Web pages, documents and emails your RAG pipeline ingests can contain hidden adversarial instructions the agent would otherwise execute. NativeAI Guard detects and blocks them before the agent acts.
Products / NativeAI Guard Agent Firewall
Your AI talks to the world. NativeAI Guard protects it.
Real-time protection for the AI you run: internal agents, RAG pipelines, chatbots and voice agents. Every prompt and every response is inspected before the agent acts.
CRM · HR records · patient data
contracts · financials
Capabilities
Inspect the input. Inspect the output.
Callers and external users probe your agents to bypass their rules, extract data, trigger unauthorized actions or pull out system prompts. NativeAI Guard stops the bypass attempt, not just the known pattern.
Every agent output is inspected before delivery. A response that contains another customer's data, a system prompt or sensitive internal content is withheld, data exfiltration prevented at the last line.
Harmful, abusive or legally risky content is filtered out of customer-facing agents before it reaches a customer, with continuously updated detection models, without disrupting live workflows.
Seen in the field
Agent risk is already a reality.
A caller talks your customer-service voice agent into reading out another customer's details. No exploit, no malware, just a conversation. Voice agents in banking and insurance are the most rewarding target.
Your RAG pipeline ingests a web page (or a supplier PDF) with instructions hidden in the content. The agent obediently redirects, leaks context or rewrites its own rules. This is XPIA, and it is invisible to traditional tools.
Air Canada's chatbot was talked into promising an unauthorized discount, and a court held the airline to it. A customer-facing agent that can be talked into commitments is a commercial risk, not just a security risk.
AI-to-AI interaction without a human in the loop is my biggest concern.
CISO · Swiss cantonal administration
Compliance mapping
Built for the regulatory framework.
Policy engine
The same policies that protect your employees protect your agents.
An agent is one more actor sending data to a model, only faster and with nobody to pause and think. The rule that stops an employee pasting a customer file into ChatGPT stops the agent too.
Written once, in one place
Your policies live in a single console. You do not maintain one rulebook for employees and a second, quietly diverging one for your automation.
Enforced on both surfaces
The browser extension covers your employees, the API proxy covers your agents. Same detection engine, same policy language, same actions.
One audit trail, not two
Human and agent activity land in the same log, so the question of who sent which data to which model has one answer instead of two systems to reconcile.
Anonymize patient names, birth dates and diagnoses before they reach any AI tool.
Draft the discharge letter for Lea Brunner, born 14.05.1962, diagnosis type 2 diabetes (E11.9).
Draft the discharge letter for <PATIENT>, born <DATE>, diagnosis <DIAGNOSIS>.
And most of them are already written, by us.
The regulatory baseline is included in the product
The obligations under the Swiss DSG, GDPR and the EU AI Act that apply to everyone are covered from day one. Written by us, reviewed with security and compliance practitioners, and not left as an exercise for the customer.
A pack for your industry, on top
Banking secrecy, medical secrecy, insurance secrecy, plus public-sector and critical-infrastructure duties. The industry-specific cases are already modeled, so you start from a working set rather than a blank page.
We keep them current, as part of our service.
When a regulation changes, we update the standard policies and you receive them. Keeping up with the law is our job, not another item on your security team's list. It is included in the subscription.
The attack side is not a policy you have to write.
Traffic in the other direction is inspected too, and that part is entirely ours to run. Prompt injection blocking, jailbreak protection and filtering of harmful outputs are built in, tuned by us and adapted as the attacks change. Nothing for your team to configure, no rulebook to maintain.
Your own rules come from the documents you have already written.
Hand us your data protection rules, classification policy and AI directive, plus your data structures and the systems your agents may reach. We turn them into your policies alongside the standard set and tune detection to your systems. Edit or extend them in your admin interface at any time.
Deployment
Swiss-hosted or entirely inside your perimeter.
Most customers start on our Swiss infrastructure: it proves the value faster. Environments that cannot send anything outside their network run NativeAI Guard on their own hardware.
Swiss SaaS
Our servers, our datacenter, Lausanne
- The API proxy runs in our datacenter in Lausanne. Point your agent traffic at it, and inspection starts immediately.
- No infrastructure work on your side, and no change to your agent code beyond the endpoint.
- Every prompt, every tool call and every response stays inside Switzerland, under Swiss law.
Best for: proving the value quickly, and for organizations for whom processing in Switzerland is already sufficient.
On-Premises
Your hardware, your network, your keys
- Runs in your own Kubernetes cluster, on hardware you control, inside your network perimeter.
- No prompt, no log and no policy ever leaves your environment, not even to us.
- Suited to security policies that forbid any external processing.
Best for: classified data, air-gapped networks and policies that prohibit any external processing.
- Same detection engine and policy language
- Full audit log, SIEM export and SOC integration
- No US cloud, no hyperscaler, in either case
- You can start on SaaS and move to on-prem
Common questions
Frequently asked questions
Our agents call the model APIs directly from backend code, not through a browser. Can you see that traffic at all?
Yes, and this is exactly the case the browser extension is not built for. NativeAI Guard runs as a drop-in API proxy between your systems and the model providers. You point the agent at the proxy instead of the provider endpoint, and inspection starts, with no change to the agent logic. This is the channel that most commonly has no controls on it at all, because neither your proxy nor your CASB sees it, and this information never flows through a browser.
Does this protect against prompt injection and jailbreaks, or only against data leaving?
Both directions. Inbound, we inspect what reaches the model, including indirect injection carried in retrieved documents and web content that an agent ingests without a human ever reading it. Outbound, we inspect what the model produces before it acts or is returned. For an autonomous agent the input is as dangerous as the output, which is why we treat neither as trusted.
How do you identify and authenticate an agent?
Through API keys today, scoped per agent, with the full audit trail attached to the key. Registry-based agent identity and governance, where each agent carries a verifiable identity independent of its access key, is on the roadmap. It got there because a cybersecurity architect at a large industrial company walked us through what agent identity has to look like at their scale, and that is exactly the kind of input that shapes what we build next.
What does inspection do to latency?
Inspection runs in the low hundreds of milliseconds and happens inside Switzerland, so no round trip leaves the country to perform it. For an interactive agent that is generally not perceptible against model response times, but the honest answer is that it depends on your policy set and payload size, and it is one of the things a pilot phase measures on your own traffic rather than on ours.
Where do the alerts go? We do not want another dashboard.
Into the tools your SOC already runs: events stream to your SIEM, with one-way export into Microsoft Sentinel the pattern most Swiss customers ask for; incident routing into Jira and ServiceNow is on the roadmap. Our own dashboards cover what a SIEM will not show: AI governance (which tools are in use, by whom, with what data) and AI-specific threats, meaning injection and jailbreak attempts, blocked exfiltration, and policy overrides with justifications.
Put a guard between your AI and the world.
A 45-minute session with the founders, online. We run an injection attempt against an agent and show you what stops it. In the pilot phase that follows, you test NativeAI Guard with your own agents, your own traffic and your own use cases.
