks it.
Every tool list, call and response. Every message between agents.
In depth: MCP security and A2A protocol security.
| Traffic | What Cyron AI Security does |
|---|---|
| MCP over Streamable HTTP | Inspects tool lists, tool calls and tool responses, including streamed responses |
| A2A over JSON-RPC | Inspects messages, tasks and delegations between agents |
| Malformed or ambiguous messages | Refuses or flags messages crafted to confuse parsers |
15 detectors for the agent layer
Each detector looks for one way an agent can be turned against its owner. Each finding carries its class from a public standard.
| Threat | What it catches | Standard |
|---|---|---|
| Secrets and personal data in tool arguments | Cloud keys, private keys, tokens, card numbers, email addresses, social security numbers | LLM02:2025 |
| Tool-description poisoning | Directives hidden in a tool's description | LLM01:2025, ASI04 |
| Hidden instructions | Invisible and look-alike characters, text pushed out of sight | ASI04 |
| Rug-pull | A tool definition that changes after approval | ASI04 |
| Tool shadowing | A tool imitating another tool's name | ASI04 |
| Weak or poisoned schema | Permissive or unsigned tool schemas | ASI04 |
| Output poisoning | Instruction-shaped text in a tool's response | LLM01:2025 |
| Response-schema divergence | A response that breaks the schema the tool declared | LLM05:2025 |
| Oversized or encoded arguments | Argument shapes typical of data being smuggled out | LLM02:2025 |
| Cross-server exfiltration | Data from one tool server reappearing in a call to another | LLM02:2025, ASI04 |
| Shared-credential hijack | One credential used across identities | ASI03 |
| Confused deputy | An agent used beyond its caller's authority | ASI03 |
| A2A session smuggling | Instructions injected into an agent-to-agent session | ASI07 |
| A2A delegation replay | Replayed delegations and tokens that never expire | ASI07 |
| A2A transitive trust | Trust escalated through a chain of agents | ASI07 |
LLM classes come from the OWASP Top 10 for LLM Applications (2025) and ASI classes from the OWASP Top 10 for Agentic Applications (2026).
Detect everything. Block only what you name.
You choose the threat classes to block and the severity at which blocking starts. Everything else is allowed and recorded, and blocked calls leave evidence too.
Verified result, gateway role: sensitive-information disclosure blocked at high severity
Want personal data blocked too? Lower the severity to medium.
| Tool call carrying | Result |
|---|---|
| AWS access key | Refused. The tool server received it zero times |
| Email address | Allowed and recorded |
| 14-digit order number | Correctly ignored: it is not a card |
| Phone number | Allowed |
| Ordinary text | Allowed |
Every detection becomes evidence an auditor can read.
Durable
Findings survive restarts and upgrades.
Classified
Every finding carries its class from the OWASP Top 10 for LLM Applications (2025) or the OWASP Top 10 for Agentic Applications (2026).
Honest
A transparent control status report shows exactly what is inspected.
Discreet
Credentials seen in traffic are never written to disk.
Gateway, or kernel sensor: your choice
Every capability works on its own. Run Cyron AI Security as a gateway in front of your MCP and A2A servers, where it refuses malicious calls before they reach the tool. Or run it inside Cyron On-Premise, where the iris kernel sensor captures agent traffic, your agents need no changes, and sources are blocked at the kernel.
-
Agent
-
Cyron AI Security
-
MCP tools and A2A agents
You choose one role per installation and can switch roles in a maintenance window.
| What | Gateway | Kernel sensor, inside Cyron On-Premise |
|---|---|---|
| How traffic reaches it | Agents call the gateway, one route per registered tool server | The iris kernel agent copies agent traffic. Nothing is re-routed |
| Who enforces | The gateway refuses the call with HTTP 403 before the tool server is reached | For the threat classes you chose, Cyron API Security blocks the source at the kernel |
| Where you see it | Findings in Cyron AI Security | Findings, plus incidents and SIEM events in Cyron API Security |
| Works with Cyron API Security | On its own or alongside | Together, as one loop |
No internet. No call-home. No GPU.
Offline install
The installer verifies checksums, loads images offline and creates its keys on site. Run it twice and nothing breaks.
Offline updates
New threat definitions and rules arrive as signed, encrypted bundles.
Safe upgrades
Each upgrade backs up your evidence, checks that every finding survived and rolls back if anything fails.
Modest hardware
A Linux host with a container runtime.
What's next
We are building deeper behavioural insight for every agent, and a direct path from your agent-security evidence into Cyron AI Compliance.
Frequently asked questions
What is Cyron AI Security?
What is agent boundary protection?
Is Cyron AI Security an MCP gateway?
Why is it on-premise only?
Does it work without Cyron API Security?
Does it use an AI model to make decisions?
Does it detect prompt injection?
Which standards does it use?
How is it licensed?
Evaluate it against your own agents.
Cyron AI Security installs on a Linux host inside your network. Tell us which MCP servers and agents you run, and we will set up an evaluation on your servers.