Available · SaaS and On-Premise

Cyron API Security

See: kernel-level API security

An eBPF kernel agent copies REST, WebSocket, gRPC and streaming traffic out of band, so nothing is added to your request path. Cyron detects business-logic abuse, account takeover and data leaks, and blocks the source at the kernel.

  • Detection for all ten OWASP API risks
  • Behavioural intelligence, beyond signatures
  • Free plan and published prices; On-Premise by quote
  • System 2 Thinking, a reasoned verdict on borderline events
Available · On-Premise

Cyron AI Security

Measure: security for AI agents

Agent boundary protection for MCP and A2A. It inspects tool lists, tool calls and tool responses, blocks the threat classes you name, and records every detection as evidence.

  • Tool poisoning, rug-pulls and secret exfiltration detected
  • Blocking by threat class and severity, chosen by you
  • Findings classified to the OWASP LLM and Agentic Top 10
  • Fully air-gapped
In development

Cyron AI Compliance

Prove: EU AI Act and ISO 42001

The governance layer, in development. It is being built to consume evidence produced by live measurement, map it to regulatory duty elements, keep a qualified human at the point of judgement, and write the filing itself.

  • EU AI Act and ISO/IEC 42001 duty coverage
  • Evidence graded by how it was obtained
  • Discharges will expire; attestations will void on change
  • Filings will regenerate byte-for-byte from the ledger
How they fit together

Each product feeds the next.

They are sold separately and deploy independently. On your own infrastructure, two of them are already one system. Cyron On-Premise installs Cyron API Security and Cyron AI Security together. One kernel sensor captures API and agent traffic, each product judges its own layer, and the sensor blocks the source. See how the loop works.

LayerProductWhat it answersWhat it hands on
SeeCyron API SecurityWhat is actually reaching my APIs, and which of it is abuse?Behavioural findings and forensic incident reports
MeasureCyron AI SecurityWhat did my AI agents send to their tools and to each other, and what was stopped?Durable findings, each classified to a public standard
ProveCyron AI ComplianceWhich regulatory obligations are discharged, by what evidence, and until when?In development: attested filings and an auditable gap register
Our approach

Security designed from the attacker's side of the table.

Every product starts with a real, underserved gap and an offensive understanding of how it gets exploited. Four refusals hold across all three.

Never the cause of your outage

Cyron API Security analyses a copy of your traffic, so your requests never wait for it. Where Cyron blocks, the block is precise: an attacker’s address, or the agent threat classes you have named.

Never silence as assurance

Where nothing has been seen, we never report “safe”. Cyron AI Security’s transparent control status report shows exactly what is inspected.

Never out of your hands

Both products run on your own infrastructure. Cyron AI Security runs fully air-gapped, with signed offline updates. Prefer a service? Cyron API Security is also offered as SaaS, hosted in Germany.

Never a questionnaire

Cyron AI Compliance is being built so that no obligation is discharged because someone ticked a box. Where only an assertion exists, the filing will say so.

Start with what is available. Shape what is next.

Protect your APIs today with Cyron API Security, evaluate Cyron AI Security on your own servers, or join the list for Cyron AI Compliance.