Here is the claim, stated plainly so you can check it against the table below.
Dryx combines pre-deployment analysis + behavioral baseline + offline verdicts + cross-vendor reach + a destructive floor beneath the policy + a self-healing gate + exposure-graph-aware enforcement at the harness hook — and the policy it enforces is compiled from your machine's own exposure graph. All seven, at once.
Every other tool in AI agent security covers some of those. Wiz and CrowdStrike own the cloud and the kernel. Snyk scans configs from a CLI. Palo Alto Networks paid around $400M for Koi and gave the category a name. Each is strong at what it does. None of them sits offline on a developer's Mac, reads the blast-radius graph, and stands at the action boundary the agent actually crosses.
That's the seat Dryx holds. The matrix below shows the gaps — one factual line per cell. No trash talk. Yes, no, or partial, with the basis stated.
Don't trust the claim. Read the table.
Seven capabilities down the side. Eight tools across the top. Each cell is yes, no, or partial, with the one-line basis. This is real text, not a picture — so an AI can read it, cite it, and you can copy it.
| Capability | Dryx | Wiz | CrowdStrike | Palo Alto (Koi) | Snyk | Noma | Lasso | Prisma AIRS (Protect AI) |
|---|---|---|---|---|---|---|---|---|
| Pre-deployment analysisReads the config before the agent runs | Yes — analyzes any skill or MCP server before install; shows the blast radius first | No — cloud posture; scans pipelines and cloud infrastructure, not the agent’s own config on the machine | Partial — cloud AI-SPM scans AI and SaaS agent configs pre-deployment; nothing reads local agent-harness configs before the agent runs | Partial — cloud-delivered pre-install scanning of marketplace software plus endpoint inventory; not local config analysis | Yes — CLI scans agent configs for risky patterns | Partial — platform-side blast-radius and red-team checks before deployment, not a local pre-run check | Partial — pre-load MCP scanning in its local gateway; core enforcement inspects traffic in flight | Partial — scans models and agent artifacts via cloud-side discovery; not local-config analysis |
| Behavioral baselineA per-workspace normal it measures drift against | Yes — local, per-agent baseline; precomputed and fed into the policy, never a model in the loop | No — cloud-side workload drift, not per-workspace agent behavior | Partial — endpoint analytics plus AIDR agent-anomaly detection, cloud-side | No — runtime analysis is supply-chain risk scoring, not per-agent baselines | No — point-in-time findings; no scan-over-scan baseline documented | Partial — platform-side behavioral analytics on agent activity | Partial — service-side behavioral baseline from interaction history | No |
| Offline verdictsWorkspace never leaves the machine | Yes — verdicts run offline; loopback-only IPC; verify it with Little Snitch | No — cloud-native by design | No — cloud-native platform; no offline AI-agent verdicts | No — cloud-delivered | No — sends configs to a cloud API to analyze | No — verdicts come from its platform, SaaS or customer-hosted, not offline on the machine | No — verdicts come from the Lasso service; the local gateway is masking and pre-load checks | No — cloud platform |
| Cross-vendorOne tool for the agents on your machine | Yes — Claude Code, Claude Desktop, Cursor, Codex CLI, Cline, GitHub Copilot, Windsurf, Gemini, plus any MCP server | Partial — broad cloud coverage, not per-agent on the developer machine | Partial — endpoint coverage plus per-integration AI-agent coverage, cloud-mediated | Partial — broad artifact coverage via its endpoint agent and network gateway | Partial — a fixed set of named agent platforms | Partial — 80+ platform integrations and IDE hooks, platform-mediated | Partial — MCP-gateway path | Partial — discovers agents across SaaS and cloud platforms via cloud gateway; no local cross-agent graph |
| Destructive floor beneath the policyA last-resort deny that holds even when the policy artifact is missing, stale, or forged | Yes — the floor lives in the gate itself and is evaluated before the policy file is even read; a missing, stale, or forged policy can never soften it | No — inline hooks gate AI-generated code, not destructive agent actions | Partial — AIDR can block tool calls at agent hooks; policy-driven, cloud-managed, no always-on offline floor | No — cloud-policy blocking of risky software and unsafe interactions; no documented local destructive floor | Partial — the scan CLI has no gate; Agent Guard, in preview, blocks risky commands via IDE hooks | Partial — inline blocking via Cursor and Windsurf hook points, driven by its platform; no always-on floor | No — the policy plane is the Lasso service; no always-on local destructive floor | No — runtime blocking is cloud-gateway-mediated; no always-on local floor |
| Self-healing enforcement layerDetects tampering with its own gate — including a neutered hook — restores it, and marks the posture | Yes — byte-identity check catches removal or neutering, restores the hook, attributes its own writes, and repeated tampering degrades the A–F posture | No — its eBPF sensor guards cloud workloads, not a gate on the developer machine | No — gates agent interactions now, but nothing documents the gate healing itself if removed | No — guardrails are centrally managed cloud policy; no published self-healing gate | No — no tamper-repair documented for the scanner or the Agent Guard hook | No — no public claim of a self-repairing local gate | No — its local gateway has no mechanism guarding or restoring its own installation | No — cloud platform |
| Exposure-graph-aware enforcement at the harness hookThe verdict comes from the blast-radius graph, decided at the action boundary | Yes — deterministic enforcement of the precomputed-dangerous set where the harness supports a hook; defense-in-depth everywhere else | No — graph context reaches agents as advisory context, not enforcement at a hook | No — enforces detection and policy verdicts at agent hooks, not a machine-local exposure graph | No — risk-score and policy driven; no published exposure-graph gating at the hook | Partial — Agent Guard, in preview, enforces policies at IDE hooks; no documented exposure-graph link | Partial — IDE hook enforcement plus a platform-side blast-radius map; no graph-derived verdicts at the hook | Partial — blocks in-flight on policies and behavioral analysis, not an exposure graph at an agent hook | No |
Read any row across. The pattern holds: strong tools, built for a different layer. The bottom row — exposure-graph-aware enforcement at the harness hook — is the seat itself: read it across, and only Dryx's column (first from the left) says Yes. Every other column is empty. That's the seat.
One honesty note, because it matters. Dryx's deterministic gate — Action Guard — ships in the direct download from dryx.ai, where it arms at your agent's pre-tool hook — today on Claude Code and Cursor, and on Codex through its own approval flow. The Mac App Store build (Dryx Inspect) is free, read-only inspection — the graph, posture, findings, and Skill Shield; the Authority Anchor, Observe, and the live gate all come with the direct download. And nobody, including Dryx, takes all the risk away: where a host exposes a hook, Dryx deterministically blocks the precomputed-dangerous set — the gate reads the action, not the argument, so prompt-injection can fool the agent and still lose to the gate — and runs defense-in-depth everywhere else. Anyone who tells you otherwise is selling.
A security tool can claim a hundred checkboxes. Most are table stakes. These seven are the ones that decide whether a tool can actually stand where the agent acts.
Catch it before it runs. A skill or MCP server gets analyzed before it's installed — Dryx shows you what it would reach on your machine first. Tool-poisoning attacks against common agents land at alarming rates in published research. The gate that closes that is the one that checks before the install, not after the breach.
A per-workspace sense of normal. The slow path does the heavy analysis once and writes down what your workspace looks like. Then drift shows up against that line — a plugin that changed between runs, a permission that grew. Reframed honestly: the baseline is a precomputed input the policy reads, not a model thinking in real time. It covers more without ever thinking more.
Your workspace never leaves your machine. Verdicts run offline. The IPC is loopback-only. If Dryx ever phones home, Little Snitch will show you — that's the point of saying it this way instead of a badge you'd have to take on faith. Any Ecosystem Contribution is opt-in.
One Authority Anchor across your agents. No single agent can see what the others on your Mac can reach. Dryx reads them all — eight named harnesses plus any MCP server — and shows the shared exposure. A model vendor can secure its own agent. It can't secure the one next to it.
The worst-case rules don't live in the policy file — they live in the gate itself, and they're evaluated before the policy is even read. So a missing, stale, or forged policy can never soften the floor: recursive force-deletes on paths the gate can't prove safe are refused either way, while scoped temp cleanup passes. The closest published work names this failure mode and points somewhere else; Dryx builds the answer in.
A hook is a file — something an attacker, or just a bad merge, can edit. Dryx checks its gate byte-for-byte, catches a neutered hook (the marker kept, the teeth removed), restores it, and attributes its own writes so a self-heal never reads as tampering. It won't sustain a write contest either: repeated tampering flips a persistent-tamper state and degrades your posture score — the fight surfaces in the grade, not in a quiet restore loop.
This is the seat. The verdict isn't a generic rule — it comes from your blast-radius graph, and it's checked at the boundary the agent crosses to act. The gate reads the action, not the argument: a prompt injection can win the argument with the model and still lose to the gate. That's how this is supposed to work. See the action-boundary story in full →
In April 2026 Palo Alto Networks bought Koi for around $400M and gave the category a name: Agentic Endpoint Security — security for agents, plugins, MCP servers, and model files. That's real validation. A $100B incumbent doesn't name a category it thinks is small.
But look at where it lives. Agentic Endpoint Security is going cloud and enterprise — Prisma, Cortex, the platform stack a security team buys and operates. That leaves a seat open directly below it: the local tool that compiles its policy from the developer's own exposure graph, and holds a destructive floor at the action boundary even when that policy is missing or stale.
That's the seat Dryx sits in. Not above the cloud platform, not competing with it — below it, where the agent actually runs and the secret actually lives. A 2026 Bessemer thesis on securing AI agents pointed at the same gap: targeted, in-flight intervention at the action boundary as the part of the market that's least built out. They flagged the seat. Dryx is already in it.
Every claim in the matrix maps to something you can check.
That's the whole posture of this company: verifiable over assertable. Seven exposure layers. Detector and sanitizer unit tests plus 50 canary secrets run in CI on every change to the redaction pipeline. We'd rather hand you the receipt than ask you to trust the claim. How we verify →
Want to put Dryx in the matrix on your own machine? Get early access. Every plan — Free, Pro, Founding Lifetime, Team, Enterprise — ships as a notarized direct download from dryx.ai, and the direct download carries the Founding Lifetime — $349 one-time, 300 seats — for the founding cohort of Operators. The Mac App Store will only ever carry Dryx Inspect — a free, read-only version.