IntentGate Product Brief (v1.9)
the customer-facing introduction in PDF form.
The conceptual model, seven runtime controls, standards mappings, product references, operator documentation, and executive material for teams evaluating or deploying the AI runtime security platform and MCP firewall for AI agents.
This is not a flat sitemap. Each chapter is sequenced around how security, architecture, compliance, and operations teams actually evaluate the category, from definitions, to controls, to standards evidence, to implementation.
Definitions and the broad picture for the agent runtime authorization control category.
The canonical definition of the category: what it is, the threat model, the seven required controls, how it fits with your existing security stack. Start here.
60+ definitions covering the agent runtime authorization vocabulary: capability tokens, intent enforcement, destructive verbs, memory provenance, MCP, Rego, and related concepts.
Deep-dive pages on each of the seven controls a complete agent runtime authorization solution must implement.
HMAC-bound credentials that scope an agent to specific tools, tenants, and time windows. The foundational control.
Zones on the token, default-deny agent-to-agent (east-west) calls, and per-zone tool scope, with a live flow map and estate matrix. Contains lateral movement across the estate.
The gateway control that matches the agent's resolved tool call against the user's declared structured intent. The primary defence against prompt injection.
Rego-based policy for destructive-verb deny-lists, bulk-row ceilings, value thresholds, and approved-destination lists.
Per-tenant token and cost ceilings, fail-closed. The defence against unbounded consumption.
Signed chain-of-custody on agent memory writes so high-stakes reads can require verified provenance. Defeats memory poisoning.
Content inspection on prompts and responses. Nine checksum-validated PII classes plus eight credential and secret classes, with counts-only audit so matched values are never persisted.
Capabilities that work alongside the seven-check pipeline to harden secrets and watch behaviour over time.
The gateway holds each tool's credential and injects it per call, so agents never possess a production secret. Encrypted at rest, rotated centrally, enforced as defence in depth against bypass.
Baselines each agent over the audit trail and flags denial bursts, new tools, volume spikes, and off-hours activity. Alerts through a webhook and can revoke the offending token automatically.
How agent runtime authorization maps to the frameworks security teams, auditors, and procurement reference during evaluation.
Per-standard mapping for OWASP Top 10 for LLM, OWASP Top 10 for Agentic AI, NIST AI RMF, MITRE ATLAS, EU AI Act, ISO/IEC 42001, SOC 2, ISO 27001, GDPR.
The CISO-readable OWASP coverage matrix. 14 risks directly mitigated, 1 partial, 5 explicitly out of scope by deployment model.
What IntentGate is and how it works in practice.
The four-control bypass essay. The sharpest single positioning page on the site.
What ships, what it does, where it fits.
Live evaluation lab: a representative agent deployment with all controls enabled and audit chain visible end-to-end.
Five-check authorization pipeline walkthrough with the install demo cast.
Tamper-evident audit, RBAC, JIT elevation, evidence for SOC 2, ISO 27001, GDPR, AI Act.
Apache 2.0 licensed gateway, contribution model, the relationship between the open-source core and IntentGate Pro.
Operator-facing reference for deploying and operating IntentGate.
The following PDFs are available on request through contact . They are the deeper deliverables that complement the public pages: the OWASP-anchored vendor security pack, the CISO-facing threat stories doc, the operations overview, and the architectural comparison battle cards.
the customer-facing introduction in PDF form.
the CISO walk-through organised around the CIA triad, with the OWASP-anchored coverage map.
deep technical pack with full OWASP coverage matrix.
CISO-facing operational commitment doc.
architectural comparison for prospects evaluating IntentGate alongside their perimeter stack.
architectural comparison for prospects evaluating IntentGate alongside their existing API gateway.
Tell us whether you are evaluating architecture, control coverage, compliance evidence, or deployment. We will point you to the shortest useful route.