The Tiresias Platform

One platform, three pillars
of AI agent security

Identity. Detection. Enforcement. Tiresias-ZT governs your agents' access to their memory and MCP backends from inside your own infrastructure - seeing threats, never taking your data.

How the platform works together

AI Agent
SoulAuthIdentity & AuthZ
SoulWatchMonitoring
SoulGateGateway
Resources

Agent requests flow through identity verification, real-time monitoring, and gateway enforcement - end to end.

Better Together

Each product is powerful on its own, but the real magic happens when they work as an integrated platform. Identity feeds monitoring. Monitoring informs enforcement. Enforcement validates identity.

Identity

SoulAuth establishes who an agent is and what it can do. Every action starts with verified identity.

Visibility

SoulWatch monitors what agents actually do against what they should do. Behavioral baselines, anomaly signals, quarantine.

Enforcement

SoulGate enforces deny-by-default policy at the request layer. Bad requests never reach your backend.

Three products. One mission.

Secure every agent, every action, every API call.

SoulAuth

Private Beta

Agent Identity & Zero-Trust Access

Every AI agent gets a durable cryptographic identity. Every action is evaluated against deny-by-default policy. No standing permissions, no over-provisioned tokens, no blind trust.

Learn more

Key capabilities

  • Cryptographic SoulKey identities
  • Zero-trust policy decision point
  • Capability-token introspection
  • Policy-as-code
  • RBAC: Platform → MSSP → Tenant → Agent
  • OIDC single sign-on

SoulWatch

Private Beta

Behavioral Anomaly Detection

Behavioral detection for your agent fleet. Baselines, anomaly signals, and automated quarantine - watching how agents behave at the request layer, not reading your data at rest.

Learn more

Key capabilities

  • Per-agent behavioral baselines
  • Anomaly detection across fleets
  • Automated quarantine
  • Usage metering + budget governor
  • Monitor-first rollout mode
  • SoulKey-signed audit of every action

SoulGate

Private Beta

Deny-by-Default Policy Enforcement

The enforcement point between your agents and their memory / MCP backends. Deny-by-default decisions and injection screening at the request layer - with no LLM in the decision path.

Learn more

Key capabilities

  • Reverse proxy for memory / MCP backends
  • Deny-by-default request evaluation
  • Prompt-injection screening
  • Sovereignty-gated reads
  • Rate limiting & cost governor
  • Full request audit logging

Ready to secure your agents?

Tiresias is in private beta. Request a design-partner slot for early access to the full platform.