For Security and Infosec Teams

Test What Agents Do.
Limit What They Reach.

Probe vendor agents, turn findings into policies, and replay attacks to test the fix. Set each agent’s access through your directory.

For Security and Infosec Teams
Test What Agents Do.
Limit What They Reach.

The Details Your Architecture Review Depends On

Security teams need to test agent behavior, verify fixes, and contain access – even when they don’t own the code.
Gaps in testing, follow-through, and permissions make each of those tasks harder.

Untested Agents
Untested Agents
Vendor agents and no-code builds go live without a security test. Scanners need source code and SDKs need an install, and these agents offer neither.
Reports Without Replay
Reports Without Replay
Findings sit in a PDF until the next test, fixes land weeks later, and no one replays the original attack to confirm the gap is actually closed.
Inherited Access
Inherited Access
Agents run on shared provider keys with whatever access the service account had, and revoking one means hunting down every copy.

Your Perimeter, Your Controls

The Details Your Architecture Review Depends On

Review deployment, identity, data handling, and failure behavior, with clear documentation of certifications, access controls, and audit records.

Self-Hosted Deployment

Runs entirely inside your own perimeter. Model calls go only to the providers you choose, never to Lumenova AI.

Directory Identity

People and agents sign in through Entra ID or any OIDC provider. Remove someone from a directory group, and their gateway access goes with it.

In-Process Masking

Sensitive fields are masked in your process before traces are sent, including spans from third-party instrumentation.

Failure Behavior

Platform policy fails closed. The SDK fails open by default and can be set to fail closed. Detection models fail open.

Certifications

Lumenova AI holds a current SOC 2 Type II report and ISO 27001 certificate, both independently audited.

Roles and Audit

Custom roles export as JSON for GitOps review. The audit log is append-only by application design, with retention you configure.


How It Starts

  1. Your team

    Name an endpoint

    One agent endpoint you can clear for testing, including one a vendor runs.

  2. Platform

    Probe

    Black-box probes run with the credentials you supply. Nothing is installed on the target.

  3. Platform

    Findings

    Each finding comes with the request and response that proved it.

  4. Together

    Fix and replay

    Fix a finding with policy, then replay the attacks that worked to see whether they now fail.


Frequently Asked Questions

Each agent gets an identity from your directory and reaches only what its approved use case allows. Per-key tool permissions are checked before a request reaches an MCP server. Access follows directory groups, so removing someone from a group removes their gateway access, with no separate list to maintain.

Import MCP servers from npm and PyPI, score them for known vulnerabilities, and set rules that block risky servers automatically. The dependency graph shows which agents rely on each server, and anything that disappears upstream is flagged as deprecated rather than silently removed.

Revoke access through the directory or the key, and the call history still shows which agent did what, even after the key is deleted. Hunt past sessions for signs of injection or exfiltration, and trace each suspicious request across the agents and tools it touched.

Agents that appear in gateway traffic without a registry entry are held until someone reviews them, and keys that keep getting flagged are revoked once they cross a threshold you set. Agents that never touch the gateway aren’t visible there, so routing traffic through it is what gives you coverage.

Traces are standard OpenTelemetry and can flow to Splunk or other tools you already run, and alerts can go out through webhooks and ITSM integrations.

Control, Test, and Prove What Your AI Agents Do

This is one piece of Lumenova AI. See how it connects to the rest on your own use case.

Book a discovery call