Today we are launching Embroidery. We collect data about everything your AI agents are doing, and use LLMs to monitor and alert on security threats, misuse, policy violations, and more. In other words, we use AI to watch your AI so you know what’s going on.

But AI agent security is such a messy and evolving area, so we want to say more than that. Everyone has ideas about how to secure agents, and there’s a wide range of commercial offerings claiming to solve the problem. It is therefore worth explaining our view of this area, and why we built this the way that we did.

Overview of Agent Security

Fundamentally, we believe that the best way to secure agents is to give them set, deterministic boundaries and then allow them to act freely and unrestricted within that area. To do that, it is important to have good visibility so you know if something goes wrong, and also so you can get good feedback on how you can adjust the boundaries you’ve set.

Notably absent from that setup is any sort of “classifier” model that promises to scan for dangerous actions and block them in real time. We strongly believe that is a bad approach. You’re paying for leading AI models, then letting far less intelligent classifiers with less context and less time to reason decide on the fly what the model can and can’t do. That doesn’t make any sense.

We also don’t believe in managing agent permissions at runtime. If your agent can request access and have it granted via some non-human interaction, then it should be treated as having those permissions all along. Of course, this doesn’t mean all agents and subagents should have long-lived tokens, but it means that the dynamic granting of access shouldn’t be treated as a security boundary.

Where Does Embroidery Fit In?

Realistically, AI agent security has four main components:

  • Discovery: What AI agents do you have and what content (skills, MCP servers, etc.) are they using?
  • Isolation: What resources does the agent have access to?
  • Permissions: What can the agent do with those resources?
  • Monitoring: What data do you have visibility into, and do you get alerts to the types of behavior you’re interested in?

Embroidery is a discovery and monitoring solution. That is to say, we reveal which agents and resources your organization is running (and give you control over them), and we monitor everything going on to alert you to various types of threats and misuse that you would want to know about.

Why Use AI to Secure AI?

There are a lot of jokes within the security community about the use of AI to secure AI; it is, to some, a snake eating its own tail or a way for the AI labs to push more token consumption. We don’t believe that to be correct. The reality is that LLMs are good at reasoning, and reasoning is extraordinarily useful for detection.

Google DeepMind has written about this and made the same argument. In short, getting the most out of AI means giving agents a great deal of freedom, and the line between safe and dangerous, intended and unintended, and benign and malicious is determined based on the overall context and purpose. LLMs can make those determinations in ways that other solutions cannot.

This is a departure from the traditional infosec argument in favor of deterministic detection combined with LLMs for triaging alerts. We strongly believe deterministic detection in this context misses some of the most important threats, and fails to account for the enormous and evolving variety of risks.

Why Trust Us?

AI agent security is rapidly changing. Every few months we get an entirely new use case and a new category of risks to worry about. We recognize that this area is going to continue to develop, so it is important that we stay in front of new risks and threats.

Our CEO, Zack Korman, is widely recognized for his security research work in this area. He is known for his work on MCP security, malicious use of agent skills, and using AI to escape agent sandboxes. So he knows how to break AI agents, which means he has a good idea of how to secure them too.

But just as importantly, all three cofounders at Embroidery have experience leading tech teams, which means we understand the challenges developers face. Zack has previously held roles including CTO and Director of Tech and Product. Carina Eikaas, our COO, has previous experience as the VP of Data and AI at a cybersecurity company, and Director of Data at a media company. And our CTO, Kasper Rynning-Tønnesen, has been the VP of Engineering at a cybersecurity company, as well as Lead Architect at a previous company.

You can read more on the rest of our website, so we will leave it at that for now. If you find this interesting, please leave your email address so we can get in touch.