For the CISO
Mault Shield
join the waitlist
Agents run on your machines with system-level access. Shield is how you stay in control of that: five independent defense layers, the four pillars of identity, logging, audit, and transparency, machine-level locking on the files that steer your agents, and 100% attribution of every action, verifiable offline.
100% attribution to the machine
Tamper-resistant kernel tier
Breach-time kill switch
Signed, tamper-evident chain
Shield is the foundation that Governance and Merge run on.
The problem it kills
Your agents have system-level access. Nobody approved what they can do with it
Agents act, no one owns the action
When something goes wrong, “which agent, whose machine, whose authority?” has no answer
Agents can rewrite their own guardrails
The files that constrain an agent are writable by the agent. One injection away from no rules at all
Your audit trail can be rewritten
An editable log proves nothing. Boards and regulators want a record that can’t be changed
The four pillars
The relationship between human and AI, made provable.
Shield begins at the origin, the moment a human decides what the AI should do, and carries the rules of that decision through whatever workflow the work flows into. The authority a human granted is the authority the machine obeyed, and Shield can prove it.
Identity
When something goes wrong, “which agent, whose machine, whose authority?” has no answer
Logging
Every governance decision written as a signed event.
Audit
Events chain-linked; change one and the chain breaks. Local JSONL your existing SIEM ingests through your own pipeline.
Transparency
Anyone can verify the chain themselves, offline.
Access control
Admin control of execution and hook files, written once, pushed to every team.
Kill switch
Halt agent activity at the machine when something is wrong.
File-access assurance
Tamper-evident down to the machine.
The kernel tier locks agent-steering files beneath the layer where attackers and extensions operate. Alongside it, OS-level resistance and always-on tamper logging, three layers of defense, each named for exactly what it can back.
Tier
What it does
Kernel-level
tamper-resistant
tamper-resistant
Enforcement lives below where an attacker or the extension operates, the deepest tier in the stack.
OS-level
tamper-resistant · default
tamper-resistant · default
Admin-controlled, centralized config. Tampering escalates: loud warnings, then the extension refuses to load, up to the breach-time kill switch.
Tamper logging
always on
always on
Every tamper attempt recorded in the signed chain, so nothing happens quietly.
Defense in depth
Five independent layers. Bypassing one doesn't bypass the rest.
Every agent action passes through the whole stack before it reaches the filesystem. Each layer has its own mechanism and its own audit surface, and any one of them can block. The agent gets through only if all five allow it.
five independent checks · an action goes through only if all five allow it
5
Communications governance
Is it sending data externally?
4
Protocol governance
Is this tool allowed for this role?
3
Runtime hooks
Is this file in the declared zone?
2
Process governance
Does this identity have filesystem access?
1
Kernel governance
Is this write permitted at the machine level?
Lock the files that steer your agents.
Identity, logging, audit, and transparency, sealed at the machine level.