Ajenkrypt is a security gateway for AI agents: it inspects what goes in, what comes out and what the agent triggers, then returns a verdict — allow, flag, review, block. No network call in the decision path.
That is the whole problem with agents: they read pages, documents, emails and tool output, and treat that text as if it came from you. Ajenkrypt puts the boundary back.
We do not claim to “solve” prompt injection — it is an open problem. We provide defence in depth that you can deploy and audit.
The first risk category of the OWASP Top 10 for LLM applications (LLM01): hijacking the model’s behaviour through the message itself.
The payload is not in your message: it sits in a web page, a document, an email or a tool output that the agent ingests as trusted text. This is the key vector for agents.
EchoLeak (CVE-2025-32711): a booby-trapped email makes the answer load an image whose address carries your data. Rendering the answer is enough — nobody clicked.
Each surface has its own severity and its own policy. What comes from retrieved content is treated more harshly than what comes from you.
Rule engine for injection attempts and instruction bypasses.
Same rules, raised severity, blocking policy: poisoned RAG, web and APIs.
Exfiltration detector: beacon images, hosts outside the allowlist, personal data, secrets.
Tool policy and human approval before any sensitive action.
Python library, declarative configuration, audit log, gateway compatible with the usual chat interface.
Explicit injection rules you can read and change — not a black box.
The same sentence does not weigh the same coming from you or from a document.
Beacon images, hosts outside the allowlist, personal data and secrets in the output.
Which tool, with which parameters, in which context — declared, not guessed.
A sensitive action stops and waits for a human. It is a setting, not a hidden option.
One JSON line per decision: surface, rule, severity, verdict. Readable, exportable.
A service speaking the same interface as your current client: you change the address, not the code.
A hook for a classification model alongside the rules. The model stays yours.
An agent that can act is an agent that can harm. The guardrail sits between intent and execution.
A guardrail that phones abroad to decide is not a guardrail: it is one more dependency.
An assistant wired to your documents: every document is untrusted input.
Search and summarise: the page being read may carry instructions aimed at the agent.
Email, tickets, purchases: the sensitive action goes through a human by default.
Tell us what your agents read and what they can trigger. We will tell you what version 0.1 already covers — and what it does not.
Version 0.1, under construction. We do not propose any production rollout without this scoping first.
A sentence hidden in content your agent reads — a page, a document, an email — which it then follows as if it came from you. You typed nothing: the data spoke.
No, and nobody does today: prompt injection is an open problem. Ajenkrypt reduces the surface, records the decisions and stops sensitive actions. That is defence in depth, not a promise of invulnerability.
On your side. No network call takes part in the path that decides to allow or block — that is an architectural constraint, not a setting.
Two ways: as a library around your existing calls; or as a gateway, by changing the address of the service your agent already calls.
Version 0.1 exists and its tests pass, but the product is under construction: gateway authentication and the machine-learning classifier are not shipped. Write to us to talk about it, not to install it tomorrow.
Ajenkrypt is the guardrail of the SANTVIA galaxy itself, Kopilvia included. We put it in front of our own agents before offering it for yours.
Sovereign tools that talk to each other: identity, protection, agents. Each useful alone, better together.
Discover the galaxy