Smooth gradient background transitioning from dark teal at the top to white at the bottom.
AI agent runtime security

Stop AI agents from going rogue.

Intent is the new perimeter.

An agent can have the right access and still take the wrong action. Capsule checks proposed actions against the authorized task and your policies, helping stop unsafe tool calls before they execute.

Access is abused. Alerts arrive late. Intent remains a blind spot.

Diagram showing Capsule securing AI Agents during runtime with strict access controls and prompt/input rules on the left, including access controls and prompt guardrails, and manual review methods on the right, including human review and post-hoc scanning.Diagram showing Capsule securing AI Agents during runtime with strict access controls, prompt and input guardrails, human review and approvals, and post-hoc scanning and monitoring.
Our latest detection model

Capsule One:
the System One Model for Agentic Intent Security

Built to decide. Not to generate another answer.

Capsule One is Capsule’s own fine-tuned small language model for runtime security decisions. Instead of generating a long response, it scores whether a proposed tool call fits the authorized task, fast enough to decide at the tool-call boundary.

Capsule One · runtime decision
Tool call
upload_file → external service
Capsule One
Violation score
0.96
policy threshold 0.80BLOCK
Builds on our collaboration with
NVIDIA

Together, we fine-tuned NVIDIA Nemotron detectors and tested them on the public StepShield benchmark.

Read the research
98%
Accuracy on the StepShield benchmark
71 ms
Fastest decision time

Secure intent. Not just access.

Access answers “Can this agent use the tool?” Intent security asks “Does this action belong to the task?”

Task context
Understand the task

Evaluate agent behavior in context: its identity, instructions, session history, and the action it is about to take.

Runtime decision
Stop the wrong action

Detect when a proposed tool call crosses the authorized boundary, then allow, flag, or block it according to policy.

Supported integrations
Fit the way you deploy AI

Connect runtime protection to your AI workflows through supported integrations, without redesigning your architecture. Monitoring and blocking capabilities vary by integration.

Dive deeper into Al Agent runtime security

Abstract digital artwork with a teal background and textured edges blending into black and red elements on the left.
View more

GhostSquatting: Model Theft and RCE via Abandoned Names in AI Agent Files

Read more

To Jev Or Not to Jev?

Read more

OWASP Named the Ten Ways Skills Go Wrong. All Ten Are Already Happening.

Read more

CurseBox: The Agent That Sends Your Files to Strangers to Get the Job Done

Read more

Compliance Comes for the Agents: Every Agentic AI Framework You Need to Know

Read more

When Agents Go Rogue

Read more

Keeping AI Agents on Track: How Capsule Powers State-of-the-Art Rogue Agent Detection with NVIDIA Nemotron

Read more

Capsule Launches Security Integration for Claude Platform

Read more

The Agentic Supply Chain: You Installed More Than You Think

Read more

Guardian Agent: Shipping a Useful Agentic Experience

Read more

Your AI Agent Inventory is Lying to You: The Rise of the "Inline Agent"

Read more

We Analyzed 206,435 AI Agent Skills. Here's What We Found.

Read more

Mitigating the Agentic AI Threat: What Security Leadership Needs to Prioritize

Read more

OWASP State of Agentic AI Security and Governance 2026: What Changed, and What It Means

Read more

Every agent needs a "stop". We're standardizing it.

Read more

The Agentic AI Threat Landscape Has Crossed a Threshold

Read more

The Rise of Guardian Agents: Securing the Agentic AI Ecosystem

Read more

CurseChain: How Hidden README Comments Trick Cursor Into Stealing - and Spreading - Your SSH Keys

Read more

The State of AI Agent Security 2026

Read more

Capsule Security Raises $7M to Prevent AI Agents from Going Rogue in Runtime: Intent is the New Perimeter

Read more

Why MCP Gateways are a Bad Idea (and What to Do Instead)

Read more

ClawGuard: Open Source Security for the Agentic Era

Read more

PipeLeak: The Lead That Stole Your Database - Exploiting Salesforce Agentforce With Indirect Prompt Injection

Read more

ShareLeak: Taking the Wheel of Microsoft’s Copilot Studio (CVE-2026-21520)

Read more
Gradient background transitioning from white at the top to dark teal at the bottom.

See Every Agent. Secure Every Action

Frictionless Discovery

Capsule connects in minutes using agentless integration to automatically discover AI agents across home-grown systems, SaaS agent platforms, and endpoint environments delivering immediate visibility without disrupting workflows or requiring ongoing maintenance.

Dashboard interface showing deployment logs with timestamps, project names, directions, detected threats, content previews, and applied policies.

Agent Security Graph

The Capsule Agent Security Graph maps how agents think, act, and interact at runtime by analyzing relationships between agents, tools, data, and actions—revealing risky paths, control gaps, and emerging threats in a clear, intuitive view.

Dashboard interface showing a table with columns for Timestamp, Project, Direction, Threats detected, Content, and Policy, with various security threat labels and statuses.

Deep Observability

Gain deep, real-time visibility into agent behavior, including actions, decisions, and execution paths—providing continuous insight into how agents operate in production and enabling faster investigation, governance, and safe scaling.

Screenshot of a dashboard showing a table with columns for Timestamp, Project, Direction, Threats detected, Content, and Policy, listing multiple entries with various threat detections like Moderated content, PII, Prompt attack, and Unknown links.

Runtime Protection

Enforce security and governance policies in real time, before actions are executed. Capsule detects and blocks unsafe, unintended, or risky agent behavior in real time, preventing incidents without slowing agents or engineering teams.

Dashboard table showing timestamps, projects, input/output directions, detected threats like moderated content and unknown links, content snippets, and policy types.

Agent Identity Control

Continuously understand who the agent is, who owns it, who can access it, and what it’s allowed to do, maintaining clear ownership, least privilege, and accountability across all agent environments.

Dashboard showing a table of timestamps, projects, directions, detected threats, content snippets, and policy names with a navigation sidebar on the left.

Whitebox Red Teaming

Generate white-box AI agent red teaming to proactively uncover weaknesses in agent logic, prompts, and behaviors—feeding real attack insights directly into runtime protection for stronger, continuously improving defenses.

Dashboard interface showing a table of deployment logs with columns for timestamp, project, direction, detected threats, content snippets, and policy names.
Dashboard interface showing deployment logs with timestamps, project names, directions, detected threats, content previews, and applied policies.
Agent Security Graph
Frictionless Discovery

Capsule connects in minutes using agentless integration to automatically discover AI agents across home-grown systems, SaaS agent platforms, and endpoint environments delivering immediate visibility without disrupting workflows or requiring ongoing maintenance.

Dashboard interface showing a table with columns for Timestamp, Project, Direction, Threats detected, Content, and Policy, with various security threat labels and statuses.
Agent Security Graph
Agent Security Graph

The Capsule Agent Security Graph maps how agents think, act, and interact at runtime by analyzing relationships between agents, tools, data, and actions—revealing risky paths, control gaps, and emerging threats in a clear, intuitive view.

Screenshot of a dashboard showing a table with columns for Timestamp, Project, Direction, Threats detected, Content, and Policy, listing multiple entries with various threat detections like Moderated content, PII, Prompt attack, and Unknown links.
Agent Security Graph
Deep Observability

Gain deep, real-time visibility into agent behavior, including actions, decisions, and execution paths—providing continuous insight into how agents operate in production and enabling faster investigation, governance, and safe scaling.

Dashboard table showing timestamps, projects, input/output directions, detected threats like moderated content and unknown links, content snippets, and policy types.
Agent Security Graph
Runtime Protection

Enforce security and governance policies in real time, before actions are executed. Capsule detects and blocks unsafe, unintended, or risky agent behavior in real time, preventing incidents without slowing agents or engineering teams.

Dashboard showing a table of timestamps, projects, directions, detected threats, content snippets, and policy names with a navigation sidebar on the left.
Agent Security Graph
Agent Identity Control

Continuously understand who the agent is, who owns it, who can access it, and what it’s allowed to do, maintaining clear ownership, least privilege, and accountability across all agent environments.

Dashboard interface showing a table of deployment logs with columns for timestamp, project, direction, detected threats, content snippets, and policy names.
Agent Security Graph
Whitebox Red Teaming

Generate white-box AI agent red teaming to proactively uncover weaknesses in agent logic, prompts, and behaviors—feeding real attack insights directly into runtime protection for stronger, continuously improving defenses.

How Capsule enforces intent

From intent to action. With a security decision in between.

Follow a proposed tool call from its authorized task to Capsule’s runtime decision.

Secure runtime for any AI Agent in your workflow

Stacked layers icon with a gradient line design on a dark circular background.

AI Agent Builder Platforms

AWS Bedrock

Azure Foundry

GCP Vertex

Circular dark button with light green angle brackets symbol, representing code or programming.

AI Coding Agents

Claude Code

Cursor

Github Copilot

Icon with a screen showing binary code 1011 and a pair of angled brackets representing code.

Enterprise AI Agents

ChatGPT Enterprise

Microsoft Copilot Studio

Salesforce Agentforce

Green 3D circular arrows forming a continuous loop, symbolizing recycling or rotation.
Three-dimensional green circular arrow forming a continuous rotating loop.
Gradient background transitioning from white at the top to dark teal at the bottom.

See every agent. Secure every action.

Guardian Agent

Capsule acts as the enterprise’s intelligent, always-on guardian agent, continuously discovering, observing, and securing AI agents across the organization while proactively detecting threats, vulnerabilities, and suspicious behavior in real time.

Dashboard interface showing deployment logs with timestamps, project names, directions, detected threats, content previews, and applied policies.

Agent Security Graph

The Capsule Agent Security Graph maps how agents think, act, and interact at runtime by analyzing relationships between agents, tools, data, and actions—revealing risky paths, control gaps, and emerging threats in a clear, intuitive view.

Dashboard interface showing a table with columns for Timestamp, Project, Direction, Threats detected, Content, and Policy, with various security threat labels and statuses.

Deep Observability

Gain deep, real-time visibility into agent behavior, including actions, decisions, and execution paths—providing continuous insight into how agents operate in production and enabling faster investigation, governance, and safe scaling.

Screenshot of a dashboard showing a table with columns for Timestamp, Project, Direction, Threats detected, Content, and Policy, listing multiple entries with various threat detections like Moderated content, PII, Prompt attack, and Unknown links.

Runtime Protection

Enforce security and governance policies in real time, before actions are executed. Capsule detects and blocks unsafe, unintended, or risky agent behavior in real time, preventing incidents without slowing agents or engineering teams.

Dashboard table showing timestamps, projects, input/output directions, detected threats like moderated content and unknown links, content snippets, and policy types.

Agentic Policy Control

Continuously understand who the agent is, who owns it, who can access it, and what it’s allowed to do, maintaining clear ownership, least privilege, and accountability across all agent environments.

Dashboard showing a table of timestamps, projects, directions, detected threats, content snippets, and policy names with a navigation sidebar on the left.
Dashboard interface showing deployment logs with timestamps, project names, directions, detected threats, content previews, and applied policies.
Agent Security Graph
Guardian Agent

Capsule acts as the enterprise’s intelligent, always-on guardian agent, continuously discovering, observing, and securing AI agents across the organization while proactively detecting threats, vulnerabilities, and suspicious behavior in real time.

Dashboard interface showing a table with columns for Timestamp, Project, Direction, Threats detected, Content, and Policy, with various security threat labels and statuses.
Agent Security Graph
Agent Security Graph

The Capsule Agent Security Graph maps how agents think, act, and interact at runtime by analyzing relationships between agents, tools, data, and actions—revealing risky paths, control gaps, and emerging threats in a clear, intuitive view.

Screenshot of a dashboard showing a table with columns for Timestamp, Project, Direction, Threats detected, Content, and Policy, listing multiple entries with various threat detections like Moderated content, PII, Prompt attack, and Unknown links.
Agent Security Graph
Deep Observability

Gain deep, real-time visibility into agent behavior, including actions, decisions, and execution paths—providing continuous insight into how agents operate in production and enabling faster investigation, governance, and safe scaling.

Dashboard table showing timestamps, projects, input/output directions, detected threats like moderated content and unknown links, content snippets, and policy types.
Agent Security Graph
Runtime Protection

Enforce security and governance policies in real time, before actions are executed. Capsule detects and blocks unsafe, unintended, or risky agent behavior in real time, preventing incidents without slowing agents or engineering teams.

Dashboard showing a table of timestamps, projects, directions, detected threats, content snippets, and policy names with a navigation sidebar on the left.
Agent Security Graph
Agentic Policy Control

Continuously understand who the agent is, who owns it, who can access it, and what it’s allowed to do, maintaining clear ownership, least privilege, and accountability across all agent environments.