One sentence
Rig admits the seat. Cyphrex proves the act: who approved, what was touched, and what stayed blocked.
Who each is for
Rig
Agentic identity protection
A platform for identity teams who need one view of human, non-human, and AI identities, a way to tell an agent session from the person whose credentials it borrowed, and a block that stops the agent without locking out the employee.
Inventory → correlate → distinguish → endpoint enforce.
Cyphrex
Compliance infrastructure for agents
A decide-and-prove layer for teams who will instrument an agent or route its MCP traffic, and who need each decision kept as tamper-evident evidence.
Enforce the action → tamper-evident evidence.
Capability comparison
| Capability | Rig | Cyphrex |
|---|
| Tell human vs AI agent on the same credential | Strong fit (session attribution) | Not the primary job |
|---|
| Identity inventory / graph across environments | Strong fit | Per-agent identity you register |
|---|
| Endpoint block of an agent without locking out the person | Strong fit | Policy check before action in the SDK / gateway path |
|---|
| Identity posture (blast radius, toxic access, remediation) | Strong fit | Not an ISPM suite |
|---|
| Runtime policy on agent actions you instrument / route | Adjacent | check() + MCP gateway |
|---|
| Tamper-evident, independently verifiable decision record | Account and session visibility for identity teams | Ed25519-signed packages + public verify |
|---|
| Who approved / what touched / what stayed blocked | Identity of who acted | Compliance receipt for auditors, insurers, legal |
|---|
When Rig is the better fit
- The audit log still names the person when an agent borrowed their credentials.
- Security needs to block the agent without locking out the employee.
- You want an identity graph across human, non-human, and AI agents: blast radius, toxic paths, and remediation.
- The buying center is IAM, identity security, or endpoint, not compliance evidence packaging.
- You are early in agent adoption and the first gap is which session this is.
When Cyphrex is the better fit
- Legal, risk, or compliance asks for a receipt: who approved the step, what was touched, and whether a blocked action stayed blocked.
- You need evidence a third party can verify without trusting Cyphrex’s UI.
- Builders will instrument agents or route MCP through a gateway and want decide, enforce, and prove in one path.
- You already know which session is an agent, or you will buy a tool that tells you. The missing piece is the durable decide-and-prove trail.
- Regulated buyers want a signed, hash-bound action history, not only identity telemetry.
Better together
Rig answers who is in the seat. Cyphrex answers what that actor was allowed to do, and proves it. The two jobs are different, and they can sit on the same estate.
What Cyphrex evidence proves
What a signed report contains
- Agent
- Action and resource
- Allowed or blocked
- Rule and violations
- Timestamp
How verification works
Every Cyphrex evidence package is signed with Ed25519 and bound with SHA-256. On /verify, someone can check it without a Cyphrex login.
Compliance mapping
Evidence artifacts map toward SOC 2 / EU AI Act / HIPAA / SR 26-2 style reporting — not certification; details on Trust.
Limits
Cyphrex signs what flows through the SDK check() or the MCP gateway. It does not invent coverage for a path it never saw. Cyphrex is not your auditor.
Frequently asked
Is Cyphrex a Rig alternative or a complement?▾
Often a complement. Rig tells you who is in the seat. Cyphrex records what that actor was allowed to do, and proves it. Cyphrex does not replace Rig.
Does Cyphrex tell a human session from an AI agent on the same credential?▾
No. That is Rig’s job. Cyphrex checks policy before each action you instrument or route, and records the decision.
Are blocked actions recorded as blocked?▾
Yes. Allowed or blocked is part of the decision record, with the agent, action type, resource, rule, and timestamp.