Cerberus blocks the lethal trifecta at the tool boundary — see the 525-run evidence set.
WARDENBy Odingard

Governed Autonomy

The engineers who build our runtime security work on your agent estate

Warden is Odingard's services organization. Same people, same research, applied to the systems you are already running — red-teaming autonomous agents, constraining what they can reach, and turning the results into evidence an auditor accepts.

Assurance built for software that waits is the wrong tool here

A traditional assessment describes an application that does what it is told. An agent chooses its next action from context it was handed at runtime, which means the interesting question is not what the code can do but what the agent can be persuaded to do with the credentials you gave it.

  1. The boundary is the tool call, not the perimeterNetwork controls do not see an agent reading a document and then calling an API with what it just read.
  2. Findings expire faster than reportsA point-in-time assessment of a system whose behavior depends on its prompt is stale before it is formatted.
  3. Regulators want evidence, not assertionsThe EU AI Act, ISO/IEC 42001 and NIST AI RMF all ask what you can show, not what you have documented.

The five practices

AI Governance

Get an AI program that satisfies the EU AI Act, ISO/IEC 42001 and NIST AI RMF on evidence rather than intent.

Continuous Compliance

Run the control monitoring and evidence operation without hiring a team to do it.

Deployment

Get Cerberus and TraceLock into production, integrated with what you already run.

Advisory

Standing access to the people who do this work, for the decisions that do not wait for an engagement.

How a Warden engagement runs

Every practice follows the same shape, because the value is in the sequence: find out what is true, prove it adversarially, fix the boundary, then leave the evidence running.

1

Establish the estate

Inventory the agents, models, tools and data paths actually in use — including the ones nobody registered.

2

Test it adversarially

Attack the agents with the same techniques we research, so the failure mode surfaces in an exercise rather than in production.

3

Constrain the boundary

Put the enforceable control where the action happens, then confirm the attack that worked no longer does.

4

Leave evidence behind

Wire the result into continuous monitoring so the next auditor question is answered by a system, not by a person remembering.

Start with a briefing, not a statement of work

Tell us what your agents can reach today. We will tell you which of these engagements is worth doing first, and which ones you do not need yet.