The data an AI agent reads is attacker-writable: an instruction you trust and a sentence an attacker planted look identical to the model. Permissions decide what an agent may do. Aeguard proves what it actually did, and whether it stayed inside the rules you declared.
In beta on macOS and Windows. Apple Endpoint Security entitlement granted. Detect-only, on-device.
An AI agent reads its instructions, the user’s request, and whatever data it retrieves as one stream of text. It cannot reliably tell an instruction you trust from a sentence an attacker planted in a document, an email, a webpage, or a tool description. So the data your agents act on is, in practice, attacker-writable.
Most programs invest in identity, permissions, and access scopes for their agents. That is necessary. But permissions only describe what an agent is allowed to do. They say nothing about what it actually did, or whether the input that triggered it was legitimate. When something goes wrong, every gate shows green and you still cannot answer the questions that matter: what did it do, on whose instruction, and can you prove it?
A permission model with no record is hard to tell apart from no control at all.
In June 2025, Gartner predicted that guardian agents, software whose job is to supervise other AI agents and keep their actions inside defined goals and boundaries, will grow to 10 to 15 percent of the agentic AI market by 2030. When an analyst gives a control its own category, it usually stops being optional. The gap is real, and the market is now paying to close it.
Source: Gartner, June 2025.
Built for the organization whose answer is not to ban the agents, but to prove they stayed in bounds. Aeguard sits above your agents and checks what they do.
Reads the rulebook you declare
Permission rules (allow, deny, ask), MCP tool grants, trusted-folder scopes, and the agent’s own CLAUDE.md / AGENTS.md. Aeguard knows what each agent said it was allowed to do.
Returns a verdict for every action
HONORED, VIOLATION, UNDECLARED, or UNVERIFIABLE, attributed to the exact agent, per machine, over time. Policy becomes evidence, not a promise.
Writes it to a tamper-evident log
An append-only BLAKE3 hash-chain on the machine itself, chain-head mirrored to the Keychain. Any edit, deletion, or database swap is detectable.
Detect-only and on-device
It observes and records, it does not block, so it runs alongside your EDR. SQLCipher-encrypted, no keystroke capture, no cloud dependency: a witness that never becomes a new point of failure or a new place your data can leak.
If the honest answer is no, that is the thing to fix before your estate gets larger. Aeguard gives you an attributable, tamper-evident record: what each agent did, on whose instruction, and proof the log is intact, in language your board, auditor, and insurer can rely on.
Apple Endpoint Security entitlement granted
Beta on macOS and Windows
Detect-only, runs alongside your EDR
Local-first, SQLCipher-encrypted, air-gap capable
Book a 30-minute pilot scoping session, or access Aeguard on your own machines.


