Skip to content

Cyron AI Security · Agent boundary protection · On-Premise

AI agent security for MCP and A2A, on your own infrastructure.

Cyron AI Security sits at the boundary between your AI agents and the tools and agents they call. It inspects tool lists, tool calls, tool responses and agent-to-agent messages, blocks the threat classes you name, and turns every detection into evidence classified to OWASP's LLM and Agentic Top 10 lists. It runs fully air-gapped.

15 agent-layer detectorsMCP and A2ABlocks by threat classFully air-gappedNo GPU needed

Your API security sees an authorised call. Cyron sees the instruction behind it.

AI agents no longer only answer questions. They call internal tools, read records and message other agents. To a firewall, a gateway or an API security product, that is an authorised application making authorised calls. The attack is in what the agent was told: a directive hidden in a tool description, a tool that changed after approval, an instruction planted in a tool's response, a delegation replayed between agents. Cyron AI Security reads that layer.

A poisoned tool description

A hidden instruction tells the agent to read a key file and pass it along. Every call that follows is authorised; Cyron flags the description itself.

A rug-pull

A tool you approved last month quietly changes; Cyron flags the change.

A secret in a tool argument

An agent is steered into sending an AWS access key to a tool; Cyron catches it and, when you choose, blocks it.

Every tool list, call and response. Every message between agents.

Traffic What Cyron AI Security does
MCP over Streamable HTTP Inspects tool lists, tool calls and tool responses, including streamed responses
A2A over JSON-RPC Inspects messages, tasks and delegations between agents
Malformed or ambiguous messages Refuses or flags messages crafted to confuse parsers

15 detectors for the agent layer

Each detector looks for one way an agent can be turned against its owner. Each finding carries its class from a public standard.

Threat What it catches Standard
Secrets and personal data in tool arguments Cloud keys, private keys, tokens, card numbers, email addresses, social security numbers LLM02:2025
Tool-description poisoning Directives hidden in a tool's description LLM01:2025, ASI04
Hidden instructions Invisible and look-alike characters, text pushed out of sight ASI04
Rug-pull A tool definition that changes after approval ASI04
Tool shadowing A tool imitating another tool's name ASI04
Weak or poisoned schema Permissive or unsigned tool schemas ASI04
Output poisoning Instruction-shaped text in a tool's response LLM01:2025
Response-schema divergence A response that breaks the schema the tool declared LLM05:2025
Oversized or encoded arguments Argument shapes typical of data being smuggled out LLM02:2025
Cross-server exfiltration Data from one tool server reappearing in a call to another LLM02:2025, ASI04
Shared-credential hijack One credential used across identities ASI03
Confused deputy An agent used beyond its caller's authority ASI03
A2A session smuggling Instructions injected into an agent-to-agent session ASI07
A2A delegation replay Replayed delegations and tokens that never expire ASI07
A2A transitive trust Trust escalated through a chain of agents ASI07

LLM classes come from the OWASP Top 10 for LLM Applications (2025) and ASI classes from the OWASP Top 10 for Agentic Applications (2026).

Detect everything. Block only what you name.

You choose the threat classes to block and the severity at which blocking starts. Everything else is allowed and recorded, and blocked calls leave evidence too.

Verified result, gateway role: sensitive-information disclosure blocked at high severity

Want personal data blocked too? Lower the severity to medium.

Tool call carrying Result
AWS access key Refused. The tool server received it zero times
Email address Allowed and recorded
14-digit order number Correctly ignored: it is not a card
Phone number Allowed
Ordinary text Allowed

Every detection becomes evidence an auditor can read.

Durable

Findings survive restarts and upgrades.

Classified

Every finding carries its class from the OWASP Top 10 for LLM Applications (2025) or the OWASP Top 10 for Agentic Applications (2026).

Honest

A transparent control status report shows exactly what is inspected.

Discreet

Credentials seen in traffic are never written to disk.

Gateway, or kernel sensor: your choice

Every capability works on its own. Run Cyron AI Security as a gateway in front of your MCP and A2A servers, where it refuses malicious calls before they reach the tool. Or run it inside Cyron On-Premise, where the iris kernel sensor captures agent traffic, your agents need no changes, and sources are blocked at the kernel.

  1. Agent

  2. Cyron AI Security

  3. MCP tools and A2A agents

You choose one role per installation and can switch roles in a maintenance window.

What Gateway Kernel sensor, inside Cyron On-Premise
How traffic reaches it Agents call the gateway, one route per registered tool server The iris kernel agent copies agent traffic. Nothing is re-routed
Who enforces The gateway refuses the call with HTTP 403 before the tool server is reached For the threat classes you chose, Cyron API Security blocks the source at the kernel
Where you see it Findings in Cyron AI Security Findings, plus incidents and SIEM events in Cyron API Security
Works with Cyron API Security On its own or alongside Together, as one loop

No internet. No call-home. No GPU.

Offline install

The installer verifies checksums, loads images offline and creates its keys on site. Run it twice and nothing breaks.

Offline updates

New threat definitions and rules arrive as signed, encrypted bundles.

Safe upgrades

Each upgrade backs up your evidence, checks that every finding survived and rolls back if anything fails.

Modest hardware

A Linux host with a container runtime.

What's next

We are building deeper behavioural insight for every agent, and a direct path from your agent-security evidence into Cyron AI Compliance.

Frequently asked questions

What is Cyron AI Security?
Cyron AI Security is an on-premise security product for AI agents. It sits between your agents and the MCP tool servers and A2A agents they call, inspects what passes between them, blocks the threat classes you choose and records every detection as evidence classified to OWASP standards.
What is agent boundary protection?
Agent boundary protection means inspecting the traffic that crosses the line between an AI agent and the tools or agents it uses: the list of tools, each call and each response. It catches attacks that arrive as instructions rather than as malformed requests.
Is Cyron AI Security an MCP gateway?
It can be. As a gateway, agents reach each MCP server through Cyron, which inspects every exchange and can refuse it. Inside Cyron On-Premise it works from the kernel sensor instead, so agents are not re-routed.
Why is it on-premise only?
Agent-layer analysis reads tool arguments, credentials and internal data in full. That belongs on your own servers, so that is where Cyron AI Security runs.
Does it work without Cyron API Security?
Yes. Cyron API Security adds kernel-level enforcement, agent incidents in the same dashboard as your API incidents, and signed SIEM events.
Does it use an AI model to make decisions?
No. Detection is deterministic: the same exchange always gets the same verdict, every verdict can be explained, and no GPU is needed.
Does it detect prompt injection?
Yes, the injection that reaches your agents through the tool layer: directives hidden in tool descriptions and instruction-shaped text in tool responses.
Which standards does it use?
The OWASP Top 10 for LLM Applications (2025) and the OWASP Top 10 for Agentic Applications (2026), with MITRE ATLAS vocabulary.
How is it licensed?
By a signed licence file, issued for your deployment, with no call-home.

Evaluate it against your own agents.

Cyron AI Security installs on a Linux host inside your network. Tell us which MCP servers and agents you run, and we will set up an evaluation on your servers.

See how it works with Cyron API Security