Tiresias sees threats.
Never data.
A self-hosted zero-trust proxy that governs what your AI agents can do with their memory and MCP backends. Deny-by-default policy, tamper-evident audit - and your data never leaves your store.

AI agents are the new attack surface
Every autonomous agent is an identity without governance. They call APIs, access data stores, and communicate with other agents - all with implicit trust and zero audit trails. Traditional IAM was never built for this.
0%
of enterprises deploy AI agents in production
0
implicit permissions per agent on average
0%
visibility into agent-to-agent traffic
Statistics are illustrative, based on industry trends and research estimates.
The Soul* Platform
End-to-end agent governance. From identity to detection to enforcement - in front of the backend you already own.
SoulAuth
Agent Identity & Zero-Trust Access
Cryptographic agent identity, capability-token introspection, and RBAC from platform down to individual agents - with OIDC single sign-on for the humans who govern them. No standing permissions. No implicit trust.
Explore SoulAuthSoulWatch
Behavioral Anomaly Detection
Behavioral detection for your agent fleet. Per-agent baselines, anomaly signals, and automated quarantine of misbehaving agents - every action recorded in the tamper-evident audit trail.
Explore SoulWatchSoulGate
Deny-by-Default Policy Enforcement
The enforcement point between your agents and their memory / MCP backends. Deny-by-default decisions, prompt-injection screening, and usage metering with a cost governor - no LLM in the decision path.
Explore SoulGateHow it works
Three layers of defense. One unified platform.
STEP 01
Identity
Every agent gets a cryptographic SoulKey identity, verifiable across your entire fleet - with RBAC and OIDC SSO for the humans who govern it.
STEP 02
Authorize
Deny-by-default policy evaluation on every request to your memory and MCP backends. Deterministic decisions - no LLM in the decision path.
STEP 03
Protect
SoulWatch behavioral anomaly detection with automated quarantine, plus a budget governor that stops runaway usage before it stops you.
We can't see your data. That's the point.
Tiresias-ZT is self-hosted and bring-your-own-backend. The proxy runs in your infrastructure, decisions happen at the request layer, and your agents' memory never leaves your store. We govern access - we never take custody of your data.
- Self-hosted: the proxy and your data live in your infrastructure
- Bring your own backend - memory never leaves your store
- Sovereignty gates: never-cloud content never leaves a cloud instance
- Designed with GDPR Article 25 principles in mind
DENY BY
DEFAULT
Built for the enterprise
Production-grade security infrastructure, not another proof-of-concept.
Policy-as-Code
Define deny-by-default authorization policies as code, version them, and roll them out monitor-first before enforcing. No drift, no surprises.
Tamper-Evident Audit
Every decision is SoulKey-signed with hybrid Ed25519 + post-quantum ML-DSA signatures. Append-only, exportable, and independently verifiable.
Metering & Budget Governor
Per-tenant usage metering with a cost governor that cuts off runaway agents before they burn your budget.
Multi-Tenant RBAC
A full role hierarchy - Platform, MSSP, Tenant, Agent - with OIDC SSO. Each tenant gets its own policy namespace and audit trail.
Automated Quarantine
SoulWatch flags behavioral anomalies and can isolate a misbehaving agent automatically. Policy-driven and audit-logged.
Compliance Ready
Architecture designed with data protection by design principles. Exportable audit logs and policy versioning support your compliance journey.
Ready to secure your AI agents?
Tiresias-ZT is in private beta. Request a design-partner slot.
Pricing is being finalized during the beta — a free community tier is planned. Design partners get direct access to the engineering team.