Agent Security Control Plane v0.5
Agent security control plane for inventory, policy, and boundary evaluation
Organizations deploying Claude, Cursor, Codex, MCP servers, and custom agents need more than static artifact scans. Noetfield Shield provides a deterministic policy decision point, six-suite adversarial evaluation, hostile trace simulations, and tamper-evident SHA-256 receipts mapped to SOC 2 and OWASP controls.
- Policy decision point:
POST /v1/agent-control/decidereturns ALLOW, DENY, or STEP_UP per tool, file, network, and process action. - Boundary evaluation: six suites covering tool overreach, secret access, prompt injection, network egress, process execution, and privilege escalation.
- Enterprise policy packs: Cursor coding agent, MCP read-only, CI deploy, skills marketplace, research, and support bot authority templates.
- Forensic receipts: SHA-256 verified evaluation history for audit, SOC, and CI release gates.
- Hostile simulations: regression scenarios for prompt injection, data exfiltration, tool overreach, and process escape.
Aligned with 2026 agent governance direction
NIST is defining software-agent identity and authorization. OWASP focuses on secure MCP and agentic security. Runtime protection around prompts, tool requests, and tool responses is becoming baseline. Noetfield Shield evaluates normalized traces from isolated adapters; the control plane never executes untrusted agent code.
Wire adapters from your sandbox, MCP proxy, or CI pipeline. Get deterministic gates before agents touch production credentials, filesystems, or egress.