Security News

Cybersecurity news aggregator

🔓
MEDIUM Vulnerabilities Reddit r/netsec

MCP is becoming a major attack surface here's what we built to govern it

  • What: Assury MoCoP introduces AI agent control plane
  • Impact: Helps organizations govern AI workflows and reduce risk
Read Full Article →

Control What Your AI Agents Do Before They Do It. Zero-trust enforcement at the execution layer. The first execution-layer control plane that governs entire multi-step agent workflows - not just single tool calls. Govern what your agents do - not just who they are. Get Started For Business Leaders Assury MoCoP is the control layer that decides what AI agents are allowed to do inside your company. We govern what agents can do before they take action - so you reduce risk and stay compliant. For Technical Teams Assury MoCoP is a runtime control plane that sits in the execution path between agents and their tools, dynamically governing based on cumulative risk, security zones, intent classification, and identity. Every decision and tool call is inspected before execution - not just logged after the fact. Key Capabilities ✓ Autonomy Levels 0–3: Classify + enforce agent privileges (read-only to root-equivalent) to prevent escalation ✓ Domain Zones: Segment tools/domains (e.g., internal_low → pii_sensitive) and block lateral movement ✓ Multi-step Risk Graph: Track cumulative risk across chains + auto-block anomalous patterns ✓ Intent-based governance: Route agent actions based on intent classification and risk assessment ✓ OTel Full Observability: Complete telemetry on every prompt/tool/decision with enrichment for insights ✓ Tamper-Proof Logs: Immutable S3 export + provenance chains for audit-ready evidence ✓ OPA Granular Policy: Policy-as-code (Rego) for JIT creds, tenant scoping, and custom rules ✓ OWASP LLM Top 10 Compliance: Built-in protections against injection, overreliance, and agency risks ✓ SOC 2 / HIPAA / NIST / ISO 42001 Evidence Export: logs and Artifacts See It In Action Watch MoCoP govern real agent workflows — from intent classification to tamper-proof audit trails — across multiple MCP servers. Live simulation — scenarios cycle automatically every few seconds Dynamic Governance for AI Agents The only control plane that governs entire multi-step agent workflows - not just single tool calls Dynamic Risk Scoring Patent pending The only governance system that tracks cumulative risk across entire multi-step workflows - not just individual tool calls. Risk accumulates as agents act, automatically triggering controls when patterns emerge. Stop multi-step incidents before they escalate. Rego Policy Engine Enterprise-grade policy-as-code Built on Open Policy Agent (OPA), the same policy engine trusted by Google, Netflix, and Microsoft. Write policies in Rego, version control them, and give security teams full visibility without touching application code. Battle-tested technology, not proprietary black boxes. Autonomy Zones & HITL Lateral movement prevention Segment tools and domains into security zones. When agents attempt to cross boundaries or approach risk thresholds, actions automatically pause for human-in-the-loop approval. Like network segmentation, but for AI. Agents can't escalate beyond their assigned privileges. Tamper-Proof Agent Logs OpenTelemetry-native audit trail Every agent decision, tool call, and policy evaluation is captured as OpenTelemetry spans with cryptographic integrity. Stream to your SIEM for security monitoring, feed DFIR investigations, or power your observability stack. Logs that actually tell you what your AI agents did. The only complete audit trail for AI agent activity. Transparent Pricing Simple, predictable pricing - no per-seat licenses Dev Free Get started building and prototyping with AI agents at no cost. ✓ 2 agents ✓ 3,000 calls per month ✓ Control plane and dashboard ✓ Standard audit logs ✓ No credit card required Get Started Most Popular Team $699 /month For teams scaling AI agents across projects and workflows. ✓ 20 agents ✓ 60,000 calls per month ✓ $0.03 per call overage ✓ Everything in Dev ✓ BYOK (Bring Your Own Key) ✓ Email support Get Started Enterprise $2,500 /month For organizations scaling AI agents across teams, products, and public APIs. ✓ Unlimited agents ✓ 120,000 calls per month ✓ $0.015 per call overage ✓ Everything in Team ✓ SSO (SAML / OIDC) ✓ Advanced RBAC and policy packs ✓ Extended audit log retention ✓ Enterprise support and SLAs Get Started Early adopter pricing - subject to change as the platform evolves. Strategic Partner Enterprise Partnership Strategic governance alignment for mission-critical AI systems For organizations where AI agent risk impacts revenue, compliance, or brand - this tier formalizes Assury as a long-term governance partner, not just a vendor. ✓ Full platform access - including future premium capabilities ✓ White-glove deployment & architecture alignment ✓ Executive governance reviews & risk posture analysis ✓ Dedicated support channel & priority engineering access ✓ Roadmap collaboration & early feature access ✓ Formal security & assurance engagement support Contact Sales Pricing FAQ Common questions about our pricing What counts as a call? Do we pay per user or per seat? What happens if we exceed our included calls? W...

Share this article