Defensive intelligence · Alpha
Security built for autonomous systems.
Threeum Defense reviews what your AI agents do through an integrated gateway, and contains suspicious actions in a controlled local simulation — all under your policy. It runs quietly in the background, not as a chat assistant.
What it does
Background defense, in plain terms.
As teams hand more work to AI agents, the number of actions and tool boundaries a defender has to review multiplies quickly. Threeum Defense is built to keep up — reviewing agent actions, deciding by your rules, and containing in simulation, always under your control.
01Watch what agents do
It records the agent actions that pass through the gateway, plus opt-in aggregate host metrics you enable, and turns them into a single, consistent event stream for review.
02Understand & connect
Small specialist models and correlation link individually harmless actions into a bigger picture, surfacing coordinated behavior across many identities and systems.
03Contain under your policy
When an action looks like an attack, the gateway holds or blocks it and runs containment steps in a controlled simulation — only within what your policy allows — and records why, with a timeline. It does not take over your OS or network in this alpha.
A continuous loop — decisions are made by your rules, with model signals as input. How it works →
Model family
Seven models, each for one job.
Threeum Defense is a family of small, task-specific models sharing one event format and policy language — not a single large model. Every family is experimental today.
Edge
ExpLightweight detection close to the workload.
Behavior
ExpLearns what normal looks like, flags drift.
Guardian
ExpReviews AI-agent tool and API actions.
Swarm
ExpFinds coordinated activity across identities.
Reasoning
ExpExplains incidents from the evidence.
Enterprise
ExpCorrelates activity across an organization.
Infrastructure
ExpWatches infrastructure and network telemetry.
Where the product is
What works today, and what's next.
Today Alpha
- A hosted alpha runtime and API, also available to run in your own environment.
- An integrated agent gateway that allows, holds, or blocks tool and API actions under your policy.
- Seven trained research models (statistical) plus an optional text companion.
- An opt-in, read-only host collector for aggregate resource metrics (pseudonymous host id).
- Guarded local simulation for containment, and incidents with reasons and a timeline.
- An operations console that connects to your runtime and shows live data.
In development Building
- Full production integrations with existing security tooling, added only once verified.
- Enterprise SSO and high-availability operation.
- Deeper cross-organization correlation and campaign views.
- Production hardening and independent field evaluation.
Start with the runtime.
Run the local API, register an agent, and route its tool calls through the gateway. The dashboard connects to your own runtime on the same origin.