Platform

One layer.
Real control.

Cipherion puts AI agents and the connections they make under one layer of policy and evidence. Sentri governs what agents do, Gatekeeper enforces where devices connect, and decisions land in a tamper-evident record.

The parts, and what each one does today.

Live means we have watched it work in production. In development means built and tested, and not yet running for customers.

Live

Sentri

AI governance and chain of custody

Checks each tool call an enrolled agent makes against that agent's policy, refuses anything outside it, and holds sensitive actions for a person to decide.

Explore Sentri
Live

Gatekeeper

Enforcement at the resolver

Blocks known phishing, scam, malware and tracking sites for homes, and can switch off AI assistants on one device without touching the rest of the household.

Explore Gatekeeper
In development

EYEQ

Behavioral intelligence

Learns each agent's normal and proposes a review when behavior drifts. It advises; people decide.

Explore EYEQ
In development

Identity integrations

Who the agent acts for

Ties an agent's action to the person it acts for, using the identity provider you already run. Verifying assertions from external identity providers is in development.

Ask about your identity provider
Live

Evidence

Records you can check

Each enforcement service writes hash-chained records. Change one row and verification points to the row where the chain breaks.

How the record works

How it fits together.

  1. 01

    Connect

    An agent host is enrolled with its own certificate, and its outbound traffic is limited to the Sentri gateway. Going around the gateway cuts the connection and raises an alert.

  2. 02

    Decide

    Each tool call is checked against the agent's policy: who, what, when, where, why and how. Outside the policy, it is refused. Sensitive, it waits for a person.

  3. 03

    Record

    The decision, the reason and the operator who acted are written to a hash-chained record you can verify later.

Where the edges are.

We would rather you hear the limits from us.

  • Sentri controls agents that route through its gateway. An agent on a host you have not enrolled is outside its reach.
  • Resolver controls act on names. A device that connects straight to an IP address skips the resolver, and a connection that is already open stays open until it reconnects.
  • Automatic containment across systems is research, not product. Today a person contains and releases, and the record shows who did it and why.

See what your agents do. Prove why. Decide what happens next.

Talk with the people who build and run Cipherion, in Dallas.