Chaingraph
The defining property of an agent swarm attack is that no single action looks suspicious. Load a dataset. Run code. Read a credential. Open a connection. Every link is an ordinary operation that a reasonable policy permits — and no component owner is in a position to see the whole.
We stop it. Not detect it, not report it — stop it.
A swarm moves at machine speed, so anything that waits for a person has already lost. The reversible half of the response fires in the path of the action, with no approval queue: the agent is throttled, the session revoked, the channel denied, the coordinating coalition quarantined, a solicited approval voided, and the whole thing snapshotted for replay. A human is then given the irreversible half — a decision, not an alert dump.
The swarm did not need permission
Every permission system ever built asks whether an agent may do a thing. None asks what a group could do by pooling what each member is separately allowed. That is not an oversight in anyone's product — it is a question the industry has not been asking.
Two agents. Both compliant. Both approved.
One agent may execute code. Another may reach the network. Reviewed separately — which is how they are always reviewed — neither is dangerous, and both pass. There is no finding to raise, no policy being violated, and no reviewer who has done anything wrong.
Together they are an escape.
Danger here is a set-union property, not a behaviour. It does not depend on intent, on a signature, or on anyone acting badly first. It is a fact about the permission map that was true the day the estate was built — and it stays true, silently, until something uses it.
This is the only control we own that would have flagged a swarm the day before the run started — because it does not wait for behaviour. It reads the map.
Closed at one hop. Open at two.
The second failure in the same family, and the one that defeated a textbook remediation. A model has no internet access. It can reach an internal service. That service has internet access. Every statement is true, every control is correctly configured, and the estate is open end to end.
Entry to objective, not findings
Chaingraph composes the estate into complete multi-hop routes and ranks them by how feasible they are, not by per-item severity. One answer, not four hundred findings that each need a human to correlate.
The one control that cuts the most
Out of the whole route map it names the single control that severs the largest share of it, and states plainly when the coverage it can offer is partial rather than overstating what one fix buys you.
A leading indicator, not a snapshot
It re-runs continuously, so what you hold is whether the estate is growing routes or shrinking them — which is the number that tells you if last quarter's work was real.
It never reads the model's language
This is a design constraint, not a limitation we are apologising for. Every judgement Chaingraph makes is drawn from timing, topology, ratios and permissions — things that stay legible no matter what the model is doing internally.
The industry's remaining line of defence is monitoring what the model says. That line is thinning: models increasingly reason in compressed forms that are, in a frontier lab's own words, "harder and harder to process" — and nobody can read everything anyway. A control that depends on understanding the language fails exactly when the language stops being readable. Ours does not read it, so it does not care. It also means Chaingraph works on an attack nobody has catalogued yet, because it never needed a catalogue.
The honest limits — what we do not claim
Read this before you repeat anything from this page. Every claim above is checkable, which is exactly why the ones we refuse to make are worth stating out loud.
That Chaingraph finds vulnerabilities
It is not a scanner and it does not discover anything. It reasons over the state you declare. Wrong input, wrong graph — and we would rather you knew that before you bought it than after.
That tempo proves malice
Machine cadence proves that no human produced it. That is a different and much smaller claim than intent, and we will not stretch it in a sales room.
Unlimited coalition depth
The set analysis is bounded, and the bound is stated inside the verdict itself rather than buried in a footnote. You are told the edge of what was checked.
That we out-scan a dedicated scanner
We do not, and we are not trying to. That layer belongs to someone else and it is good. Chaingraph answers the question that sits above it.
Who this is for
Deliberately narrow. If you are not running a fleet of agents with real permissions against real systems, this is not the control you need — and we would rather tell you that now.
You operate agent estates whose members are individually reviewed and collectively unexamined. You need the set question answered before a campaign, not after an incident.
Your agents each passed review. Nobody has ever computed what they can do together, because no tool you own asks that question.
You are asked to accept per-agent compliance as evidence that an estate is safe. It is not, and this is the artefact that shows the difference.
What you get
A ranked route map
The complete entry-to-objective routes your estate currently has, ordered by feasibility, with the bound of the analysis declared on the face of it.
The next control to add
The single highest-value control to add next — and an honest statement when one control is not enough to clear the map.
Whether you are winning
Routes opening or routes closing over time. The only version of this number that survives contact with a board meeting.
Chaingraph is delivered with Containment Witness
The two planes answer one wave and are scoped together against your estate, so there is no shelf price to quote. Tell us how many agents you run, what they are each permitted to do, and who has computed what they can do as a set. If the answer to the last one is nobody, that is the conversation.
Contact us See Containment Witness