One sentence
Astrix secures the credentials and admits the agent identity. Cyphrex proves the act: who approved, what was touched, and what stayed blocked.
Who each is for
Astrix
NHI and agent identity security
Astrix discovers and governs the API keys, service accounts, and OAuth tokens AI agents use, from provisioning to decommissioning, and detects compromised credentials and out-of-scope actions. Astrix is part of Cisco (acquisition completed June 29, 2026). Capabilities are integrating into Cisco Identity Intelligence, Secure Access, Duo, and Splunk.
Discover → lifecycle → detect.
Cyphrex
Compliance infrastructure for agents
A decide-and-prove layer for teams who will instrument an agent or route its MCP traffic, and who need each decision kept as tamper-evident evidence.
Enforce the action → tamper-evident evidence.
Capability comparison
| Capability | Astrix (Cisco) | Cyphrex |
|---|
| NHI + AI agent discovery (keys, service accounts, OAuth) | Strong fit | Per-agent identity you register |
|---|
| Agentic access & lifecycle (provision → decommission) | Strong fit | Not an NHI lifecycle suite |
|---|
| Threat detection on credential abuse / out-of-scope actions | Strong fit | Policy violations + alerts; not ITDR/SOC |
|---|
| Secrets management across vaults & cloud | Strong fit | Not Cyphrex’s job |
|---|
| Runtime policy on instrumented agent / MCP actions | Adjacent (identity & access) | check() + MCP gateway |
|---|
| Tamper-evident, independently verifiable decision record | Identity / activity visibility in Cisco security stack | Ed25519-signed packages + public /verify |
|---|
| Who approved / what touched / what stayed blocked | Who/what identity acted | Compliance receipt for auditors, insurers, legal |
|---|
When Astrix is the better fit
- The pain is invisible non-human identities and agent credentials: keys, tokens, and service accounts.
- You need lifecycle governance from provision to decommission.
- The buying center is IAM, NHI, or the Cisco security stack: Identity Intelligence, Duo, Secure Access, and Splunk.
- You want threat detection on compromised credentials and out-of-scope agent use.
- You are already a Cisco shop consolidating agent identity into the platform.
When Cyphrex is the better fit
- Legal, risk, or compliance asks for a receipt a third party can verify.
- Builders will instrument agents or route MCP through a gateway and want decide, enforce, and prove in one path.
- You already know which non-human identity the agent is, or Cisco and Astrix will tell you. The missing piece is the durable decide-and-prove trail.
- Regulated buyers want a signed, hash-bound action history, not only identity telemetry.
- Blocked steps are recorded as blocked, with the rule and timestamp, as compliance infrastructure.
Better together
Astrix and Cisco answer which non-human identity the agent is, and whether that credential is healthy. Cyphrex answers what that actor was allowed to do on each step, and proves it.
What Cyphrex evidence proves
What a signed report contains
- Agent
- Action and resource
- Allowed or blocked
- Rule and violations
- Timestamp
How verification works
Every Cyphrex evidence package is signed with Ed25519 and bound with SHA-256. On /verify, someone can check it without a Cyphrex login.
Compliance mapping
Evidence artifacts map toward SOC 2 / EU AI Act / HIPAA / SR 26-2 style reporting — not certification; details on Trust.
Limits
Cyphrex signs what flows through the SDK check() or the MCP gateway. It does not invent coverage for a path it never saw. Cyphrex is not your auditor.
Frequently asked
Is Cyphrex an Astrix alternative or a complement?▾
Often a complement. Astrix secures the credentials and admits the agent identity. Cyphrex proves what that actor was allowed to do on each step. Cyphrex does not replace Astrix or Cisco identity security.
Can you still buy Astrix as a standalone product?▾
Standalone new-license sales ended June 30, 2026. Existing customers continue. New licenses are through Cisco, and Astrix capabilities are integrating into Cisco Identity Intelligence, Secure Access, Duo, and Splunk.
Can a third party verify a Cyphrex decision without a Cyphrex login?▾
Yes. A Cyphrex package is Ed25519-signed and SHA-256-bound. On /verify, someone can check the decision without a Cyphrex login.