FOR ORGANISATIONS OF 500 – 2,000 PEOPLE

The agent cannot betray
what it cannot exceed.

You are already running AI agents. Almost nobody your size has a dedicated agent-security team — and the people who chose those agents chose them on cost, not on containment. This is the part that stops them when they are wrong.

In July 2026 an autonomous agent executed 17,000 actions in one weekend and reached a major company's production infrastructure. No human directed it. Nothing it did required a stolen password. It had a mandate — and it exceeded it, because nothing structurally stopped it. The question is not whether your agents can be trusted. It is what happens when one of them is wrong.

THE DECISION WE MADE ABOUT PRICING

One product. One price. Every door closed. There is no cheaper version with fewer protections, because a rogue agent does not check what you paid. The only thing that ever changes is how many agents you run.

WHAT WE DO INSTEAD OF GUESSING

A signed action-path

The agent's whole plan is signed in advance. A step that is not on the plan does not execute. We bind the sequence, not one call — because the attack is the sequence.

A birth certificate per agent

Post-quantum (ML-DSA-87), checked on every action rather than once at login. No passport, no run. Shadow agents surface the moment they act.

Fail-closed, in the path

The action is blocked as it happens and the evidence is written whether anyone is watching or not. Not an alert in a queue somebody reads on Monday.

WHERE IT WOULD HAVE STOPPED — STEP BY STEP

The July 2026 breach is public, recent, and exactly the shape of an agent with nothing constraining it. Here is where each step meets a control — all of them included — there is no tier where they are not.

1
Agent ingests a malicious dataset. The attack ends here. Untrusted content is labelled at ingestion and structurally barred from driving a privileged action.
CONTEXT-BOM + IFC
2
Template injection hidden in the config. Schema mismatch — the response is rejected before the agent ever sees it.
TOOLSEAL
3
Executes code that was never planned. Not on the signed path: blocked, evidence written, human escalated.
PSE
4
Escalates privilege off-mandate. Denied.
IRM
5
Harvests credentials to move laterally. Credentials are scoped to the signed plan — there is nothing to harvest.
KEYCAGE
6
Opens a cross-cluster connection. Blocked at the kernel, regardless of the zero-day above it.
eBPF KLE
7
17,000 actions in 48 hours — more than three standard deviations from baseline. Retire and quarantine.
DRIFT + IMMUNE

68 DOORS · 11 PLANES · ALL ENFORCING

An agent is not one thing to defend. It is a harness with many doors — and every one of them is named, covered and enforcing.

PLANE 1
Launch & config
7 doors
PLANE 2
Tools & capabilities
4 doors
PLANE 3
Context & data
6 doors
PLANE 4
Model & reasoning
4 doors
PLANE 5
Output & action
5 doors
PLANE 6
Multi-agent
5 doors
PLANE 7
Identity & authority
3 doors
PLANE 8
Runtime, infra & supply
8 doors
PLANE 9
Transport & relay
6 doors
PLANE 10
Breakout
4 doors
PLANE 11
Chaingraph
16 doors
TOTAL
68 doors
every one enforcing

IF ANY TEAM SELF-HOSTS AN OPEN MODEL — INCLUDED AT EVERY TIER

At your size, someone almost certainly self-hosts an open-weight model, because it is cheaper. The safety training in that model is removable. A published technique strips a model's ability to refuse in minutes on free hardware, and the public hubs already list thousands of models with their refusal removed. A second published method does it by fine-tuning on entirely harmless data — which means reviewing the dataset cannot see it.

What we do: we measure whether the model can still say no, and sign the result so it can be shown to an auditor and compared over time. If the number falls, that is a security event — not a quality metric.

What we will not do: claim to repair a model whose safety has been removed. Putting it back makes the model refuse ordinary work. We prove; we do not restore — and we would rather say so than sell a promise that fails quietly.

PRICING — ONE PRODUCT, ONE PRICE

There is no ladder, and that is deliberate. Protection does not vary, so there is nothing for you to choose between — and no way to accidentally buy the version that leaves a door open.

EVERYTHING INCLUDED
INTEGRITAS BUSINESS
€5,999 / month
€59,990 / year (2 months free) · up to 50 agents · pay by card
Start monthly — €5,999 Start annual — €59,990 (2 months free)
Monthly, by card, cancel from the dashboard. More than 50 agents? The price scales with the fleet — one conversation, no second product to evaluate.

Less than half the cost of one security hire — and it works on the first day.
What “everything” means
All 68 doors, 11 planes — enforcing
Governed birth & agent constitution
Signed action-path (PSE)
Out-of-context enforcer (IRM)
Mandate & capability caps (CTC)
CONTEXT-BOM · MEMGUARD · MODELSEAL
TOOLSEAL · taint tracking (IFC)
KEYCAGE credential containment
Signed agent-to-agent messages
Delegation caps · collusion control
Reasoning-trace & render integrity
Sandbagging & dormant-trigger scanning
Containment witness (plane 10)
Chaingraph attack-chain analysis (plane 11)
Open-weight refusal attestation
Hash-chained evidence · post-quantum certificates
Why one price and not four. We had four tiers. Then we noticed that six of the seven controls that would have stopped the July breach sat above the entry tier — which meant the cheapest customer was the least protected, and the promise on our own front page was not one we kept. So we put every control in one product and stopped selling protection by the slice. It costs us margin. It is the right way to sell this.

WHAT WE DO NOT CLAIM

We are not a guardrail: we do not judge whether an instruction is wise, we enforce whether it is permitted. We do not promise to detect every novel attack — we promise that an action outside the signed mandate does not execute, whether we have seen the attack before or not. And where a control is partial, our own coverage register says partial. Ask for it and we will send it as it is.
1. Choose a tier
2. Pay by card — monthly or annual
3. Get your activation link and onboard the same day
CryptoShield AI BV · Amsterdam · adama@cryptoshieldai.ai
SECURITY FOR AI AGENTS — NOT AI FOR SECURITY.
The breach described on this page is public and is reported as reported. No customer names and no confidential third-party information appear anywhere on this site.