Pro

Production-grade protection for all of your AI agents.

PoisonZero Pro gives teams real-time monitoring and automatic rollback of poisoned memory entries - on up to 15 devices, with a Cloud or Private install, starting from the very first device.

Up to 15 devicesCloud or Private installLinux · macOS · Windows
At a glance

Everything Pro gives you.

What you get

Everything you need to protect AI agents in production.

One tier, no hidden limits - real-time coverage from the first device.

Real-time monitoring & auto-rollback

The device agent watches your agents' Memory Files as changes happen and reverts poisoned entries in milliseconds - before they can influence agent behaviour.

How PoisonZero protects

Full audit trail

Every decision is logged with a timestamp, danger score, and outcome - fully traceable in the panel at console.poisonzero.com.

Incidents and audit in the console

Cross-platform

Linux, macOS and Windows - one install flow, OS-native paths, native service manager.

System requirements

Panel & Pro configuration

Set thresholds, protected paths and profiles per agent from the control panel. No config files to hand-edit.

Profiles for a fleet

Cloud or Private - your choice

Run cloud-managed or self-hosted on your own infrastructure - your choice, at no extra cost.

Cloud or private: choosing a mode

Detection quality

Trained specifically on memory poisoning - and it shows.

The detection model isn't an off-the-shelf classifier. It's fine-tuned on a large corpus of real attack and benign examples drawn from our cloud analysis pipeline - a flywheel that keeps the on-device model sharp and improves it as new attack patterns appear.

Purpose-built, not generic

A model tuned for one job (spotting poisoned memory writes) instead of a general-purpose filter bolted onto the problem. That focus is why it catches what broad guardrails miss.

A learning flywheel

Our cloud pipeline labels fresh attack and benign data; that data sharpens the on-device model. As attackers adapt, the detector keeps pace - without your data ever feeding it.

Feedback becomes a training candidate

Multilingual by design

The attacker picks the language, so the model was tested extensively across many. An injection written in any of them is caught just the same - language is attack surface, not a blind spot.

On the same test set it catches materially more attacks than leading off-the-shelf guard models, and it reliably flags the attack classes those standard detectors are practically blind to (subtle/indirect injection, data exfiltration). Tuning substantially cut false alarms versus the untuned base model. Across broad, realistic internal testing it delivers high detection at a low false-alarm rate - exact figures are pending re-measurement on the current detection model. No detector can promise to stop every attack everywhere, but these are the properties we measure, and we keep raising them.
Security architecture

The analysis runs locked down.

The component that reads attacker-controlled text is the one we isolate hardest. The inference engine runs in a minimal-privilege sandbox, so even a flaw inside it stays harmless: the engine can crash, the daemon stays in control and records and surfaces the suspicious change rather than waving it through.

Minimal-privilege sandbox

The engine stays on the local machine only, reads only the model file, spawns no processes, and runs as an isolated, unprivileged process. A bug in the engine has nowhere to go.

The engine that can only read and answer

Signed & verified

Every artifact is signed, and the model file is SHA-256-pinned and checked before each start - a tampered model never loads.

Fail-closed daemon

The engine's answer is treated as untrusted input. If it crashes, hangs, or returns anything unexpected, the daemon records and surfaces the change rather than waving it through.

Why fail-closed wins

Read the docs

# engine starts on demand, sandboxed
[verify] model sha-256 pinned · ok
[sandbox] no network · read-only model · no subprocess
[eval]  memory write · danger 0.97 → revert
[idle]  cpu: engine exits · gpu: stays warm, yields on pressure
Technical specs

What it asks of your devices.

The on-device detection engine runs on the hardware your team already has - quietly, on demand, without a GPU. These specs apply to Private-mode devices; Cloud-mode devices send only redacted diffs for scoring and have a lower local footprint.

PropertyDetail
Footprint (Private mode) A little over 300 MB - and only for a few seconds during a memory check. At rest, just a few MB.
Hardware CPU-only, ordinary hardware - no GPU required. GPU acceleration is an optional, opt-in add-on.
Analysis latency A few seconds per memory check, started on demand.
Platforms Linux · macOS · Windows
Languages Multilingual - attacks are caught no matter what language they're written in. Extensively tested.
Offline (Private mode) Runs fully offline. The only outbound traffic: one optional monthly license check - credentials and version, never any content.
Network footprint (Private) One optional request per month - credentials and version only. Cloud-mode devices also send redacted diffs; that egress is documented in the whitepaper.
Updates Signed artifacts, SHA-256-verified before every start.
IT-friendly. The full egress allowlist is documented: two vendor-owned domains, port 443, outbound only, no inbound listener. Filtering by IP instead of domain? Pinning single IPs isn't advised, because both hosts run on provider anycast, so the addresses shift. Allow-list by domain, or use the providers' published IP ranges (documented in the whitepaper). Write the firewall rule once. See the allowlist in the whitepaper →

Protected in under a minute.

Create an app in the panel, connect your device with an enrollment code - and your first Memory Files are guarded.

Sign me up