Latency budget
Design targets per execution stage.
Cirvix is the runtime authorization layer for AI agents. Every tool call, API action, credential request, and consequential operation is evaluated against identity, policy, and context before execution. See how AI-agent security works at Cirvix.
The agent can reason. Cirvix decides whether it gets to act.
Editable. Try ~/.aws/credentials.
Secrets and risk resolve before policy — a rule may test risk >= HIGH, so the value has to exist first.
total—
—
sha‑256 —
prev —
A model being capable of executing an action does not mean the agent is authorized to cause that consequence.
Frontier models (such as GPT-6 Astra) are reaching critical cyber-capability thresholds, discovering novel vulnerabilities and chaining multi-step exploits autonomously. Static allowlists and prompt guardrails fail. CIRVIX operates directly in the execution path, enforcing machine-speed (design-target <1.2ms authorization latency) against real-world side effects before actions run.
Every agent action crosses a single control layer before it reaches a model, service, or database.
A focused set of mechanics for operating AI agents in production without losing the evidence behind every decision.
Design targets per execution stage.
One evaluation call, one decision — hash-chained evidence, optionally Ed25519-signed (0.1.3+).
cirvix.policy.eval({
agent_id: "agent-01"
})Rules are live before execution.
Keep the control plane inside the boundary that makes sense for your team.
Built on engineering mechanisms you can inspect instead of unverified marketing claims.
CIRVIX_MASTER_KEY is customer managed. No escrowed master key path.
Cryptographically linked SHA-256 logs preserve the integrity of each execution.
org_id row-scoping is enforced in routing rather than added as an application convention.
Decisions enter the audit chain; payload data is discarded when it is not approved for retention.
Native integration points for enterprise identity providers and managed access.
Export a coherent audit trail for a review without assembling raw logs by hand.
Cirvix enforces strict structural security mechanisms. Formal SOC2 and ISO certifications are currently in progress; we publish no unverified SLA claims. Cirvix is an independent, founder-led company (a sole proprietorship — see the terms) rather than an established enterprise vendor.
Enforcement is identical across tiers. What changes is coordination, identity, retention and deployment.
You do not need this list to start. npx @cirvix_ai/agent-control scan works now, needs no account, and sends nothing anywhere. The list is for early access to the paid tiers and the control plane, and for shaping what gets built next.
Over the daily limit, the call is denied rather than passed through unchecked. A security control that stops enforcing when a counter runs out is not a degraded product, it is an absent one.
You will hear from us when there is access to give, and not before. In the meantime the Free tier is the whole enforcement engine — npx @cirvix_ai/agent-control scan.
The operational details matter. Here is a clear view of how Cirvix behaves under real constraints.
System statusEnvelope encryption uses AES-256-GCM. CIRVIX_MASTER_KEY remains customer managed and is never held in escrow by the service.
Cirvix can be deployed through Docker Compose, Helm, or directly on a Bare Node environment with the control plane inside your chosen network boundary.
Audit evidence is exported as structured JSON with linked execution records and SHA-256 hash metadata for each recorded decision.
Only approved decision evidence is committed to the audit chain. Unsanctioned payload data is discarded rather than stored for later use.
Set durable policy, preserve a verifiable record, and give teams a safer way to put intelligent systems to work.
Discuss custom VPC deployments, policy requirements, or dedicated enterprise support.
Prefer to talk? Book a 30-minute call