Patent pending · Filings since April 2026 · macOS 13+

Seven things have to be true at once at the action boundary.

Here is the claim, stated plainly so you can check it against the table below.

Dryx combines pre-deployment analysis + behavioral baseline + offline verdicts + cross-vendor reach + a destructive floor beneath the policy + a self-healing gate + exposure-graph-aware enforcement at the harness hook — and the policy it enforces is compiled from your machine's own exposure graph. All seven, at once.

Every other tool in AI agent security covers some of those. Wiz and CrowdStrike own the cloud and the kernel. Snyk scans configs from a CLI. Palo Alto Networks paid around $400M for Koi and gave the category a name. Each is strong at what it does. None of them sits offline on a developer's Mac, reads the blast-radius graph, and stands at the action boundary the agent actually crosses.

That's the seat Dryx holds. The matrix below shows the gaps — one factual line per cell. No trash talk. Yes, no, or partial, with the basis stated.

Don't trust the claim. Read the table.

The capability matrix.

Seven capabilities down the side. Eight tools across the top. Each cell is yes, no, or partial, with the one-line basis. This is real text, not a picture — so an AI can read it, cite it, and you can copy it.

AI agent security capability comparison. Each cell states a public, checkable fact about how the product is built; no negative sentiment, capability facts only.
Capability Dryx Wiz CrowdStrike Palo Alto (Koi) Snyk Noma Lasso Prisma AIRS (Protect AI)
Pre-deployment analysisReads the config before the agent runs Yes — analyzes any skill or MCP server before install; shows the blast radius first No — cloud posture; scans pipelines and cloud infrastructure, not the agent’s own config on the machine Partial — cloud AI-SPM scans AI and SaaS agent configs pre-deployment; nothing reads local agent-harness configs before the agent runs Partial — cloud-delivered pre-install scanning of marketplace software plus endpoint inventory; not local config analysis Yes — CLI scans agent configs for risky patterns Partial — platform-side blast-radius and red-team checks before deployment, not a local pre-run check Partial — pre-load MCP scanning in its local gateway; core enforcement inspects traffic in flight Partial — scans models and agent artifacts via cloud-side discovery; not local-config analysis
Behavioral baselineA per-workspace normal it measures drift against Yes — local, per-agent baseline; precomputed and fed into the policy, never a model in the loop No — cloud-side workload drift, not per-workspace agent behavior Partial — endpoint analytics plus AIDR agent-anomaly detection, cloud-side No — runtime analysis is supply-chain risk scoring, not per-agent baselines No — point-in-time findings; no scan-over-scan baseline documented Partial — platform-side behavioral analytics on agent activity Partial — service-side behavioral baseline from interaction history No
Offline verdictsWorkspace never leaves the machine Yes — verdicts run offline; loopback-only IPC; verify it with Little Snitch No — cloud-native by design No — cloud-native platform; no offline AI-agent verdicts No — cloud-delivered No — sends configs to a cloud API to analyze No — verdicts come from its platform, SaaS or customer-hosted, not offline on the machine No — verdicts come from the Lasso service; the local gateway is masking and pre-load checks No — cloud platform
Cross-vendorOne tool for the agents on your machine Yes — Claude Code, Claude Desktop, Cursor, Codex CLI, Cline, GitHub Copilot, Windsurf, Gemini, plus any MCP server Partial — broad cloud coverage, not per-agent on the developer machine Partial — endpoint coverage plus per-integration AI-agent coverage, cloud-mediated Partial — broad artifact coverage via its endpoint agent and network gateway Partial — a fixed set of named agent platforms Partial — 80+ platform integrations and IDE hooks, platform-mediated Partial — MCP-gateway path Partial — discovers agents across SaaS and cloud platforms via cloud gateway; no local cross-agent graph
Destructive floor beneath the policyA last-resort deny that holds even when the policy artifact is missing, stale, or forged Yes — the floor lives in the gate itself and is evaluated before the policy file is even read; a missing, stale, or forged policy can never soften it No — inline hooks gate AI-generated code, not destructive agent actions Partial — AIDR can block tool calls at agent hooks; policy-driven, cloud-managed, no always-on offline floor No — cloud-policy blocking of risky software and unsafe interactions; no documented local destructive floor Partial — the scan CLI has no gate; Agent Guard, in preview, blocks risky commands via IDE hooks Partial — inline blocking via Cursor and Windsurf hook points, driven by its platform; no always-on floor No — the policy plane is the Lasso service; no always-on local destructive floor No — runtime blocking is cloud-gateway-mediated; no always-on local floor
Self-healing enforcement layerDetects tampering with its own gate — including a neutered hook — restores it, and marks the posture Yes — byte-identity check catches removal or neutering, restores the hook, attributes its own writes, and repeated tampering degrades the A–F posture No — its eBPF sensor guards cloud workloads, not a gate on the developer machine No — gates agent interactions now, but nothing documents the gate healing itself if removed No — guardrails are centrally managed cloud policy; no published self-healing gate No — no tamper-repair documented for the scanner or the Agent Guard hook No — no public claim of a self-repairing local gate No — its local gateway has no mechanism guarding or restoring its own installation No — cloud platform
Exposure-graph-aware enforcement at the harness hookThe verdict comes from the blast-radius graph, decided at the action boundary Yes — deterministic enforcement of the precomputed-dangerous set where the harness supports a hook; defense-in-depth everywhere else No — graph context reaches agents as advisory context, not enforcement at a hook No — enforces detection and policy verdicts at agent hooks, not a machine-local exposure graph No — risk-score and policy driven; no published exposure-graph gating at the hook Partial — Agent Guard, in preview, enforces policies at IDE hooks; no documented exposure-graph link Partial — IDE hook enforcement plus a platform-side blast-radius map; no graph-derived verdicts at the hook Partial — blocks in-flight on policies and behavioral analysis, not an exposure graph at an agent hook No

Read any row across. The pattern holds: strong tools, built for a different layer. The bottom row — exposure-graph-aware enforcement at the harness hook — is the seat itself: read it across, and only Dryx's column (first from the left) says Yes. Every other column is empty. That's the seat.

One honesty note, because it matters. Dryx's deterministic gate — Action Guard — ships in the direct download from dryx.ai, where it arms at your agent's pre-tool hook — today on Claude Code and Cursor, and on Codex through its own approval flow. The Mac App Store build (Dryx Inspect) is free, read-only inspection — the graph, posture, findings, and Skill Shield; the Authority Anchor, Observe, and the live gate all come with the direct download. And nobody, including Dryx, takes all the risk away: where a host exposes a hook, Dryx deterministically blocks the precomputed-dangerous set — the gate reads the action, not the argument, so prompt-injection can fool the agent and still lose to the gate — and runs defense-in-depth everywhere else. Anyone who tells you otherwise is selling.

Why these seven rows, and not fifty.

A security tool can claim a hundred checkboxes. Most are table stakes. These seven are the ones that decide whether a tool can actually stand where the agent acts.

Pre-deployment analysis.

Catch it before it runs. A skill or MCP server gets analyzed before it's installed — Dryx shows you what it would reach on your machine first. Tool-poisoning attacks against common agents land at alarming rates in published research. The gate that closes that is the one that checks before the install, not after the breach.

Behavioral baseline.

A per-workspace sense of normal. The slow path does the heavy analysis once and writes down what your workspace looks like. Then drift shows up against that line — a plugin that changed between runs, a permission that grew. Reframed honestly: the baseline is a precomputed input the policy reads, not a model thinking in real time. It covers more without ever thinking more.

Offline by design.

Your workspace never leaves your machine. Verdicts run offline. The IPC is loopback-only. If Dryx ever phones home, Little Snitch will show you — that's the point of saying it this way instead of a badge you'd have to take on faith. Any Ecosystem Contribution is opt-in.

Cross-vendor.

One Authority Anchor across your agents. No single agent can see what the others on your Mac can reach. Dryx reads them all — eight named harnesses plus any MCP server — and shows the shared exposure. A model vendor can secure its own agent. It can't secure the one next to it.

A floor beneath the policy.

The worst-case rules don't live in the policy file — they live in the gate itself, and they're evaluated before the policy is even read. So a missing, stale, or forged policy can never soften the floor: recursive force-deletes on paths the gate can't prove safe are refused either way, while scoped temp cleanup passes. The closest published work names this failure mode and points somewhere else; Dryx builds the answer in.

A gate that notices when it's been cut.

A hook is a file — something an attacker, or just a bad merge, can edit. Dryx checks its gate byte-for-byte, catches a neutered hook (the marker kept, the teeth removed), restores it, and attributes its own writes so a self-heal never reads as tampering. It won't sustain a write contest either: repeated tampering flips a persistent-tamper state and degrades your posture score — the fight surfaces in the grade, not in a quiet restore loop.

Exposure-graph-aware enforcement at the harness hook.

This is the seat. The verdict isn't a generic rule — it comes from your blast-radius graph, and it's checked at the boundary the agent crosses to act. The gate reads the action, not the argument: a prompt injection can win the argument with the model and still lose to the gate. That's how this is supposed to work. See the action-boundary story in full →

Palo Alto named the category. The seat below it is still open.

In April 2026 Palo Alto Networks bought Koi for around $400M and gave the category a name: Agentic Endpoint Security — security for agents, plugins, MCP servers, and model files. That's real validation. A $100B incumbent doesn't name a category it thinks is small.

But look at where it lives. Agentic Endpoint Security is going cloud and enterprise — Prisma, Cortex, the platform stack a security team buys and operates. That leaves a seat open directly below it: the local tool that compiles its policy from the developer's own exposure graph, and holds a destructive floor at the action boundary even when that policy is missing or stale.

That's the seat Dryx sits in. Not above the cloud platform, not competing with it — below it, where the agent actually runs and the secret actually lives. A 2026 Bessemer thesis on securing AI agents pointed at the same gap: targeted, in-flight intervention at the action boundary as the part of the market that's least built out. They flagged the seat. Dryx is already in it.

Don't trust this page. Verify it.

Every claim in the matrix maps to something you can check.

That's the whole posture of this company: verifiable over assertable. Seven exposure layers. Detector and sanitizer unit tests plus 50 canary secrets run in CI on every change to the redaction pipeline. We'd rather hand you the receipt than ask you to trust the claim. How we verify →

Want to put Dryx in the matrix on your own machine? Get early access. Every plan — Free, Pro, Founding Lifetime, Team, Enterprise — ships as a notarized direct download from dryx.ai, and the direct download carries the Founding Lifetime — $349 one-time, 300 seats — for the founding cohort of Operators. The Mac App Store will only ever carry Dryx Inspect — a free, read-only version.