BeaconAiBook a call
04 — AGENT SECURITY

Your developers already gave an agent a shell.

Agentic tools got installed faster than anyone wrote a policy for them. Every one of them holds a file system, a terminal, and a network connection, and loads code written by strangers. We build the software that watches what those agents do on real machines, and we run the reviews and red teams that tell you where it goes wrong.

APPLICATIONS
Local software you install: monitoring, runtime policy, skill vetting.
SERVICES
Fixed-scope reviews, red teaming, and guardrails your team keeps running.
POSTURE
Findings leave the machine. Raw telemetry never does.
FLAGSHIPLOCAL APP · WINDOWS · GA

Beacon Security — see what your AI agents are doing on your computer

You gave Claude, OpenAI, and Gemini a shell, a file system, and a network. Beacon Security is a local app that watches what they do with it: which agents and skills are installed, what permissions they hold, what they write and where, what they visit mid-conversation, and whether any of it matches known malware. It raises signals; it does not convict.

Monitor
  • Which agents and CLIs are installed, and which are running right now
  • Every skill, plugin, and MCP server they can load, each scored for risk
  • Live file and command activity, read from the agent's own transcripts
Assess
  • SHA-256 of every file an agent wrote, matched against a local reputation list
  • Written-then-executed payloads caught without needing a hash match
  • Elevated processes, browser native-messaging bridges, and over-broad allow-lists
Report
  • One-click HTML report for a security team or a compliance file
  • Optional Sysmon channel for process and network telemetry
  • Nothing leaves the machine — you export findings, telemetry never uploads

The rest of the stack

Watching is the first step. These three close the loop: stop an action before it runs, vet what an agent is allowed to load, and roll both out across a team.

Runtime policyBeta

Beacon Guard

Sits between the agent and the shell. Commands, file writes, and network calls are checked against your policy before they run, not after.

  • Allow-lists per agent, per project, per directory
  • Blocks and asks a human when a rule is ambiguous
  • Every decision logged locally and exportable as evidence
Join the pilot →
Skill and MCP vettingBeta

Beacon Registry

Nothing loads into an agent until it has been audited. Static scan first, then one allow-list for the whole team.

  • Static audit of every skill, plugin, and MCP server
  • Pinned versions, so an upgrade cannot change behaviour quietly
  • One org allow-list instead of one per laptop
Join the pilot →
Team rolloutWaitlist

Beacon Fleet

The same local monitor on every machine, with findings — not raw telemetry — collected into one view for whoever owns security.

  • Per-machine findings, one dashboard
  • Raw telemetry stays on the developer's machine
  • Alerts routed to Slack, email, or your SIEM
Join the waitlist →

What actually goes wrong

Not hypotheticals. These are the findings the engine looks for, because these are the ones that turn up on real developer machines.

  • A skill you installed once now contains a base64 blob and a curl to a pastebin
  • An agent writes six files outside the directory you thought it was scoped to
  • A helper script the agent wrote yesterday matches a known stealer loader
  • The agent's own allow-list has an unrestricted shell entry nobody approved
  • A browser extension talking to a local executable through a native-messaging bridge
  • Credentials read from a config file and posted to an endpoint mid-conversation

And the work we do ourselves

Software tells you what is happening. These three tell you what to do about it, with a fixed price and a stop date like every other engagement we take.

SERVICE 01
From $9k · two to three weeks

Agent security review

We inventory every agent already running in your org, what each one can reach, and where data can leave. No agent inventory survives contact with a real laptop fleet, so we look at the machines.

A ranked findings report with the fix and the owner for each.

SERVICE 02
From $12k · two weeks

Agentic red team

We attack your own agent deployments the way an outsider would: prompt injection through documents and tickets, tool abuse, and exfiltration through whatever channel the agent was handed.

Reproducible attack paths, severity, and what stops each one.

SERVICE 03
From $14k / phase

Guardrails and policy build-out

We design and implement the permission model, allow-lists, approval gates, and audit trail — then hand it to your team with runbooks so it survives us leaving.

A policy your agents run under, and the evidence trail to prove it.

Start with one machine, or one honest review.

Install Beacon Security on a single laptop and see what it finds in an hour, or bring us in for a review of what your org is already running.

Book a security review