Skip to main content
Organizations are handing internal knowledge to AI agents faster than they can answer basic questions about them. Airlock records who accessed what, through which tool, on whose behalf — people and agents in one stream — and surfaces the agent decisions worth a second look.

The problem it solves

An agent reads a thousand documents in the time a person reads one, acts on behalf of whoever prompted it, and reaches whatever its network allows. Three questions follow, and most organizations cannot answer any of them:
  • Who was that? An agent session with no identity behind it is an audit gap, not a log line.
  • Where did it go? Data leaves through an agent’s egress as easily as through a person — prompt injection included.
  • Can that decision be trusted? When an agent’s output moves money or closes a case, “it said so” is not a record.

What Airlock does

Capture

Every agent act becomes one identity-attributed event (access, chat, and decisions) from the sandbox, SaaS audit logs, and a push API for agents anywhere.

Detect

Agent decisions are flagged when they cite nothing, report low confidence, or contradict another decision on the same target.

Govern

Roles and self-view, employee notice, and action gates where an agent’s next step cannot be taken back.

Self-hosted

Runs in your VPC. The backend makes no outbound connections.

The agent runtime

Airlock’s own sandbox is the deepest capture surface:

Only this repo

The repo is mounted read-write at /<reponame>. Your home directory, ~/.ssh, ~/.aws, and every other repo simply do not exist inside.

One way out

The sandbox sits on an internal Docker network with no route out. Its only exit is the Airlock proxy — allowlist by default, blocklist when you would rather not gate the team, logged either way.

Every request attributed

Allowed or denied, each connection is logged with the user behind it, plus path, byte counts, and duration.

Your keys stay yours

The agent gets its own isolated home. Credentials live outside every repo, and tokens never enter a container.

Then: from record to review

Every session lands in a store you operate, and the console — login-gated and role-scoped — turns it into a record a security team can review. Non-admins see their own activity, not anyone else’s.

Next steps

Quickstart

Install the CLI and open your first sandboxed, attributed session.

How it works

The capture plane, the review plane, and the boundary between them.

Capture surfaces

The agent runtime, push ingestion for agents anywhere, and SaaS audit connectors.

Detection

Decision flags, and the evidence behind each one.

Console

Timelines, sessions, and the flags review queue.

Governance

Accounts, roles, notice, and egress posture.