Connect once. Heron records every action in a chain you can reconstruct, flags what breaks your rules, and can block what crosses the line
An AI agent isn't static software. It changes every day — and security that checks once a year wasn't built for that.
“Traditional security only handles point-in-time detection. If the agent keeps updating its memory, it's a new version every time — you can't do once-a-year testing. It has to be continuous.”
So every security team is told to verify the agent. None of them has a way to.
“Every framework says verify the agent. Nobody says how to check.”
“How do you prove the agent won't read what it shouldn't? How can you prove that?”
A certificate doesn't answer it. They want to see what the agent actually does, from where it really runs.
“SOC 2 is a nice-to-have, not self-verified. Can I actually see how it's operating?”
“We don't trust the registry. We pull the data from where the agent is actually deployed.”
Across every conversation, one answer: watching isn't enough. They need continuous evidence of what the agent actually does.
That's Heron.
One product, five steps, all free to run yourself: you pay only when we keep the rules current for you. Your data never leaves your perimeter
Six questions against the traces you already have. No install, nothing sent anywhere. A one-page report of what you can prove today
Get the skill on GitHubDon't have an AI gateway or traces yet? See where to start
Close the gaps: collect the full record inside your own perimeter. Shadow mode: every action still gets its verdict, nothing is blocked yet, and your data stays home
Book a demo for pre-accessEvery finding resolves three ways: a fix on your side, a fix in Heron, or a rule that needs a human. Autonomous agents run the triage; only the human calls reach you
The same record becomes the evidence line in the frameworks you report against: SOC 2, ISO 27001, EU AI Act. Recognised, not explained
Once shadow runs quiet, flip it: an action that breaks your published rules is blocked before it runs, not written up after. You hold the switch
One hook into the platform your agents run on. Every action gets checked, and every decision lands on a signed record you can open any time
Heron hooks into the layer your agents run on, not each agent one by one. Every agent on the platform, the ones you run today and the ones you ship next month, is covered automatically. One integration, full coverage, by construction
Tracing shows what your agents did. Heron rules on it: every action checked against your published policy. Allow, deny, or step up to a human. In shadow mode verdicts are recorded, not enforced, so nothing breaks while you watch what would have been blocked
Every decision is written to a tamper-evident, hash-chained record. It cannot be altered after the fact, and it never goes stale because it updates with every action. Your buyer's security team opens it and queries the history any time, mapped to the frameworks they already report against
Assess once, report against many. Each decision Heron enforces lands on a control your buyer already knows — evidence they recognise, not a format they have to learn
AARM is an open specification for how an agent's actions get checked, enforced, and recorded at runtime — an open benchmark for agent security, the way SOC 2 is for SaaS. Heron builds to it, so the standard sets the bar, not us. Conformance in progress, not claimed
How Heron maps to AARMA customer incident, a security review, a buyer's questionnaire: when the question comes, the record is already there