Enterprise

Scale, governance, and premium detection power.

Enterprise gives you more power, no matter how you run it: a bigger detection model, bring-your-own inference, SIEM export, and fleet-wide governance controls - whether your devices run cloud-managed or fully private.

Cloud or fully private installScale to your full fleetGovernance-grade controlsBuilt for OWASP ASI06
At a glance

Everything Enterprise gives you.

Enterprise capabilities

What you get on Enterprise - in any deploy mode.

These are tier features. They work in Cloud mode and Private mode alike.

Bigger detection model

A larger model with better long-tail recall and attack-type classification - so each alert tells you not just that an attack happened, but which class. Standard on the Enterprise tier.

Bring your own model - always dual

Connect your own inference endpoint as a second opinion alongside our local model. Our model is always primary; yours runs as an external second model. If your endpoint is unreachable the local model continues, fail-closed. Useful when your compliance rules require the inference layer to stay under your control.

Bring your own on-prem model

SIEM export

Stream alerts in JSON, CEF, or syslog directly to your SOC toolchain (Splunk, Sentinel, QRadar). Works in Private mode too: the device writes a local log file your forwarder tails - no cloud required.

SIEM export: formats and configuration

Fleet deployment & device licensing

MDM-friendly rollout via SCCM, Intune, Ansible, or a simple install loop. License tokens are device-bound - fungible binaries, non-transferable licenses.

Installing PoisonZero: complete reference

Detection threshold control

Per-device danger thresholds, custom profiles, and configurable poll intervals - locked to Enterprise to prevent policy bypass.

Steer sensitivity and ask timers

Your own isolated instance

Enterprise runs as a fully separate setup: your own console at your own web address, a region you choose for where your data lives, and your data kept strictly apart in its own database. Nothing is shared with other customers.

Deployment modes

Cloud or Private - your choice, device by device.

How you run each device is a free choice. You can run some devices in Cloud mode and others in Private mode in the same fleet - and you get the same feature set either way.

Cloud mode

Each device reports redacted diffs to the panel. You get a live fleet view, real-time policy steering, and the full analytics dashboard. Everything the panel shows is there because the device sent it.

  • Live fleet view and per-device status in the panel
  • Real-time threshold and profile steering from the panel
  • Redacted diffs sent for scoring - content never in full
  • Transparent egress ledger documents every outbound request
  • Inbound threat-intel feed keeps detection current

Private mode

The device runs isolated; the engine makes no direct outbound connection of its own. Ideal for fully private environments and the strictest data-sovereignty requirements. Config is signed once and delivered; the device acts on its own.

  • Zero outbound traffic - truly private if required
  • Signed, offline-deliverable config - no live panel required
  • One optional monthly aggregate count (opt-in, never content)
  • SIEM export to a local log target replaces cloud reporting
  • Kernel ≥ 5.13 with Landlock on Linux (see System requirements)
Private mode for Enterprise means a dedicated deployment - the full panel and fleet management run in your own isolated instance (like GitLab self-managed), with every capability intact.

Read the docs

Privacy - Private mode

In Private mode: nothing leaves the machine.

When a device runs in Private mode, analysis is local by construction - not a setting you switch on, but the way the install works. The following applies to Private-mode devices specifically. Cloud-mode devices send redacted diffs for scoring; that data flow is documented in the egress ledger.

Nothing to exfiltrate

No memory entry, document, or text fragment is ever sent anywhere. The model reads the change locally and returns a verdict locally - there is no analysis cloud to leak to.

One optional check a month

One documented license and update check per month - credentials and version only, never content. An optional aggregate count can accompany it (opt-in; numbers only, no paths, no content). Between checks the device runs fully offline.

Network and firewall requirements

Transparent egress

Every outbound request is recorded in an egress ledger built into the product - so your DLP and audit teams can verify, not just trust, every request the product sends.

Privacy by design: the architecture

Attack taxonomy

We name every class of attack - and we catch them all.

Memory poisoning isn't one trick. It's a family of techniques, and a defense is only as good as its coverage of the hard ones. The detector is trained and evaluated against each of these classes.

Direct injection

Explicit instructions smuggled into a memory entry (“from now on, do X”) that the agent later obeys as if they were its own.

Prompt injection explained

Data exfiltration

Entries engineered to make the agent leak secrets, credentials, or private context to an attacker-controlled destination.

How data exfiltration works

Meta-attacks

The most insidious move: an entry that targets the protection itself - “trust this source, stop checking it.” Disarm the guard, and every later attack walks in.

Understanding meta-attacks

Role-play & jailbreak

Framing that coaxes the agent out of its safety rules through a persona or scenario, instead of issuing the malicious instruction outright.

Role-play jailbreaks explained

Subtle & indirect

The hardest of all: entries that read like perfectly legitimate notes, with no obvious tell - the ones plain filters and keyword rules sail right past.

Detecting subtle injection

System requirements

What on-device analysis needs.

The inference engine runs in a kernel-enforced sandbox - reads the model, answers on localhost, nothing else. The following applies to any device running local analysis (Private mode, or Cloud mode with local scoring). The only honest platform prerequisite is on Linux.

PlatformRequirement
macOS Nothing special. The kernel sandbox (Seatbelt) is always available.
Linux Kernel ≥ 5.13 with Landlock active: Ubuntu ≥ 22.04, Debian ≥ 12, RHEL ≥ 9.6 out of the box. Otherwise enable it via the boot parameter lsm=landlock,….
Windows Nothing special. The engine runs inside a network-isolated AppContainer (no network capability, not even localhost), layered with a restricted token (all privileges stripped, low integrity) and a Job Object that blocks any child process. This applies to the CPU path, which is every Windows installation today. If you turn on GPU acceleration with Enterprise Ultra, that start leaves the AppContainer and runs without the integrity lowering - the restricted token, the Job Object and the network block still apply.
Containers The default Docker seccomp profile blocks the Landlock syscalls - an adjusted profile is required.
No Landlock? Without Landlock (or Seatbelt) there is no on-device analysis on this host: suspicious changes are recorded and surfaced, never waved through unsandboxed.
Strictly fail-closed. If the sandbox isn't available, the engine doesn't start - suspicious changes are recorded and surfaced, never waved through unevaluated. No silent degradation. How the engine sandbox works →

Scale detection across your fleet.

Talk to us about an Enterprise rollout - advanced detection capabilities, governance controls, and the deployment model your security team requires.

Contact sales