Skip to content

Defend your systems from
the attack threat of the future.

A poisoned document, a hijacked prompt, an agent that goes wrong. None of them widens what the firm allowed.

The security review

Authority only narrows downward.

Full speed, and nothing opens.

AI does real work across the firm’s systems. The same boundary that lets it move is what shuts these out.

  1. 01

    Prompt injection

    A hidden line inside a client PDF tells the assistant to mail the client list out read as text, and text carries no permission

  2. 02

    Tool poisoning

    A connected tool rewrites its own description to ask for more than it had the tool list was pinned before the work started

  3. 03

    A rogue agent

    An agent asks for a client record outside the work it was registered to run it holds no credential, so the request never lands

  4. 04

    Exfiltration

    The assistant is talked into sending a file to an address nobody approved the firm binds the real recipient, and a person releases it

Caught, restricted, refused.

One click restricts an agent. Its next call comes back refused, and everything else keeps working.

The agent register
Proxara Console
console.proxara.ai/agents
ChatGPTClaudeGeminiProxara Console
Proxara
Coverage
AI Providers
Deployment
Telemetry
Agents
MCP & Connectors
Analysis
Intelligence
Compliance
Activity
Rox, Assistant
Settings
Online
Dana Whitfield
dana@meridian.co
Agent governance

Agents

Every individual agent on the register, recorded from its own traffic the moment it first appears. Each row is one agent with one owner, one home, and its own controls.

7D30D90D1Y
agents4owners3products3blocked1
Claude Code2 agentsProduct view
Claude Code · ws-4f2a91c3Delegated
Avery Chen · FIRM-LT-0142 · observed on the wire
4exchanges9actions25.7ktokensseen Jul 16, 10:24 AM
Claude Code · ws-b81d0c22Delegated
Jordan Lee · FIRM-LT-0077 · observed on the wire
214exchanges890actions413ktokensseen Jul 16, 09:58 AM
Cursor1 agentProduct view
Cursor · ws-9c31f0e4Delegated
Sam Ortiz · FIRM-LT-0103 · observed on the wire
96exchanges310actions128ktokensseen Jul 15, 04:41 PM
Codex CLI1 agentProduct view
Codex CLI · a91d44c0BlockedMachine
Ops automation · SRV-BUILD-02 · runs scheduled
41exchanges187actions96ktokensseen Jul 12, 02:03 AM
Window Jun 16, 2026 to Jul 16, 2026. Liveness and identity come from the durable register; counts are window bounded. Every record is content free.
10:25
One row per agent: owner, home, identity, activity

A coding agent caught, restricted, and refused at the wire.

It tries. It never crosses.

An agent holds no keys.

It gets a name, an owner, the work it may run, and limits. Never a standing credential, never raw identifiers, never arbitrary search.

A child agent can be narrower than its parent. Never broader.

See Agents
Hemanth Tadepalli

Nearly a decade of stopping this.

Hemanth Tadepalli, Founding Advisor and vCISO

  • M.S. Cybersecurity, UC Berkeley
  • Mandiant, Google, AlixPartners, May Mobility
  • Threat intelligence and API security research
The team

Security and compliance are enforced inside every workflow.

Proxara controls what AI can access, what may leave the firm, and what actions may be completed, then records the evidence.

Every request is controlled before release.

Release
Transform
Keep local

Every action is verified after execution.

ProxaraFY25
Work recordsPurposesSourcesEvidenceReports

Assurance

Work Assurance Record

Missing-document follow-up · Completed and verified

Purpose

Tax engagement administrationAuthorized

Sources used

Karbon · Outlook · SharePoint

External AI received

Approved facts and temporary referencesNo clear client identity

Protected locally

Client identity · Documents · Tax figures · Credentials
128Work completed
9Held for approval

Completed · 30 days

1 Mar15 Mar30 Mar

Send us the security review.

Tell us what the firm needs answered, and a person will answer it.

Talk to us