Control what AI agents can access, do, and remember.
SteelCipher is building the security control plane for AI agents. We help companies observe agent activity, enforce runtime policies, track sensitive data movement, and produce audit evidence before agents are approved for production.
Currently building with early design partners. Replace founder@steelcipher.com with your real email before publishing.
AI agents are becoming production software workers. Security teams can’t govern them like chatbots.
Agents now retrieve data, call tools, use RAG, write memory, modify systems, and trigger downstream actions. That creates a new runtime security and privacy problem.
Excessive tool access
Agents often get broad permissions to databases, SaaS apps, code repositories, messaging tools, and internal APIs before anyone can see what they actually do.
Sensitive data moves everywhere
Customer data can flow through prompts, outputs, logs, vector databases, memory stores, tickets, Slack messages, and generated summaries.
No clear audit trail
When something goes wrong, teams need to reconstruct which agent acted, what it accessed, what was allowed or blocked, and where the data went.
The control plane between agents and the systems they use.
SteelCipher sits in the agent runtime path through SDK wrappers, MCP/tool gateways, RAG middleware, memory connectors, and downstream integrations.
Runtime visibility
Capture tool calls, RAG retrievals, memory reads/writes, prompts, outputs, policy decisions, and downstream actions in one agent activity timeline.
Policy enforcement
Allow, block, redact, require approval, downgrade to read-only, or terminate risky sessions before agent actions execute.
RAG and memory governance
Control what agents can retrieve from private knowledge systems and what they are allowed to store in long-term memory.
Data lineage and deletion evidence
Track sensitive data across agents, tools, prompts, outputs, memory, vector stores, logs, and SaaS apps to support audits and deletion workflows.
Where SteelCipher sits
We make companies route agent tool calls, retrievals, and memory writes through a governed control layer.
Built for teams putting agents near sensitive data.
Support agents
Control access to customer records, policy docs, ticket histories, CRM data, external replies, and memory writes.
Internal operations agents
Govern agents that create tickets, update SaaS systems, search documents, summarize records, and escalate work.
Coding and DevOps agents
Audit tool usage, repo access, command execution, CI/CD changes, secrets exposure, and high-risk production actions.
Founder-led, security-first
SteelCipher is founded by Ramit Saraswat, a software engineer and cybersecurity research scientist with 10 years in the industry focused on AI and medical device cybersecurity.
Seeking design partners
We are looking for teams deploying AI agents that touch sensitive data, RAG systems, memory stores, tool calls, customer records, or business-critical workflows.
Deploying agents into production?
We’d like to learn about your workflow and show how SteelCipher can make agent activity visible, enforceable, auditable, and deletion-ready.
email@steelcipher.com