PyroTrace logo
PyroTraceA product of Pyro Security
ProductSecurityAboutGet a demo
PyroTrace logoPyroTrace

PyroTrace independently verifies what your production AI agents can reach, what they actually touch, and which of it is sensitive.

Product
PlatformData ReachAgent MapChangelog
Compliance
Security
Company
AboutContactDocsStatus
Legal
LegalPrivacyTermsCookies

© 2026 Pyro Security, Inc. All rights reserved.

The Evidence Layer for Agentic AI

Independently verify the effective access and sensitive data reach of every AI agent and MCP server you run. Then reduce that exposure.

Get a demo→How it works
Reach
What each agent is granted
Used
What it demonstrably touched
Sensitive
What it should never reach
DashboardLive posture
AI Security Score
72
2 agents flagged
1 shadow MCP server
Resource-Reach Utilization
6.4%
3 of 47 reachable touched
Sensitive Reach
1
PII-classified, observed
Unused Grants
118
never used in any observed run
Inventory Coverage
92%
agents with evidence backing

Posture you can defend, in six numbers.

Every metric traces back to evidence. It shows what was granted, what was observed, and what the data classification says about it.

AI Security Score

One posture number for your agent fleet is derived from reach, usage, and sensitivity. It is not based on alert volume.

Resource-Reach Utilization

The share of modeled reachable resources each agent actually touched. Low utilization marks least-privilege candidates.

Sensitive Reach

We flag resources that hold PII, PHI, or payment data and are within an agent's reach. We do this before anything touches them.

Shadow Access & Egress

Observed activity outside the modeled reach set, including external endpoints no policy predicted.

Unused Grants

Permissions no observed run has exercised, prioritized for least-privilege review.

Inventory Coverage

How much of your agent fleet is evidence-backed, so you know what the numbers do and don't cover.

Run starts
orchestrator prompt received
Gateway
MCP tool call
payments-tools · get_customer()
MCP gateway
AWS API call
s3:GetObject · orders-prod
CloudTrail
Resource touched
2.1 MB egress · PII-classified
Sensor

Every edge states how it was derived.

Every agent, every MCP server, and the identity behind it.

Agents are discovered and ranked by risk with the non-human identity behind each one. Inventory entries are admitted on an evidence ladder of registry facts, structural facts, operator declarations, observed behavior. A name is never evidence.

Open any observed run as a Run Story: the causal chain from prompt to tool call to cloud API to resource touched. This story includes orchestrator and subagent delegation, denied reads, and credential hops.

The flagship question: what can it reach, and what did it use?

Agent Resource-Reach Utilization is the share of reachable resources an agent actually touched. Low utilization with high sensitive reach identifies a practical least-privilege opportunity: review access with no observed use.

One click exports the evidence for each agent. The export covers reach, usage, and sensitivity in the format your auditor requested.

PII
47
Reachable · granted
3
Touched · observed
1
Sensitive · classified

Your agent fleet, as a live map.

Agent-rooted, metro-map edges, semantic color: green is observed normal, yellow is first-seen, red is risky, blue is internet egress. Only sensor-observed traffic animates.

checkout-agentrole/agent-checkoutsupport-agentrole/agent-supportmcp-gatewaypayments-toolss3://orders-prodrds/customerssecrets/paymentsPIIbedrock/claudeapi.vendor.io+41
ObservedFirst-seenRiskyInternetGranted, unused

Findings that speak your auditor’s language.

Issues are derived by joining reach and usage data. They are not based on signatures. Each issue includes its framework mapping and evidence.

OWASP LLM Top 10

Excessive agency and insecure tool integrations, grounded in observed reach

MITRE ATLAS

Agent-relevant techniques mapped to the evidence that triggered them

NIST AI RMF

Measure and Manage functions backed by exportable, evidence-linked reports

Built around the same evidence graph.

Intelligence Map

An AI-rooted graph: pick an agent or MCP server and see who can access it, its open issues, and everything within its reach.

Detections

We identify changes worth attention, including newly observed paths, shared credentials, and unauthenticated MCP servers. Every detection includes evidence.

Identities

The non-human identities behind every agent, plus the workforce principals who can assume them.

Health

Sensor, collector, and integration health, so you always know how fresh your evidence is.

PyroTrace Sensorkernel · eBPFAWS CloudTrailcontrol planeMCP gatewaytool callsLLM telemetryOTel GenAI · sidecarSIEM importSplunk · SentinelEDRhost activityEvidenceledger

AWS today. Observed from the kernel.

The PyroTrace Sensor observes workload traffic at the kernel (eBPF, read-only). CloudTrail, MCP gateway, LLM telemetry, SIEM, and EDR imports corroborate it. Reach is modeled from live IAM policy. This includes the model layer and identifies who can invoke, fine tune, or read artifacts from Bedrock and SageMaker models.

Claims stay evidence-bounded: we record that agent-attributed traffic reached a classified resource, with bytes out. Payload content remains unverified, by design.

See your agents' real reach.

A guided walkthrough of the agent inventory, Data Reach, Agent Map, and the evidence behind each exposure finding.

Get a demo →Security & trust