CydraLabs

Platform

A shared control plane for every consequential agent action

CydraLabs is built as one modular, model-agnostic platform. Products share identity, policy, approval, telemetry and evidence services, so controls stay consistent as new products arrive.

Architecture

Platform layers

The architecture separates applications from the runtime, the gateway, model routing and enterprise connectors. Each layer carries its current status.

  1. Applications

    CydraShield, CydraGateway and CydraGovern today; CydraSOC, CydraDevSec, CydraCloud and CydraWorkforce later.

    Launch products in the PoC build

    Available
  2. Agent Runtime

    Planning, reasoning, memory, orchestration, evaluation and human approval for enterprise agents.

    Roadmap
  3. CydraGateway

    Identity, authorisation, policy enforcement, guardrails and MCP controls. A2A controls are on the roadmap.

    Available
  4. Model Router

    Select OpenAI, Anthropic, Google, open-weight or customer-hosted models by task, latency, cost, privacy and deployment needs.

    Roadmap
  5. Enterprise Connectors

    OpenAI, Anthropic, MCP, Microsoft Entra ID and GitHub adapters today; SAP, Salesforce, ServiceNow, Microsoft 365 and cloud platforms later.

    Mock adapters Available; live APIs Preview

    Preview

How it works

The agent action-control workflow

Every proposed action passes through the same deterministic pipeline. No analytical service sits on the synchronous path: risk scoring and graph projection update after the decision.

  1. Step 1: Receive the proposed action

    The agent submits the tool call to CydraGateway with an idempotency key before anything runs.

  2. Step 2: Authenticate the agent

    A signed, short-lived workload token is checked for audience, expiry, tenant and replay. Suspended agents are denied.

  3. Step 3: Resolve identity and target

    Owner, delegated user, tool, operation, target and environment are resolved. Unknown tools are denied by default.

  4. Step 4: Gather context

    Data classification, the latest Agent Risk Score and Agent Security Graph context are attached to the decision input.

  5. Step 5: Evaluate policy

    Versioned, deterministic policy is evaluated. A policy engine error fails closed.

  6. Step 6: Inspect content

    Parameters and payloads are checked for secrets, personal data and prompt-injection patterns.

  7. Step 7: Decide

    Allow, deny or require approval. Deny outranks approval, approval outranks allow, and no matching rule means deny.

  8. Step 8: Approve when required

    A named approver issues a single-use, time-bound token bound to the hash of the exact request.

  9. Step 9: Execute with scoped credentials

    The action runs with a per-execution credential limited to the target and a short lifetime.

  10. Step 10: Record evidence

    The decision and result are appended to the tenant's hash-linked evidence chain and signed.

Approval tokens

Approval produces a signed token bound to the tenant, agent, delegated subject, tool, operation, target and a hash of the exact request. It expires and can be used once.

Deterministic policy

Policies are versioned rule documents evaluated by Open Policy Agent or an embedded evaluator with identical semantics, tested against the same golden cases.

Containment

The kill switch suspends or revokes an agent and its credentials. Pending and approved actions from a contained agent are revoked before execution.

Agent Security Graph

Relationships, not lists

Nodes for users, agents, models, MCP servers, tools, data and actions; edges for delegation, access and use. The graph supports search, filter, expansion, shortest path, transitive access, blast radius, high-risk paths, point-in-time history and export.

Status: Available

Agent Security Graph example: a user delegates to a sales agent, which uses a model, connects to an unreviewed MCP server and can call a CRM tool. A highlighted path shows the agent reaching confidential customer data and an external email action through the unreviewed MCP server.delegatesusesconnectscan callexposesreadsreachesUserDelegating humanSales agentagent://acme/salesModelFoundation modelMCP serverUnreviewedCRM toolwriteCustomer dataConfidentialEmail sendExternal egressHigh-risk path (dashed)
Illustrative example, not customer data.

Shared services

Platform capabilities

Foundations used by every product, with their current status.

  • Multi-tenant row-level isolation

    PostgreSQL row-level security on every tenant table, enforced for the application role.

    Available
  • Nine-role access control

    One permission matrix enforced by the API and reflected in the portal.

    Available
  • OIDC sign-in (Keycloak)

    OpenID Connect sign-in through a backend-for-frontend session.

    Available
  • Microsoft Entra ID and Okta sign-in

    Standard OIDC authorisation-code sign-in; Entra ID and Okta use the same configuration, not yet validated against live tenants.

    Preview
  • Organisation onboarding

    Create an organisation, choose a primary region and assign the initial administrator.

    Available
  • Agent Security Graph

    Search, expand, shortest path, transitive access, blast radius, high-risk paths, history and export.

    Available
  • Connector framework (mock adapters)

    OpenAI, Anthropic, MCP, Microsoft Entra ID and GitHub adapters on one contract, with mock data.

    Available
  • Live connector APIs

    The same adapters calling live provider APIs.

    Preview
  • OpenTelemetry pipeline

    API and database traces exported over OTLP when configured.

    Available
  • Hash-linked, signed evidence chain

    Append-only records, each hashing its predecessor and signed with Ed25519.

    Available
  • Notifications

    In-app notifications and signed webhooks.

    Beta
  • Reports and export

    Generate reports and export them to S3-compatible object storage.

    Available
  • Privileged-operation audit

    Every privileged change writes an audit event in the same transaction.

    Available
  • Versioned REST API

    OpenAPI, cursor pagination, structured errors, correlation IDs and optimistic concurrency.

    Available
  • Agent runtime and marketplace

    Planning, memory, orchestration and evaluation for enterprise agents; partner marketplace.

    Roadmap

Status labels

Available
Implemented, tested and demonstrable in the current proof-of-concept build.
Beta
Implemented and demonstrable, with documented limitations.
Preview
Interface or mock implementation behind a real contract; live integration not yet enabled.
Roadmap
Not built in this phase. Shared platform foundations are in place.

Integrations

Connectors on one contract

Each connector implements the same discovery interface, so mock and live adapters are interchangeable. Integrations are named in text; no logos are used.

  • OpenAI

    Preview

    Discover assistants, models and tool definitions.

    Mock adapter Available; live API Preview

  • Anthropic

    Preview

    Discover models and agent configurations.

    Mock adapter Available; live API Preview

  • Model Context Protocol (MCP)

    Beta

    Enumerate MCP servers and tools via tools/list.

    Generic MCP discovery Beta

  • Microsoft Entra ID

    Preview

    Map service principals, app registrations and delegated permissions.

    Mock adapter Available; live API Preview

  • GitHub

    Preview

    Find agents and tokens in repositories and apps.

    Mock adapter Available; live API Preview

Planned Roadmap

  • Okta — Identity
  • Google (Gemini) and open-weight models — Model provider
  • Microsoft Sentinel — Security operations
  • Splunk — Security operations
  • Google Security Operations — Security operations
  • CrowdStrike — Security operations
  • Microsoft Defender — Security operations
  • AWS Security Hub — Cloud security
  • ServiceNow — IT service management
  • Jira — Work management
  • GitLab — Developer platform
  • Salesforce — Business application
  • SAP — Business application
  • Microsoft 365 — Productivity
  • AWS, Azure and Google Cloud — Cloud platform

Deployment and trust

Design properties

How the current build is designed. These statements describe architecture, not certifications.

Modular deployment
Web, API and worker units packaged as containers; PostgreSQL, Redis, object storage and an OIDC provider as dependencies. Runs locally with Docker Compose.
Tenant isolation
Row-level security on every tenant table with a non-owner application role; cross-tenant lookups return not found.
Hash-linked evidence chain
Records hash their predecessor and are signed with Ed25519. The application role cannot update or delete evidence.
Fail-closed
Policy engine or detector errors deny the action unless an explicit, acknowledged fail-open setting applies to a read-class tool.
OIDC and sessions
OpenID Connect sign-in via a backend-for-frontend; HttpOnly session cookie plus double-submit CSRF token.
No secrets in logs
Structured logging with redaction; payloads stored as hashes plus redacted previews by default.
Explore the products