The agent never owns the credential.
Protected workers are credential-starved. Remote authority stays with a broker that grants bounded, attributable actions instead of exposing reusable secrets.
Identity · scoped grants · short leasesSecurity at Mithran
Your agents can be wrong, manipulated, or malicious. Mithran is built so no single model, rule, gateway, or reviewer has to be perfect for the company to stay in control.
Anything AI does, and anything it produces, is unsafe until independent evidence says otherwise.
Defense in depth
Every boundary catches a different class of failure. Together they keep useful work moving without asking the enterprise to trust the agent, the person directing it, or a single control.
Protected workers are credential-starved. Remote authority stays with a broker that grants bounded, attributable actions instead of exposing reusable secrets.
Identity · scoped grants · short leasesAn independent review path evaluates intent, evidence, policy, and risk before consequential work advances. Unsupported confidence is not a verdict.
Adversarial review · cited policy · typed verdictFor Forge-controlled workloads, isolation and intervention extend into the compute boundary. The runtime is part of the control plane, not a destination beyond it.
Isolated compute · runtime policy · quarantineRequests, grants, decisions, mutations, deployment state, and runtime interventions become linked records that can be replayed and reconciled.
Receipts · provenance · Flight RecorderThe compute boundary
An agent can change protocols, spawn another process, call a different tool, or attack the layer enforcing the rule. Real containment needs a boundary the workload cannot rewrite from inside.
A protected worker begins with no reusable cloud or source-control credential it can read or leak.
The system grants the smallest useful authority for the named task, then records what used it.
The app or agent executes inside a Forge-controlled runtime with declared routes and intervention points.
The controls attached during review stay with the workload in production. Approval is not the end of governance.
The trust contract
“The AI approved it” is not an answer. A trustworthy decision exposes what happened and leaves a human with real authority over the result.
The goal, actor, target, scope, and expected business outcome stay attached to the work.
The reviewer is independent of the builder and cannot inherit the builder’s incentive to finish.
Findings cite policy, system state, assumptions, and the evidence that would falsify them.
Allow, repair, block, or escalate. Missing or indeterminate evidence cannot silently become approval.
A person can block, approve a scoped exception, change policy, or revoke. Overrides carry an owner, reason, scope, and expiry.
The request, decision, authority, changes, and result remain connected in a signed evidence trail.
Honest security posture
Security copy should have the same evidence bar as the product. We say where the boundary works, where it does not, and what still needs to be earned.
Protected local and hosted sessions have evidence for broker-required remote writes and for denying raw credential material to the worker.
Local isolated-worker and hosted Firecracker paths include bad-script proofs against the named containment boundaries.
Protected source-control and cloud mutations route through typed broker actions or approved command profiles with receipts.
Local evidence and policy depend on a surviving trust base. A device that is completely owned can suppress or destroy local signals.
Mithran reduces authority and blast radius, detects suspicious behavior, and preserves evidence. It does not claim perfect classification.
Runtime protection covers traffic and authority routed through the declared Forge boundary. Alternate routes need their own evidence before they inherit the claim.
The point of security is not to slow the agentic enterprise down. It is to let more people build, with a system strong enough to carry the risk.
hello@mithran.ai →