AI agents now hold production keys: they read config, run commands and call APIs, and one poisoned ticket can turn an agent into an attacker. Tripwire is the checkpoint every agent tool call passes through, built for security and platform teams running agent fleets in production.
• Prevent: risky sends are held and judged by an AkashML model (labelled rule fallback if slow) before they run, so the secret never leaves.
• Trip: decoy honeytokens catch exfiltration instantly, with no model call.
• Detect: a millisecond ClickHouse funnel over the live stream quarantines an agent that reads a secret, encodes it and sends it out.
• Trace: it finds patient zero (the poisoned input), puts every other agent that read it on heightened watch and denies the attacker's host fleet-wide.
• Cure with proof: a guardrail ships only after it refuses a sandboxed replay of the attack, keeps normal work running and is backtested over ~30M events in under a second; then a human approves it in Guild.
• Explain: an investigator writes the incident report with its own SQL receipts.
Every number on screen comes from a receipt. On 60 labelled development cases (not a held-out test) it caught 30/30 attacks with 0 false positives. Guild-hosted agents and any MCP client are governed by the same checkpoint, and Semgrep scanned our own AI-written code: 1 real finding, fixed.