Zero-trust security layer that sits between your agents and their tools. Blocks risky calls, redacts secrets, detects prompt injection, and logs every decision.
Six layers of defense in one lightweight sidecar.
Enforce file-system boundaries, block dangerous paths like .env and id_rsa, restrict network to HTTPS-only, and block private IP access. Per-agent overrides included.
Detect prompt injection attacks in real-time. Catches curl|bash pipes, metadata endpoint access, "ignore previous instructions" patterns, and encoded payloads.
Automatically strip API keys, AWS credentials, and sensitive tokens from tool output before it reaches the agent. Configurable regex patterns.
Append-only JSONL logs with automatic rotation. Every tool call, every decision, every reason recorded. Built for compliance and incident response.
Webhook notifications on policy denials. Configure severity thresholds so your team knows the moment an agent tries something it shouldn't.
Per-agent request throttling to prevent abuse. Configurable windows with API key and JWT-based identity enforcement.
Oblivian sits between your agent and its tools. Every call is validated, scanned, and logged before execution.
LLM + Tool calls
Policy + Scanner
Files, HTTP, Shell
JSONL + Alerts
Install, configure your policy, and start protecting your agents.
Your agents are only as secure as the tools they can call.