Skip to main content

Posture

Posture answers the auditor's question directly: which controls are actually exercised by agent activity, and where is the evidence?

Runtime-attested compliance

Pick a framework and a window. Posture shows:

  • how many of the framework's controls carry at least one runtime attestation in the window, and which can never be evidenced by agent activity;
  • the share of identified decisions that attest a control, with the remainder broken down honestly: no rule fired, no taxonomy node, or a node that maps to no control in this framework;
  • the connected evidence: each firing rule, the command that triggered it, its taxonomy node and the controls it attests, sorted by how often it fired.

Click a control to see only the events evidencing it. Export evidence (CSV) writes the window as a file you can hand over.

The validation suite

Run validation fires 50 known AI-agent attacks, across prompt injection, data exfiltration, file permissions, credential access, network egress, resource abuse, output integrity, model poisoning and reconnaissance, at your organisation's actual AgentShield configuration. Nothing is executed. Every block produces a real, date-stamped attestation event, so a fresh organisation can show evidence on day one. The report is downloadable as Markdown.

Drift

Where an MCP server declares its capabilities, Posture compares what was declared with what agents were observed calling, so a server that quietly grew a write_file tool shows up as drift.

OWASP matrix

The OWASP maturity by adoption-tier matrix places every discovered agent on a grid of how governed it is against how much it is used, so you can see which agents to bring under control first.