Guard, deployment audit

One security grade for every AI agent you run.

Connect a repository read-only and point Guard at your live agent or chatbot. Guard scans the code and MCP config and probes the running agent, then grades the whole deployment A to F with a prioritized, plain-English fix list and the standard behind every finding.

Built for the agents you actually run: a customer-facing chatbot, your n8n, Make or Zapier automations, internal Claude Code crons, and any agent wired into email, files or payments.

Install the GitHub App (private repos, read-only)

Read-only. The GitHub App requests contents: read on only the repos you select. Guard never writes to your code.

What you get

One report on your whole agent estate

A–F

One deployment grade

A single A to F grade for the whole estate.

An AI Bill of Materials

Every agent, chatbot and automation inventoried, with what it can reach.

Ranked risks

Your risks ranked, each with the fix and the cited standard.

$

The money question

Can any agent spend or change production without approval.

How it works

Connect, discover, scan and probe, grade

1

Connect read-only

Public repo, or the GitHub App with contents:read on the repos you pick.

2

Discover

We build your AI Bill of Materials: agents, MCP servers, skills and what they touch.

3

Scan and probe

AgentAuditKit and agent-audit on the code; Garak on your live endpoint.

4

Grade

A to F with prioritized, plain-English fixes and the cited standard. A layer that didn't run is reported as not assessed, never passed.

Best for

The agents you actually run

A customer chatbot

Probed live with Garak for prompt injection, jailbreak and data leakage. Chatbots are the strongest fit for the dynamic layer.

Automations

n8n, Make or Zapier flows wired into your systems.

Agents on your data

Internal Claude Code crons and anything wired into email, files or payments.

Guard pricing

You pay for the exposure we secure

Start with a one-time report. Stay covered with a subscription, because your agents and keys change every week.

One-time posture report

Start with a snapshot

A one-time audit of your whole agent estate. The fee credits toward your first months if you upgrade to a subscription.

(Small)
$500 once
up to 5 agents · best for one chatbot or a couple of automations.
  • One comprehensive deployment report, up to 5 agents
  • Categorized inventory (AI Bill of Materials)
  • Prioritized findings, each with the fix and cited standard
  • Money/production-gate review and a 30-day roadmap
(Medium)
$1,500 once
up to 20 agents · best for a multi-agent workflow.
  • Everything in Small, up to 20 agents
  • Live-endpoint probing (Garak) where an endpoint is provided
(Large)
$3,500 once
up to 50 agents · best for a whole estate.
  • Everything in Medium, up to 50 agents
  • Full static and dynamic coverage across the estate

Subscription

Stay covered

The audit is a snapshot; the subscription is protection. Your agents and keys change every week.

Starter
$199 / month
up to 5 agents · best for one chatbot or a couple of automations.
  • Monthly re-scan and a fresh graded report
  • Alerted when a grade drops
Scale
$1,500 / month
up to 50 agents · best for a whole estate.
  • Weekly re-scan and priority
  • Quarterly human review
Enterprise
Custom
a security team that needs a red-team.
  • NDA, human deep red-team, board report
  • Always custom-quoted
Request a quote

No flat “unlimited” tier — every tier is bounded by agent count, and Enterprise is always custom-quoted. Payments handled by Creem.

FAQ

Is it read-only? Yes. contents:read only. Guard never writes to your repository.

Do you see our secrets? No. We flag where a secret is exposed; we don't collect your credentials.

What if we have no public endpoint? The static scan still grades the deployment; the dynamic layer is reported as not assessed, never passed.

What Guard can and can't assess

Static (code and MCP config): hardcoded secrets, missing MCP auth, tool poisoning, over-broad scopes, unsafe execution, supply chain. Dynamic (live endpoint): prompt injection, jailbreak, data leakage. Guard reads only the files it audits; runtime and infrastructure outside those files, and any language its scanners don't parse, are out of scope. A Guard grade is independent supporting evidence, a point-in-time audit against named standards, not a certification of compliance or a guarantee the deployment is safe. Guidance, not a guarantee. Re-test to confirm the fix worked.