For Security and Infosec Teams
Test What Agents Do.
Limit What They Reach.
Probe vendor agents, turn findings into policies, and replay attacks to test the fix. Set each agent’s access through your directory.
The Details Your Architecture Review Depends On
Security teams need to test agent behavior, verify fixes, and contain access – even when they don’t own the code.
Gaps in testing, follow-through, and permissions make each of those tasks harder.
Untested Agents
Vendor agents and no-code builds go live without a security test. Scanners need source code and SDKs need an install, and these agents offer neither.
Reports Without Replay
Findings sit in a PDF until the next test, fixes land weeks later, and no one replays the original attack to confirm the gap is actually closed.
Inherited Access
Agents run on shared provider keys with whatever access the service account had, and revoking one means hunting down every copy.
Your Perimeter, Your Controls
The Details Your Architecture Review Depends On
Review deployment, identity, data handling, and failure behavior, with clear documentation of certifications, access controls, and audit records.
Self-Hosted Deployment
Runs entirely inside your own perimeter. Model calls go only to the providers you choose, never to Lumenova AI.
Directory Identity
People and agents sign in through Entra ID or any OIDC provider. Remove someone from a directory group, and their gateway access goes with it.
In-Process Masking
Sensitive fields are masked in your process before traces are sent, including spans from third-party instrumentation.
Failure Behavior
Platform policy fails closed. The SDK fails open by default and can be set to fail closed. Detection models fail open.
Certifications
Lumenova AI holds a current SOC 2 Type II report and ISO 27001 certificate, both independently audited.
Roles and Audit
Custom roles export as JSON for GitOps review. The audit log is append-only by application design, with retention you configure.
How It Starts
- Your team
Name an endpoint
One agent endpoint you can clear for testing, including one a vendor runs.
- Platform
Probe
Black-box probes run with the credentials you supply. Nothing is installed on the target.
- Platform
Findings
Each finding comes with the request and response that proved it.
- Together
Fix and replay
Fix a finding with policy, then replay the attacks that worked to see whether they now fail.
Frequently Asked Questions
Each agent gets an identity from your directory and reaches only what its approved use case allows. Per-key tool permissions are checked before a request reaches an MCP server. Access follows directory groups, so removing someone from a group removes their gateway access, with no separate list to maintain.
Import MCP servers from npm and PyPI, score them for known vulnerabilities, and set rules that block risky servers automatically. The dependency graph shows which agents rely on each server, and anything that disappears upstream is flagged as deprecated rather than silently removed.
Revoke access through the directory or the key, and the call history still shows which agent did what, even after the key is deleted. Hunt past sessions for signs of injection or exfiltration, and trace each suspicious request across the agents and tools it touched.
Agents that appear in gateway traffic without a registry entry are held until someone reviews them, and keys that keep getting flagged are revoked once they cross a threshold you set. Agents that never touch the gateway aren’t visible there, so routing traffic through it is what gives you coverage.
Traces are standard OpenTelemetry and can flow to Splunk or other tools you already run, and alerts can go out through webhooks and ITSM integrations.