Black Hat logoBlack Hat 2026Book a meeting
    Cerberus symbolCERBERUS AI

    The trust layer for agentic systems

    What are your agents doing right now?

    Cerberus reads the intent behind every agent action and human request, scored against learned behavior. One signal when it matters, not a queue of noise.

    Deploy at the gateway or with the SDK · live in under 5 minutes

    Intent-Based Analysis4 threats
    agent:847·a3f9 · hashedtask: invoice triage
    PROMPT
    support ticket #4412
    Embedded instructions detected
    Prompt injected
    MCP
    db.query · customers.*
    2,300 records · off-task
    Data harvest
    HTTP
    POST paste-site.io/u8x1
    Outbound · 4.1 MB
    Exfil attempt
    MCP
    db.drop · audit_log
    Destructive call
    Blocked
    One verdict, not four alerts.
    Injected, harvesting, exfiltrating. One chain. Kill switch fired in 1.2s.
    1 agent quarantined9,847 events filtered

    Illustrative product interface. The figures shown are an example of how Cerberus presents a detection, not benchmark or performance results.

    9,847→1
    Events filtered to a single actionable alert
    2 paths
    Deploy at the gateway or embed the SDK
    <5 min
    From install to first live detection
    0
    Raw identifiers ever leave your environment

    AI-native

    Built for agentic AI and MCP.

    Agentic traffic and MCP tool calls run through the same instrumentation as your API traffic. Same identity, same scoring, same history.

    Agents are first-class actors
    Every agent gets the same identity, scoring, and history as a human user.
    MCP tool calls, instrumented
    Tool chains are read natively, not retrofitted from a legacy WAF.
    A kill switch for every agent
    The moment a chain diverges, Cerberus cuts the agent off. Quarantined in 1.2 seconds.
    Token spend, watched
    Per-agent token baselines catch torching and runaway burn before the invoice does.
    agent #847 · tool chainQUARANTINED
    ·agent.plansummarize quarterly invoices
    ·tool: db.querySELECT * FROM invoices
    tool: fs.read/etc/secrets/*.pem
    tool: http.postexfil → 203.0.113.42
    Call graph diverged from plan. Agent isolated in 1.2s.

    By design

    What's not here.

    Most tools add surface area. Cerberus removes it. The difference is what you stop seeing.

    Most API security
    Cerberus
    Alert flooding and a triage queue
    One actionable signal per real threat
    Point events with no actor context
    Patterns tied to one chain of activity
    Agentic AI bolted onto a legacy WAF
    Human and AI agent traffic, natively
    Blind spots between agent gateways
    One pipeline across every agent gateway
    Raw PII shipped to a vendor cloud
    PII removed or hashed at the source
    Dashboards of dashboards
    Quiet by default. Noise filtered out

    01 / Detection

    Detection that reads intent.

    Cerberus combines intelligence tradecraft with modern ML to protect your APIs from both human and AI-driven threats.

    Intent-Based Analysis™

    ML models and semantic context read what an actor is trying to do, human or agentic, not just what endpoint it hit. Intent, not activity.

    Activity200 OK · 14ms · valid token
    IntentCredential stuffing · 14 IPs

    Collaborative threat intel

    Hashed, privacy-preserving identities track malicious actors and compromised agents across every customer. New attacks harden everyone the moment they surface.

    Flexible responses

    One actionable response per signal. Define the workflow; Cerberus triggers it.

    BlockAuthenticateRate limitAlertKill switch

    Sanitized at the source

    PII is removed or hashed inside your environment before any event leaves it. Cerberus tracks the actor without ever holding the raw values.

    user@acme.comsha256:a3f9…7b2cleaves your env

    02 / Dashboard

    See the whole actor, not a wall of events.

    Monitor traffic, detect anomalies, and respond in real time with full visibility into events, endpoints, and alerts.

    01
    Live event stream
    Every request scored for intent in real time, agentic traffic included.
    02
    Actor timeline
    Auth, API, and MCP tool calls tied to one chain of activity.
    03
    One alert queue
    9,847 events collapse to the handful that need a human.
    app.cerberussecurity.ai/overview
    Cerberus dashboard showing API traffic overview, event volume, top endpoints, events by method, error-rate trends, and recent security alerts

    03 / Deploy

    Two paths, one detection pipeline.

    Drop the gateway in front of your APIs, or embed the SDK inside your server code. Bring any agent gateway, one or five: every path lands in one pipeline with one actor view across all of it. Live in under five minutes either way.

    cerberus.yamlno code changes
    # cerberus.yaml
    gateway:
    upstream: https://api.internal
    mode: inline
    detect:
    agents: true # MCP + tool calls
    hash_pii: at_source

    gateway or SDK · same pipeline · same dashboard

    04 / Response

    How It Works

    Cerberus integrates at the gateway or inside API server code, not as network middleware. Get deep visibility and intelligent defense in three simple steps.

    01

    Install

    Two integration paths, one detection pipeline. Drop the gateway in front of your APIs, or embed the SDK inside your server code. First events flow in under 5 minutes.

    02

    Detect

    Intent-based analysis combines machine learning, semantic context, and cross-customer threat intel to identify account takeover, data exfiltration, business logic abuse, and fraud across human users and AI agents alike. Patterns, not point events.

    03

    Respond

    Trigger remediation workflows tailored to each threat: block, authenticate, rate limit, alert, or fire the agent kill switch. One actionable response per signal, not a queue of pages to triage.

    Quiet is the default.

    See Cerberus read your own traffic. One walkthrough, tailored to your stack, human and agentic.