Defensive Agent Security Gateway · Defensive only

PhaseOne10841 Defensive Agent Security Gateway

Agent EDR for autonomous systems. Watches agents outside the agent— like CrowdStrike for endpoints—not prompt-only hope. Gateway policy, session replay, canaries, A2A firewall, and human approval for destructive actions.

A product of Veracity Integrity LLC

  • Multi-agent coordination
  • Sandbox escape attempts
  • Covert channels
  • Transcript tampering patterns
  • Unauthorized tool use

Defenses that sit outside the agent

Autonomous agents increasingly call tools, talk to peers, and mutate systems. Prompt instructions alone cannot reliably constrain that behavior. PhaseOne10841 places a defensive gateway between agents and the world: policy enforcement, recording, detection, and human approval—independent of what the model “intends.”

Context: why this matters

In July 2026, public reporting around a Hugging Face / ExploitGym agent-swarm incident underscored how coordinated agent behavior can outpace prompt-level controls. PhaseOne10841 is built for that reality: observe and gate agent actions from the outside. High-level summary only—no exploit steps or attack reproduction here. Independent analysis: METR incident report (Aug 2026).

What PhaseOne10841 includes

A complete defensive stack for autonomous agents—ready to deploy.

Gateway

OpenAI-compatible proxy with policy enforcement, tool approval API, and defensive scanners.

Policy YAML

Domain default-deny, shell deny-by-default, MCP allowlist, secret egress rules, approval timeouts, SIEM hooks.

Recorder / Postgres

Event store with deep session replay chain and SIEM JSONL / webhook export.

Canaries

Harmless marker files with high-severity detection when touched—signals for unexpected access.

MFA dashboard

Email OTP–gated admin UI: incidents, replay, approvals, policy, agents, canaries, SIEM, lab.

A2A firewall

Trust levels and injection scanning on agent-to-agent peer messages.

Prompt-injection scanner

Source-classified detection with optional block on untrusted content paths.

Human approval

Destructive tool use waits for human resolution—risk, reason, expiry, and notes.

SIEM export

ECS-style JSONL download plus optional webhook sink for your existing SOC stack.

Lab harness

Inert fake services and labeled TEST fixtures for defensive detector validation.

Quick start

npm run onboard
docker compose up

Gateway on :8080 · MFA dashboard on :3000 · Source: github.com/veracitylife/PhaseOne10841-VI

How it fits together

Request early access

Talk with Veracity Integrity about deploying PhaseOne10841 in your environment— early access, enterprise conversations, and support.

Veracity Integrity LLC

PhaseOne10841 is a product of Veracity Integrity LLC—building defensive integrity controls for modern agentic systems.

Visit VeracityIntegrity.com

Veracity Integrity LLC

7533 S Center View Ct Ste R
West Jordan, UT 84084

Phone: +1-888-64-6790

WhatsApp: +1 (808) 365-6628

info@veracityintegrity.com

support@veracityintegrity.com