AISPM · discover → govern → respond

Govern every model,
agent and MCP server.

AI is no longer an experiment — it's training pipelines, agent workloads, vector stores and MCP servers running with privileged identities. OnDuty AISPM continuously discovers your full AI estate, maps it into one live graph, and surfaces the toxic combinations attackers actually exploit.

Six capabilities, one platform

AISPM, built on
a runtime graph.

Capability / 01

Continuous AI discovery

Inventory every model, agent, dataset, prompt template and MCP server — managed, self-hosted or shadow. Refreshed continuously from runtime, not a one-off scan.

  • Hosted & self-hosted models
  • Agent frameworks fingerprinted
  • Shadow AI usage detected
Capability / 02

Prompt injection & jailbreak defense

Detect indirect prompt injection, jailbreak attempts and data exfiltration in agent traffic. Map back to the exact workload, identity and tool that was abused.

  • OWASP LLM Top 10 coverage
  • Agent trace analysis
  • Tool-call abuse detection
Capability / 03

Training & vector data protection

Find PII, secrets and regulated data inside training sets, embeddings and RAG sources. Flag poisoned datasets and over-permissioned vector stores.

  • DSPM for embeddings
  • Poisoning indicators
  • GDPR / HIPAA / EU AI Act tags
Capability / 04

AI identity & blast radius

Agents act with IAM. We graph every model, agent and MCP server to its identity, secrets and reachable resources — and score the toxic combinations.

  • Agent → IAM mapping
  • Secret & key exposure
  • Lateral reachability
Capability / 05

MCP & tool-chain security

MCP servers are the new attack surface. Audit every server, signed tool, and permitted action — and stop agents from invoking dangerous combinations.

  • Live MCP inventory
  • Tool capability scoring
  • Policy on tool invocation
Capability / 06

Pipeline & supply-chain integrity

Validate the integrity of model weights, fine-tuning jobs and inference containers — from training notebook to production endpoint.

  • Model provenance
  • Fine-tune drift checks
  • Container & SBOM linkage

How the platform works

From noisy findings
to a focused fix.

Unified AI inventory

Every model, agent and MCP server, in one graph.

Stop stitching together a model registry, an agent framework dashboard and a separate vector store audit. OnDuty puts every model, agent, dataset and MCP server on a single data model — so a policy written once applies everywhere, and shadow AI has nowhere to hide.

Hosted & self-hosted modelsAgent frameworks fingerprintedMCP servers & tool calls mapped
Models
Agents
Vector stores
MCP servers

Unified data model

One live AI graph

Toxic combination ranking

Prioritize by what an attacker could actually reach.

Every finding is scored against the agent's identity, the data it can reach and the tools it can invoke — not severity alone. OnDuty surfaces the handful of risks where an over-privileged agent sits next to sensitive data or a dangerous tool, so your team stops triaging alerts that lead nowhere.

Agent → IAM mappingData sensitivity awareBlast-radius ranking

Ranked by dynamic risk score

toxic combination
Agent identity over-privileged92
Reaches sensitive vector store81
Tool call exploitable64
Isolated · low blast radius18

agent://support-copilot reaches prod PII store

Top of 214 open findings

Guided remediation

One root cause, not a hundred alerts.

OnDuty automatically clusters related alerts into a single remediation Mission with a clear owner and deadline. One over-permissioned IAM role granted to a shared agent identity can trigger hundreds of findings — OnDuty groups them so you fix the role once, not the symptom a hundred times.

Auto-grouped by root causeOwner & deadline built inHighest-ROI fixes surfaced first
Mission · Over-permissioned agent identity86 findings

Root cause: shared IAM role agent-runtime-role grants AdministratorAccess to every LangGraph agent that assumes it.

27 of 86 resolvedowner: ml-platform · due in 5 days

1 role

Fix once

86 alerts

Resolves

12

Agents scoped

Model to production trace

Bridge MLOps and runtime AI security.

OnDuty connects the dots between the notebook that trained a model, the registry it shipped through and the agent it's running in today. A live detection traces straight back to the fine-tuning job or training set that introduced it, so your ML team fixes the source, not just the symptom.

Training → registry → runtime linkedBlocked in CI before it shipsFindings traced to source dataset

train.ipynb

Fine-tune job · PII in dataset

Model registry

Blocked · sensitive data tag

billing-bot

Deployed agent

Runtime finding

PII reachable via tool call

OnDuty AI

AI that closes the loop, not just flags it.

OnDuty AI shortens the distance between finding a risk and resolving it. Ask a question and get back a query, not a support ticket. Chat with your entire AI estate. And let AI agents handle the analysis and legwork, so your team spends its time on judgment calls instead of repetitive investigation.

AI fixes for IAM & tool policiesNatural-language asset searchAutonomous AI agents

AI Policy Fixes

Generated patches for IAM & tool policies

AI Discovery

Ask questions, get asset queries

AI Assistant

Chat with your AI estate

AI Agents

Investigate and act autonomously

The AISPM lifecycle

From inventory
to incident response.

Phase / 01

Discover

Agentless scan of cloud, K8s and CI to inventory every model, agent and dataset.

Phase / 02

Assess

Score each AI asset against OWASP LLM Top 10, NIST AI RMF and EU AI Act controls.

Phase / 03

Detect

Continuously watch agent traffic and MCP calls for injection, exfiltration and abuse.

Phase / 04

Respond

Prioritized findings ship with runtime evidence, owner and a one-click remediation path.

FAQ

Frequently asked questions.

AISPM (AI Security Posture Management) is a security category focused on discovering and governing the full AI estate — models, autonomous agents, training data, vector stores and MCP servers — rather than treating AI as just another workload. It combines inventory, identity mapping and runtime detection into one graph purpose-built for how agentic AI actually behaves.

Replace shadow AI with one graph

See the toxic combination,
not the 400 models.

See your real AI inventory, identity graph and top toxic combinations in a 30-min guided demo with our team.

  • Agentless discovery of every model, agent, dataset & MCP server
  • One graph of AI assets, identities, secrets and reachable data
  • Prompt injection & jailbreak detection mapped to OWASP LLM Top 10
  • AI identity blast-radius analysis for every agent and MCP server
  • NIST AI RMF · EU AI Act · GDPR / HIPAA — audit-ready coverage