Backed by Agentic Builders  ·  AARM-aligned verification for AI agents

Anyone can watch their agents.
Few can verify them

Connect once. Heron records every action in a chain you can reconstruct, flags what breaks your rules, and can block what crosses the line

The research

We asked 50+ security leaders how they'd trust an AI agent

An AI agent isn't static software. It changes every day — and security that checks once a year wasn't built for that.

“Traditional security only handles point-in-time detection. If the agent keeps updating its memory, it's a new version every time — you can't do once-a-year testing. It has to be continuous.”

VP, AI Security
Broker-dealer

So every security team is told to verify the agent. None of them has a way to.

“Every framework says verify the agent. Nobody says how to check.”

ICT-risk consultant
Investment bank

“How do you prove the agent won't read what it shouldn't? How can you prove that?”

Fractional CISO
Healthcare

A certificate doesn't answer it. They want to see what the agent actually does, from where it really runs.

“SOC 2 is a nice-to-have, not self-verified. Can I actually see how it's operating?”

Security architect + CISO
Enterprise

“We don't trust the registry. We pull the data from where the agent is actually deployed.”

Identity & access lead
Large bank

Across every conversation, one answer: watching isn't enough. They need continuous evidence of what the agent actually does.

That's Heron.

The path

From a free check to enforcement

One product, five steps, all free to run yourself: you pay only when we keep the rules current for you. Your data never leaves your perimeter

Free

Run the evidence check

Six questions against the traces you already have. No install, nothing sent anywhere. A one-page report of what you can prove today

Get the skill on GitHub

Don't have an AI gateway or traces yet? See where to start

01
02
FreeOpen soon

Install Heron, self-hosted

Close the gaps: collect the full record inside your own perimeter. Shadow mode: every action still gets its verdict, nothing is blocked yet, and your data stays home

Book a demo for pre-access
FreePaid

Keep the rules current

Every finding resolves three ways: a fix on your side, a fix in Heron, or a rule that needs a human. Autonomous agents run the triage; only the human calls reach you

Run it yourselfFree
Hand it to us, we keep them currentPaid
03
04
Coming soon

Map to your compliance controls

The same record becomes the evidence line in the frameworks you report against: SOC 2, ISO 27001, EU AI Act. Recognised, not explained

FreeWhen you're ready

Turn enforcement on

Once shadow runs quiet, flip it: an action that breaks your published rules is blocked before it runs, not written up after. You hold the switch

05
The Heron platform

One integration. Every agent covered

One hook into the platform your agents run on. Every action gets checked, and every decision lands on a signed record you can open any time

H
Trust overview
All tenants
live
AARM-aligned
42
clients
1,284
agents covered
318,492
actions checked · 24h
100%
coverage
41ms
check latency · p95
Coverage no bypass
100%
0 of 318,492 actions bypassed Heron · 24h
every tool call checked before it runs
Actions checked 318,492
+6.2% vs the previous 24h
Per-action volume · 24h
Tenant health avg 94 / 100
Northwind Trading
98
Vantage Media
96
Meridian Health
95
Lumen Retail
91
Aperture Finance
88
Composite of coverage, intent drift & review response · 0–100
Exposure prevented
PII touches · 24h 4,128
312 redacted 27 blocked
External egress · 24h 86
11 stopped at the perimeter 0 leaked
Evidence freshness continuous
SOC 2 · CC6.1 2m ago
SOC 2 · CC6.7 1m ago
ISO 27001 · A.5.18 3m ago
EU AI Act · Art.12 4m ago
No control older than 6 min
Response
Step-up SLA · median 3m 12s
MTTR · flag closed 7m 40s
First-seen behavior · 24h 3
Detect, hold, heal — before the action runs
Receipts tamper-evident
318,492 issued & signed · 24h
One signed receipt per checked action — action, context, decision & outcome, hash-chained.
100%
signed
Ed25519
signature
continuous
hash chain
Export evidence-log last receipt 2s ago

Connect, check, prove

01 · Connect

Plug in your platform once

Heron hooks into the layer your agents run on, not each agent one by one. Every agent on the platform, the ones you run today and the ones you ship next month, is covered automatically. One integration, full coverage, by construction

02 · Check

Every action, checked before it runs

Tracing shows what your agents did. Heron rules on it: every action checked against your published policy. Allow, deny, or step up to a human. In shadow mode verdicts are recorded, not enforced, so nothing breaks while you watch what would have been blocked

03 · Prove

Live, signed proof

Every decision is written to a tamper-evident, hash-chained record. It cannot be altered after the fact, and it never goes stale because it updates with every action. Your buyer's security team opens it and queries the history any time, mapped to the frameworks they already report against

Frameworks

Speaks the language security already uses

Assess once, report against many. Each decision Heron enforces lands on a control your buyer already knows — evidence they recognise, not a format they have to learn

receipt #4a92signed
intent"Summarize Q3 sales for leadership"
priordatabase.query(customers)
actionemail.send → [email protected]
dataPII · CONFIDENTIAL
drift0.72 · semantic distance
decisiondeny · context-dependent
sig ed25519:9f3c…a210prev #4a91
recognised as
SOC 2CC6.7 · Restrict data movement & removal
ISO 27001A.8.12 · Data leakage prevention
EU AI ActArt.12 · Record-keeping
NIST AI RMFMANAGE 2.4 · supersede / disengage / deactivate
OWASP LLMLLM02:2025 · Sensitive info disclosure
AARMR3 intent · R5 receipt
The standard

Heron and AARM (Autonomous Action Runtime Management)

AARM is an open specification for how an agent's actions get checked, enforced, and recorded at runtime — an open benchmark for agent security, the way SOC 2 is for SaaS. Heron builds to it, so the standard sets the bar, not us. Conformance in progress, not claimed

How Heron maps to AARM

Verify your agents before someone else asks you to

A customer incident, a security review, a buyer's questionnaire: when the question comes, the record is already there