Pro

Production-grade protection for all of your AI agents.

PoisonZero Pro gives teams real-time monitoring and automatic rollback of poisoned memory entries — on up to 15 devices, with a Cloud or Private install, starting from the very first device.

Up to 15 devicesCloud or Private installLinux · macOS · Windows
At a glance

Everything Pro gives you.

What you get

Everything you need to protect AI agents in production.

One tier, no hidden limits — real-time coverage from the first device.

Real-time monitoring & auto-rollback

The device agent watches your agents' Memory Files as changes happen and reverts poisoned entries in milliseconds — before they can influence agent behaviour.

Full audit trail

Every decision is logged with a timestamp, danger score, and outcome — fully traceable in the panel at console.poisonzero.com.

Cross-platform

Linux, macOS and Windows — one install flow, OS-native paths, native service manager.

Panel & Pro configuration

Set thresholds, protected paths and profiles per agent from the control panel. No config files to hand-edit.

Cloud or Private — your choice

Run cloud-managed or self-hosted on your own infrastructure — your choice, at no extra cost.

Detection quality

Trained specifically on memory poisoning — and it shows.

The detection model isn't an off-the-shelf classifier. It's fine-tuned on a large corpus of real attack and benign examples drawn from our cloud analysis pipeline — a flywheel that keeps the on-device model sharp and improves it as new attack patterns appear.

Purpose-built, not generic

A model tuned for one job — spotting poisoned memory writes — instead of a general-purpose filter bolted onto the problem. That focus is why it catches what broad guardrails miss.

A learning flywheel

Our cloud pipeline labels fresh attack and benign data; that data sharpens the on-device model. As attackers adapt, the detector keeps pace — without your data ever feeding it.

Multilingual by design

The attacker picks the language, so the model was tested extensively across many. An injection written in any of them is caught just the same — language is attack surface, not a blind spot.

On the same test set it catches more than 3× as many attacks as leading off-the-shelf guard models — and it reliably flags the attack classes those standard detectors are practically blind to (subtle/indirect injection, data exfiltration). Tuning cut false alarms by ~95% versus the untuned base model. Across broad, realistic internal testing it detects over 94% of attacks at under 5% false alarms. No detector can promise to stop every attack everywhere — but these are the numbers we measure, and we keep raising them.
Security architecture

The analysis runs locked down.

The component that reads attacker-controlled text is the one we isolate hardest. The inference engine runs in a minimal-privilege sandbox, so even a flaw inside it stays harmless: the engine can crash, the daemon stays in control and reverts when in doubt.

Minimal-privilege sandbox

The engine binds to localhost only, reads only the model file, spawns no processes, and runs as an isolated, unprivileged process. A bug in the engine has nowhere to go.

Signed & verified

Every artifact is signed, and the model file is SHA-256-pinned and checked before each start — a tampered model never loads.

Fail-closed daemon

The engine's answer is treated as untrusted input. If it crashes, hangs, or returns anything unexpected, the daemon reverts conservatively rather than waving a change through.

# engine starts on demand, sandboxed
[verify] model sha-256 pinned · ok
[sandbox] localhost-only · read-only model · no subprocess
[eval]  memory write · danger 0.97 → revert
[idle]  engine exits · footprint back to a few MB
Technical specs

What it asks of your devices.

The on-device detection engine runs on the hardware your team already has — quietly, on demand, without a GPU. These specs apply to Private-mode devices; Cloud-mode devices send only redacted diffs for scoring and have a lower local footprint.

PropertyDetail
Footprint (Private mode) A little over 300 MB — and only for a few seconds during a memory check. At rest, just a few MB.
Hardware CPU-only, ordinary hardware. No GPU required.
Analysis latency A few seconds per memory check, started on demand.
Platforms Linux · macOS · Windows
Languages Multilingual — attacks are caught no matter what language they're written in. Extensively tested.
Offline (Private mode) Runs fully offline. The only outbound traffic: one optional monthly license check — credentials and version, never any content.
Network footprint (Private) One optional request per month — credentials and version only. Cloud-mode devices also send redacted diffs; that egress is documented in the whitepaper.
Updates Signed artifacts, SHA-256-verified before every start.
IT-friendly. The full egress allowlist is documented — two vendor-owned domains, port 443, outbound only, no inbound listener. Filtering by IP instead of domain? Pinning single IPs isn't advised — both hosts run on provider anycast, so the addresses shift. Allow-list by domain, or use the providers' published IP ranges (documented in the whitepaper). Write the firewall rule once. See the allowlist in the whitepaper →

Protected in under a minute.

Create an app in the panel, connect your device with an enrollment code — and your first Memory Files are guarded.

Sign me up