PoisonZero documentation
Everything about running PoisonZero: install and operate the protection, choose cloud or private, and read up on the attacks it stops. Use the search above or the menu on the left to find a topic.
Get started
Fundamentals
What PoisonZero does and why the protection sits where it does.
- What PoisonZero does
- How PoisonZero protects
- Why fail-closed wins
- The engine that can only read and answer
- macOS: the engine inside the Seatbelt sandbox
- Linux: the engine behind Landlock
- Windows: the engine inside a network-isolated AppContainer
Operating modes
Which mode you pick and what it means for your data.
- Cloud or private: choosing a mode
- Network and firewall requirements
- What Cloud mode sends
- Privacy by design: the architecture
- Bring your own on-prem model
User confirmation prompts
When PoisonZero asks, what you see and how you answer.
Installation & operation
Set up the protection, understand what's covered, run it.
- Installing PoisonZero: complete reference
- Enroll a device on your account
- What PoisonZero watches
- System requirements
- Device status and engine health
- Updates and lifecycle
- Storage, retention and cleanup
Console & fleet
What you see and control in the console.
- Incidents and audit in the console
- OpenTelemetry export (Enterprise)
- SIEM export (Enterprise)
- Management API
- Profiles for a fleet
- Automatic model selection
- Steer sensitivity and ask timers
- Feedback becomes a training candidate
Attacks we stop
The threats against agent memory - and how PoisonZero defends against them.
- Skills as the entry point
- ClawHavoc: 1,184 poisoned skills
- Claude, MCP & tool poisoning
- Poisoned Pipeline Execution
- Supply-chain worms
- Hades: the worm that poisons AI configs
- AI agents in the CI/CD pipeline
- What is memory poisoning?
- Prompt injection explained
- Data exfiltration via memory
- What is a meta-attack?
- Role-play & jailbreak
- Subtle & indirect injection