Runtime security for production AI agents

Control what AI agents can access, do, and remember.

SteelCipher is building the security control plane for AI agents. We help companies observe agent activity, enforce runtime policies, track sensitive data movement, and produce audit evidence before agents are approved for production.

Currently building with early design partners. Replace founder@steelcipher.com with your real email before publishing.

support-agent queried customer record
PII detected: email, account ID • policy: limited read
Allowed
RAG retrieved renewal policy
approved source • entered model context
Logged
agent requested payment details
financial data • requires manager approval
Review
memory write attempted
customer-specific PII in long-term memory
Blocked
audit timeline generated
tool calls, retrievals, memory, output, lineage
Ready

AI agents are becoming production software workers. Security teams can’t govern them like chatbots.

Agents now retrieve data, call tools, use RAG, write memory, modify systems, and trigger downstream actions. That creates a new runtime security and privacy problem.

01

Excessive tool access

Agents often get broad permissions to databases, SaaS apps, code repositories, messaging tools, and internal APIs before anyone can see what they actually do.

02

Sensitive data moves everywhere

Customer data can flow through prompts, outputs, logs, vector databases, memory stores, tickets, Slack messages, and generated summaries.

03

No clear audit trail

When something goes wrong, teams need to reconstruct which agent acted, what it accessed, what was allowed or blocked, and where the data went.

The control plane between agents and the systems they use.

SteelCipher sits in the agent runtime path through SDK wrappers, MCP/tool gateways, RAG middleware, memory connectors, and downstream integrations.

Runtime visibility

Capture tool calls, RAG retrievals, memory reads/writes, prompts, outputs, policy decisions, and downstream actions in one agent activity timeline.

Policy enforcement

Allow, block, redact, require approval, downgrade to read-only, or terminate risky sessions before agent actions execute.

RAG and memory governance

Control what agents can retrieve from private knowledge systems and what they are allowed to store in long-term memory.

Data lineage and deletion evidence

Track sensitive data across agents, tools, prompts, outputs, memory, vector stores, logs, and SaaS apps to support audits and deletion workflows.

Where SteelCipher sits

We make companies route agent tool calls, retrievals, and memory writes through a governed control layer.

AI agentOpenAI Agents SDK, LangChain, LangGraph, custom agents, MCP clients, support agents, coding agents.
SteelCipher control planeIdentity, policy engine, sensitive-data detection, runtime gateway, lineage graph, audit timeline.
Tools and dataMCP servers, APIs, databases, RAG systems, vector stores, memory stores, Slack, GitHub, Zendesk, Salesforce.

Built for teams putting agents near sensitive data.

Support agents

Control access to customer records, policy docs, ticket histories, CRM data, external replies, and memory writes.

Internal operations agents

Govern agents that create tickets, update SaaS systems, search documents, summarize records, and escalate work.

Coding and DevOps agents

Audit tool usage, repo access, command execution, CI/CD changes, secrets exposure, and high-risk production actions.

Founder-led, security-first

SteelCipher is founded by Ramit Saraswat, a software engineer and cybersecurity research scientist with 10 years in the industry focused on AI and medical device cybersecurity.

Seeking design partners

We are looking for teams deploying AI agents that touch sensitive data, RAG systems, memory stores, tool calls, customer records, or business-critical workflows.

Deploying agents into production?

We’d like to learn about your workflow and show how SteelCipher can make agent activity visible, enforceable, auditable, and deletion-ready.

Request design partner access

email@steelcipher.com