PoisonZero Pro gives teams real-time monitoring and automatic rollback of poisoned memory entries — on up to 15 devices, with a Cloud or Private install, starting from the very first device.
One tier, no hidden limits — real-time coverage from the first device.
The device agent watches your agents' Memory Files as changes happen and reverts poisoned entries in milliseconds — before they can influence agent behaviour.
Every decision is logged with a timestamp, danger score, and outcome — fully traceable in the panel at console.poisonzero.com.
Linux, macOS and Windows — one install flow, OS-native paths, native service manager.
Set thresholds, protected paths and profiles per agent from the control panel. No config files to hand-edit.
Run cloud-managed or self-hosted on your own infrastructure — your choice, at no extra cost.
The detection model isn't an off-the-shelf classifier. It's fine-tuned on a large corpus of real attack and benign examples drawn from our cloud analysis pipeline — a flywheel that keeps the on-device model sharp and improves it as new attack patterns appear.
A model tuned for one job — spotting poisoned memory writes — instead of a general-purpose filter bolted onto the problem. That focus is why it catches what broad guardrails miss.
Our cloud pipeline labels fresh attack and benign data; that data sharpens the on-device model. As attackers adapt, the detector keeps pace — without your data ever feeding it.
The attacker picks the language, so the model was tested extensively across many. An injection written in any of them is caught just the same — language is attack surface, not a blind spot.
The component that reads attacker-controlled text is the one we isolate hardest. The inference engine runs in a minimal-privilege sandbox, so even a flaw inside it stays harmless: the engine can crash, the daemon stays in control and reverts when in doubt.
The engine binds to localhost only, reads only the model file, spawns no processes, and runs as an isolated, unprivileged process. A bug in the engine has nowhere to go.
Every artifact is signed, and the model file is SHA-256-pinned and checked before each start — a tampered model never loads.
The engine's answer is treated as untrusted input. If it crashes, hangs, or returns anything unexpected, the daemon reverts conservatively rather than waving a change through.
# engine starts on demand, sandboxed [verify] model sha-256 pinned · ok [sandbox] localhost-only · read-only model · no subprocess [eval] memory write · danger 0.97 → revert [idle] engine exits · footprint back to a few MB
The on-device detection engine runs on the hardware your team already has — quietly, on demand, without a GPU. These specs apply to Private-mode devices; Cloud-mode devices send only redacted diffs for scoring and have a lower local footprint.
| Property | Detail |
|---|---|
| Footprint (Private mode) | A little over 300 MB — and only for a few seconds during a memory check. At rest, just a few MB. |
| Hardware | CPU-only, ordinary hardware. No GPU required. |
| Analysis latency | A few seconds per memory check, started on demand. |
| Platforms | Linux · macOS · Windows |
| Languages | Multilingual — attacks are caught no matter what language they're written in. Extensively tested. |
| Offline (Private mode) | Runs fully offline. The only outbound traffic: one optional monthly license check — credentials and version, never any content. |
| Network footprint (Private) | One optional request per month — credentials and version only. Cloud-mode devices also send redacted diffs; that egress is documented in the whitepaper. |
| Updates | Signed artifacts, SHA-256-verified before every start. |
Create an app in the panel, connect your device with an enrollment code — and your first Memory Files are guarded.
Sign me up