Zenity
Agent security and governance
A platform for security teams who need to find agents they did not build, score how those agents are configured, steer what they can do at runtime, and investigate threats.
Discover → posture → runtime → detect.
Compare
Zenity is see-and-steer.
Cyphrex is decide-and-prove.
Zenity surfaces and steers the agent; Cyphrex proves who approved the step, what was touched, and whether a blocked action stayed blocked.
Zenity
A platform for security teams who need to find agents they did not build, score how those agents are configured, steer what they can do at runtime, and investigate threats.
Discover → posture → runtime → detect.
Cyphrex
A decide-and-prove layer for teams who will instrument an agent or route its MCP traffic, and who need each decision kept as tamper-evident evidence.
Enforce the action → tamper-evident evidence.
| Capability | Zenity | Cyphrex |
|---|---|---|
| Agent discovery / inventory across SaaS, cloud, endpoint | Strong fit | Not the primary job (sees what you instrument / route) |
| Pre-deploy posture (config, permissions, integrations) | AISPM | Policy profiles on registered agents; not a full AISPM suite |
| Runtime allow / block | Runtime Boundaries (allow / block / quarantine) | check() + MCP gateway before execution |
| Identity correlation (IdP ↔ agent) | AI IAM (Okta / Entra) | Per-agent identity |
| Threat detection / response | AIDR + Guardian Agents | Policy violations + alerts; not an AIDR/SOC platform |
| MCP tool governance | Native MCP Security | MCP gateway: check, block, same audit trail |
| Tamper-evident, independently verifiable evidence | Observability / findings / API export | Ed25519-signed packages + public verify |
| Who approved / what touched / what stayed blocked | Session/activity visibility for security teams | Designed as the compliance receipt for auditors, insurers, legal |
Zenity, or a platform like it, for discover, posture, and broad runtime steering. Cyphrex for the cryptographically checkable decision record on the actions that matter. The two jobs are different, and they can sit on the same estate.
Every Cyphrex evidence package is signed with Ed25519 and bound with SHA-256. On /verify, someone can check it without a Cyphrex login.
Evidence artifacts map toward SOC 2 / EU AI Act / HIPAA / SR 26-2 style reporting — not certification; details on Trust.
Cyphrex signs what flows through the SDK check() or the MCP gateway. It does not invent coverage for a path it never saw. Cyphrex is not your auditor.
No. Discovery of agents you did not build is Zenity’s strength. Cyphrex sees what you instrument with the SDK or route through the MCP gateway.
No. A Cyphrex package is Ed25519-signed and SHA-256-bound, so someone can check the decision without a Cyphrex login. What that check covers is on the Trust Center.
Yes. Allowed or blocked is part of the decision record, with the agent, action type, resource, rule, and timestamp.