Agent security & governance
Govern what you
cannot see.
Agents are proliferating faster than any team can track, creating security blind spots, compliance risk, and unmanaged sprawl. Arthur discovers every agent in your environment and brings it under one governance framework.
Discover
Comprehensive visibility into every agent. Anywhere.
Manual self-reporting cannot keep pace with agent proliferation. Arthur runs five sensors in parallel, each one tuned to a different way agents show up.
Listens to OpenTelemetry streams to catch new agents, new tools, and configuration changes as they happen.
Watches for new MCP servers to catch agents as they come online, and flags capability changes in real time.
Inspects network traffic for LLM API signatures to catch agents that bypass instrumentation entirely, including non-standard frameworks.
Queries AWS Bedrock, Google Vertex AI, and Azure AI Foundry, which advertise their running agents through APIs.
Scans employee machines for agents running locally, including personal assistants and local models.
The result
A live library of every agent, sanctioned or not.
Discovery runs continuously across every environment: cloud, endpoints, network, and SIEM. The library updates itself as agents appear and change capability, so official and unofficial agents surface in the same place.
Four surfaces agents arrive through
The registered agents you know about are the tip of the iceberg. Agents arrive through four different surfaces, and each one needs a different sensor to find it. That is why there are five sensors and four surfaces: one surface can take more than one.
needs triage
Observe
See inside every agent, not just its output.
Your inventory says an agent exists. Arthur also shows what it is doing: every step it takes, every tool it calls, what each one costs, and how its behavior moves over time.
For the teams building agents
For the teams accountable for them
Govern
Policy that runs, not policy that sits in a document.
Your governance framework becomes enforced rules on live traffic, with an audit trail behind every decision and a way to stop an agent immediately when it goes wrong.
Translate your written governance framework into machine-checkable policies, scoped per application, model, and environment.
Guardrails evaluate every request and response for prompt injection, PII exposure, restricted models, and off-policy tool use, and return a verdict your application enforces inline.
How a policy decision travels
Arthur evaluates every request and returns a verdict. Arthur returns the verdict; your application enforces it. Wire it in via the SDK, or through a gateway or chat interface you already control.
Deploy securely
Built for the enterprise.
Three deployment options. Fully hosted SaaS, on-prem in your own data center, or a hybrid (also called federated) architecture. RBAC, SSO, and deployed engineering support come with every one. The diagram below shows the hybrid or federated architecture: the evals engine runs next to your workloads, so sensitive data never leaves your environment.
AI applications / data plane
Lightweight, open-source, drop-in — deployed in minutes, next to your AI workloads. Inference data stays local.
Unidirectional access — only anonymized metrics cross
NO SENSITIVE DATA LEAVESCentralized control plane
Centralized visibility and governance, hosted by Arthur or by you, with real-time aggregate metrics across every business unit.
For complex enterprises, a single data plane per line of business or cloud account scales across business units without compromising security.
Procurement
Procure through your cloud marketplace.
Arthur is listed on both the AWS and Google Cloud marketplaces, so you can buy through billing and procurement you already have in place.
AWS Marketplace
Deploy the evals engine inside your own AWS account, so inference data stays where it already lives, and govern agentic, generative, and predictive systems from one control layer.
Google Cloud Marketplace
Add discovery, policy evaluation, and observability to the stack you are already building on Google Cloud, billed through the account your teams use today.