RayShield
PlatformHow it worksSolutionsSecurity teamsCISOs and CTOsDevelopersFinancial servicesDesign partnersSecurityCompanyInvestorsGet early accessBook a demo

The platform

Three planes. One source of truth for every agent.

RayShield Aegis gives you visibility, enforcement and central control over AI agents, whatever tools they use and wherever they run.

01Your agents and harnessesClaude Code · Gemini CLI · Cursor CLI · LangChain coming soon · CrewAI coming soon
02RayShield AegisPolicy · isolation · inspection · audit
03Any runtimeLaptop · server · cloud VM · Python
04Your infrastructureData · secrets · networks · internet

Your tools on top. Your infrastructure below. Aegis in between.

Bring your own harness. Aegis doesn’t replace your agent tools. It governs them.

01Your agents and harnessesClaude Code · Gemini CLI · Cursor CLI · LangChain coming soon · CrewAI coming soon
02RayShield AegisPolicy · isolation · inspection · audit
03Any runtimeLaptop · server · cloud VM · Python
04Your infrastructureData · secrets · networks · internet

Plane 1 · Discovery

What AI is running where, and what could it reach?

Aegis finds AI activity across your fleet at three levels of detail:

Network visibility

Without an agent installed, detect AI services from network traffic and see which AI families are in use.

Exact tool identity

With Aegis installed, distinguish Claude Code from Claude Desktop, identify Gemini CLI, and see whether each run is contained.

Contained run detail

See sandbox ID, run history and data volume for every contained run.

Blast radius

See the attack map before anything runs.

Before an agent runs, Aegis reads its policy and maps the networks it can reach, the data it can access, the tools and connectors it can use, and where data could leave. Run it for a single user or a whole role, and fix risk before it exists.

Agent activityENFORCED
AEGISPolicy boundary
AgentToolsDataNetwork
AllowedBlockedRecorded

Plane 2 · Execution

Only what the policy allows. Nothing else. Proven afterwards.

Isolated execution

Every agent run happens inside a fully virtualised environment.

Default-deny network

Outbound connections not in the policy are blocked outright.

Built-in data loss prevention

Pre-built rules stop sensitive data before it leaves.

Secrets stay secret

Credentials are injected at runtime; agents never see the raw value.

Connector firewall

Agents only see connectors your admins approved, each isolated in its own ring.

Tamper-evident logs

Every run produces cryptographically protected logs. If anyone edits them, it shows.

Plane 3 · Fleet control

What’s installed, what’s running, and what needs my attention?

  • Live fleet inventory: every Aegis install, its active policies, what it’s running and when it last checked in.
  • Telemetry per endpoint: prompts, network in and out, commands and detections.
  • Alerts and thresholds: set what matters and get notified by email or push.
  • Your dashboard, your way: rearrange tiles so the analyst and the CISO each see what they need.
  • Trusted-only reporting: only verified environments can report in, so the data can’t be spoofed.

One policy file defines everything an agent can do.

Think of it as a building access card for agents. One plain-text policy sets the operating system, packages, files, allowed connections and writable folders. The same policy works on any runtime. Policies are created centrally and are read-only to users. Tamper with one and it won’t run.

Three ways to create policies, none by hand

  • Describe it. Tell the policy assistant what the agent needs, and it writes a valid policy.
  • Generate it from code. Point Aegis at existing LangChain, Python or TypeScript code and it builds the policy for you.
  • Start from defaults. Ready-made policies for common tools, like Claude Code, out of the box.
aegis terminal
$ aegis run claude-code --src ./my-project --writable$ aegis blast-radius policy.cue$ aegis plan policy.cue

New tools go through you, not around you.

01

Developer requests a connector

For example, Gmail.

02

Aegis checks the request

Known-risky connectors are flagged.

03

Admin approves or denies

Security makes the decision in one place.

04

Policy updates

A centrally controlled policy is pushed to that user automatically.

Access by role, not by exception.

Map roles and teams to the tools, models and connectors they need. Marketing gets Claude Code. Engineering gets Claude Code plus their approved model provider. Nobody gets email access by default.

Bring every agent under one control plane.