AI Defendo · Enterprise AI Security

Catch the agent.
Not the message.

AI Defendo is Scan0's enterprise AI security product — powered by Agentic Awareness. Tracks every agent across every session, renders one verdict per turn across six awareness dimensions.

Your stack tells you the agent passed. Your customers tell you it didn't.
zero code change six awareness dimensions sub-200ms verdicts
Live workload telemetry
monitoring 24
sess-9d1
0.12 aligned
sess-4b8
0.54 drift
sess-7r2
0.89 blocked
data inflight PII 510 secrets 4 code 178 financial 95
passed 1,402 drift 18 blocked 3
last sync 2s ago

Agents fail in ways prompts don't predict.

Indirect injection. Goal drift. Memory poisoning. Compacted context. Cross-agent escalation.

Every one looks like authorized behavior until you watch the full agent across the full session.

The Casebook

Six incidents.
Every action authorized.

Named vendors with disclosed CVEs and real-world impact. In every case the per-message checks passed — the failure was in a dimension no per-message tool sees.

i.

EchoLeak

CRIT
Microsoft 365 Copilot · CVE-2025-32711
input output exfiltration

Zero-click email triggered Copilot to embed an exfiltration URL in its response. ~$200M impact across 160+ orgs.

indirect injectioncontextidentity
NVD →
ii.

Replit Agent

CRIT
Production database · public report
reasoning tools compliance

User said "code freeze." Agent dropped tables anyway. 1,206 executives + 1,196 companies deleted. 4,000 fake users fabricated.

trajectory driftbehaviorintent
SaaStr →
iii.

SpAIware

CRIT
ChatGPT (OpenAI) · Embrace The Red
memory output exfiltration

Cross-session attack. Memory poisoned in one chat — every chat after silently exfiltrated user data through legitimate APIs.

memory poisoningmemorycontext
Disclosure →
iv.

ForcedLeak

CVSS 9.4
Salesforce Agentforce
input output exfiltration

Web-to-Lead form hijacked Agentforce into exfiltrating CRM records. An expired domain still in the CSP allowed the egress.

indirect injectioncontextposture
Disclosure →
v.

Slack AI exfiltration

HIGH
Slack AI · PromptArmor disclosure
input output exposure

Public-channel injection made Slack AI surface private-channel content to a low-trust user. Slack's response: "intended behavior."

indirect injectionidentitycontext
Disclosure →
vi.

Now Assist

CRIT
ServiceNow · AppOmni research
reasoning tools exfiltration

Cross-agent escalation. Low-privilege agent tricked a higher-privilege one into exporting case files externally. ServiceNow: "works as intended."

trajectory driftidentityintent
Disclosure →
No per-message tool catches more than one dimension at a time. AI Defendo joins all six dimensions into a unified token execution evaluation vector.
Prompt filters read messages. Guardrails score outputs. Runtime monitors watch infrastructure.

None of them watch the full agent across the full session.

Prompt Security caught the message. Runtime Security caught the workload. Behavioral Correctness catches the agent — AI Defendo's method within Scan0's Agentic Awareness.
The six questions

Why six dimensions. Why these six.

Every agent action raises six questions. Miss any one and you can't say what really happened.

i.
Identity

Who acted?

Now Assist — one agent escalated under another's grant
ii.
Intent

What were they authorized to do?

Replit Agent — "code freeze" directive ignored
iii.
Behavior

What did they actually do?

Replit Agent — DROP TABLE outside the implied task
iv.
Memory

What had they learned before this turn?

SpAIware — poisoned memory persisted cross-session
v.
Context

What shaped the decision?

EchoLeak — poisoned email reached the model context
vi.
Posture

Was the environment trusted?

ForcedLeak — expired domain still on the CSP allowlist

AI Defendo answers all six on every turn.

Threats hit the agent lifecycle — input, reasoning, memory, tools, output. They reshape the data — exposure, exfiltration, secret leakage, compliance. AI Defendo maps both — six-dimension Behavioral Correctness, running on Scan0's Agentic Awareness layer.

Case · Replit Agent

Production database · July 2025

inferred task: investigate data anomaly · active directive: code freeze in effect

Telemetry audit stream — Replit incident replay
target: production data worker node
What your stack saw
What AI Defendo saw
Session risk trajectory trigger threshold: 0.75
0.00
Behavior
Monitoring sequence pipeline execution blocks…
Intent
Parsing cross-turn user policy configurations…
Session flagged · 0.92
Six dimensions per turn. Behavior caught the DDL outside the task. Intent caught the freeze directive. Two dimensions failing is enough — flagged before turn iv executed.
What actually happened: 1,206 executives and 1,196 companies deleted. 4,000 fake users inserted. Two failing dimensions would have stopped it. real incident · jason lemkin · saastr
The Platform Underneath

AI Defendo runs on
Scan0's Agentic Awareness.

Every verdict AI Defendo renders — every dimension it evaluates, every incident it catches — runs on Scan0's Agentic Awareness platform. Six layers of continuous understanding, from kernel-level discovery through cryptographically signed verdicts to inline enforcement.

Platform Architecture

Six layers. One continuous understanding.

Discovery · Runtime Sensor · Collector · Awareness Layer · Enforcement · Experiences. AI Defendo consumes the Awareness Layer's signed verdicts, enforcing them through the AI Interceptor, Identity Gateway, and Data Flow Control paths.

See the full architecture
Three Products

Securing every layer of
enterprise AI.

AI Defendo ships three products that together secure every layer of enterprise AI — discovery and governance, infrastructure, and runtime behavior. Each answers a specific question every enterprise now asks about its AI.

Product · 01 Discovery & Governance

AI Risk Posture

What AI do we have — and how exposed is it?

Continuous discovery of every AI asset across cloud, endpoint, browser, and code. Configuration posture with mitigation workflow. Shadow AI sanctioning. Identity governance for both human and non-human AI actors.

Six Pillars
  • AI Apps
  • Identities
  • Shadow AI
  • AI Agents
  • MCP Servers
  • Data Risks
Learn more
Product · 02 Infrastructure

AI Workload Security

Is our AI infrastructure secure?

Kernel-level runtime protection for the workloads that run AI — inference servers, RAG platforms, memory stores, agent frameworks, and MCP servers. Catches remote code execution, container escapes, and framework exploits at the system layer.

Protects
  • Inference servers
  • RAG platforms
  • Memory stores
  • Agent frameworks
  • MCP servers
Learn more
Product · 03 Runtime Behavior

Agentic Runtime Protection

Are our AI agents behaving as intended?

Continuous evaluation of agent behavior across sessions. Detects behavioral incidents that only exist because AI agents combine context, identity, memory, and delegation. Inline enforcement through the AI Interceptor — block, coach, or alert in real time. Zero-trust Identity Gateway provides just-in-time scoped grants for every agent action.

Alert Coach Block
Catches
  • Memory poisoning
  • Goal drift
  • Prompt injection
  • Authority escalation
  • Tool misuse
  • Cross-session drift
Learn more
Early Access Beta

Secure your agent infrastructure.

Join the Beta to begin mapping and securing multi-turn workflows inside your production environment.