FAQ
Frequently asked questions
Straightforward answers about how Cerberus works.
Cerberus instruments inside the application instead of sitting in front of it. A WAF or API gateway has to infer intent from traffic shape; Cerberus sees the real request and response context, ties every event to a hashed user identity, and tracks behavior across services. The result is attribution, a single chain of activity per actor, rather than a queue of disconnected alerts.
No. PII is removed or hashed at the point of instrumentation, so raw values never leave the customer environment. This is the same property that makes cross-customer threat intelligence possible without identifiers crossing between environments, and it materially shortens vendor and privacy review cycles.
Cerberus handles agentic AI traffic and MCP tool calls natively, with the same in-app instrumentation model used for traditional API traffic. That means tool calls are tied to the same user-level attribution graph as the rest of the application, so prompt injection, exfiltration, and abuse of MCP servers exposed to untrusted content are detected as part of one chain of activity rather than as a separate, retrofitted bolt-on.
Cerberus detects account takeover and credential abuse, business logic abuse, broken object-level authorization (BOLA), data scraping and exfiltration, bot-driven attacks, prompt injection through agentic AI tool calls, and abuse of MCP servers exposed to untrusted content. Detection runs against both a per-customer behavioral baseline and a cross-customer threat-intelligence layer.
