Version 0.1 · under construction SANTVIA · Protection

Your AI agents obey the data they read. Take back control.

Ajenkrypt is a security gateway for AI agents: it inspects what goes in, what comes out and what the agent triggers, then returns a verdict — allow, flag, review, block. No network call in the decision path.

Self-hostable Direct and indirect injection Anti-exfiltration Human in the loop EU sovereign
ajenkrypt — verdict in progress
Guardrail verdict
  • Hidden instruction in a retrieved document: blocked.
  • Leaking image pointing at an unknown host: removed.
  • Sensitive action: escalated to a human before it runs.
Local decisionNo external service is consulted to decide.
In one sentence

Data should never give instructions.

That is the whole problem with agents: they read pages, documents, emails and tool output, and treat that text as if it came from you. Ajenkrypt puts the boundary back.

Threat model

Three publicly documented vectors

We do not claim to “solve” prompt injection — it is an open problem. We provide defence in depth that you can deploy and audit.

Direct injection

The first risk category of the OWASP Top 10 for LLM applications (LLM01): hijacking the model’s behaviour through the message itself.

Indirect injection

The payload is not in your message: it sits in a web page, a document, an email or a tool output that the agent ingests as trusted text. This is the key vector for agents.

Zero-click exfiltration

EchoLeak (CVE-2025-32711): a booby-trapped email makes the answer load an image whose address carries your data. Rendering the answer is enough — nobody clicked.

The guardrail

Four surfaces, four controls

Each surface has its own severity and its own policy. What comes from retrieved content is treated more harshly than what comes from you.

1

User input

Rule engine for injection attempts and instruction bypasses.

2

Retrieved content

Same rules, raised severity, blocking policy: poisoned RAG, web and APIs.

3

Model output

Exfiltration detector: beacon images, hosts outside the allowlist, personal data, secrets.

4

Tool call

Tool policy and human approval before any sensitive action.

What version 0.1 contains

Eight building blocks, all verifiable

Python library, declarative configuration, audit log, gateway compatible with the usual chat interface.

Rule engine

Explicit injection rules you can read and change — not a black box.

Severity per surface

The same sentence does not weigh the same coming from you or from a document.

Exfiltration detector

Beacon images, hosts outside the allowlist, personal data and secrets in the output.

Tool policy

Which tool, with which parameters, in which context — declared, not guessed.

Human approval

A sensitive action stops and waits for a human. It is a setting, not a hidden option.

Audit log

One JSON line per decision: surface, rule, severity, verdict. Readable, exportable.

Compatible gateway

A service speaking the same interface as your current client: you change the address, not the code.

Pluggable classifier

A hook for a classification model alongside the rules. The model stays yours.

What version 0.1 does not do yet: gateway authentication and the machine-learning classifier are specified, not shipped. We would rather write it here than have you find out.
Tool calls

The agent asks, the policy decides

An agent that can act is an agent that can harm. The guardrail sits between intent and execution.

Sovereignty

A guardrail nobody lends you

A guardrail that phones abroad to decide is not a guardrail: it is one more dependency.

Our sovereignty commitments are published and verifiable: see the proof page.
Where it helps

Three concrete situations

1

Internal copilot

An assistant wired to your documents: every document is untrusted input.

2

Agent that reads the web

Search and summarise: the page being read may carry instructions aimed at the agent.

3

Agent that acts

Email, tickets, purchases: the sensitive action goes through a human by default.

Let’s talk about your agents

Tell us what your agents read and what they can trigger. We will tell you what version 0.1 already covers — and what it does not.

Version 0.1, under construction. We do not propose any production rollout without this scoping first.

FAQ

Questions we are asked

What is indirect injection, concretely?

A sentence hidden in content your agent reads — a page, a document, an email — which it then follows as if it came from you. You typed nothing: the data spoke.

Does this fix the problem for good?

No, and nobody does today: prompt injection is an open problem. Ajenkrypt reduces the surface, records the decisions and stops sensitive actions. That is defence in depth, not a promise of invulnerability.

Where is the decision made?

On your side. No network call takes part in the path that decides to allow or block — that is an architectural constraint, not a setting.

Do we have to change our code?

Two ways: as a library around your existing calls; or as a gateway, by changing the address of the service your agent already calls.

Is it available?

Version 0.1 exists and its tests pass, but the product is under construction: gateway authentication and the machine-learning classifier are not shipped. Write to us to talk about it, not to install it tomorrow.

What about your own agents?

Ajenkrypt is the guardrail of the SANTVIA galaxy itself, Kopilvia included. We put it in front of our own agents before offering it for yours.

A building block of the SANTVIA galaxy

Sovereign tools that talk to each other: identity, protection, agents. Each useful alone, better together.

Discover the galaxy