Ceros
by Beyond Identity
Bind every AI agent session to a real person on a verified device — and block what policy forbids
Ceros is Beyond Identity's agentic AI trust layer: a middleware proxy that sits between AI agents and the LLMs, MCP servers and tools they call, binding each session to a named human on an attested device. It is aimed at security teams that have lost track of which agents run where, under whose credentials, and with what permissions.
Ceros is an agentic AI trust layer from Beyond Identity, the New York identity vendor co-founded by Jim Clark and Tom Jermoluk and backed by more than $200 million in funding. Launched publicly on 16 June 2026 and currently open as a free developer preview, it extends the company's device-bound, phishing-resistant IAM model from human employees to AI agents. Architecturally it is a context-aware proxy positioned between agents and everything they call — cloud-hosted LLMs, MCP servers, local programs and SaaS assistants in tools such as Jira and Slack — intercepting every API call and tool invocation. Four mechanisms do the work: each agent runs with a cryptographic credential bound to specific hardware (a TPM chip, Secure Enclave or VM attestation module) rather than a shared API key; the proxy enriches every request with user, device and permission context before it reaches an AI service; security teams define runtime policies governing which agents may use which tools and under what conditions, continuously evaluated before and during a session; and every action produces a cryptographic audit trail proving who initiated it, from which device, under which policy. API keys are vaulted in hardware, which the company argues eliminates credential sprawl by leaving attackers nothing to steal, and the proxy blocks malicious tool use and hostile MCP servers in real time. It also fails over to an alternate model automatically when a primary LLM goes offline. Installation is deliberately trivial — an npm global install of the Ceros CLI then a single wrapper command around an agent such as Claude Code — with the vendor claiming full forensic audit trails within five minutes and no pipeline changes. Beyond Identity holds SOC 2 Type 2 and GDPR certification, alongside CCPA, PCI DSS, PSD2, NYDFS and FIDO2.
CISOs and identity teams at enterprises where developers have already deployed coding agents and MCP servers faster than security can inventory them.
Converts written AI policy into a runtime control, and turns "someone used an API key" into "this person, on this device, at this time".
At a Glance
- Category
- Governance & Security
- Pricing
- Contact for pricing, Freemium
- Target Market
- CISOs, CIOs, Identity and Access Management Teams, Platform Engineering Leaders, Enterprise Developers
- Deployment
- Cloud-first, API-based
- Headquarters
- New York, United States
- Team Size
- 101-250
Key Features
- ✓Device-bound agent credentials
Each agent runs with a cryptographic credential tied to a TPM, Secure Enclave or VM attestation module, so it cannot be stolen and replayed.
- ✓Context-aware proxy
Sits between agents and AI services, enriching every request with user, device and permission context before it is allowed through.
- ✓Runtime policy enforcement
Security teams define which agents may access which tools and data, evaluated continuously before and during every session.
- ✓Cryptographic audit trails
Every agent action carries proof of who initiated it, from which device and under which policy, for compliance and forensics.
- ✓Hardware API key vaulting
Keys are held in hardware rather than distributed to agents, removing the credential sprawl attackers normally harvest.
- ✓MCP and tool blocking
Detects and blocks malicious tool use and hostile MCP servers in real time rather than reporting them afterwards.
- ✓LLM failover
Automatically reroutes prompts to an alternate model when the primary LLM goes offline, reducing developer intervention.
- ✓Two-command deployment
An npm CLI install plus a wrapper command around the agent, with no changes to existing developer pipelines.
Capabilities
Use Cases
- •Shadow agent discovery
Security teams find every AI agent already running in the estate, including who launched it and from which device.
- •Incident attribution
When a suspicious file change appears, the audit trail names the agent, the human operator and the device involved.
- •MCP server governance
Administrators allowlist which MCP servers and tools each agent group may call, blocking unapproved ones at runtime.
- •Prompt injection containment
Injected instructions that try to invoke unauthorised tools or exfiltrate API keys are blocked by proxy-side policy.
- •Compliance evidence for agentic AI
Cryptographic session records give auditors provable answers about agent access, replacing best-effort application logs.
Ideal For
Best For
- ✓Inventorying and attributing shadow AI agents already running across developer laptops and CI environments
- ✓Enforcing which agents may invoke which MCP servers and tools, evaluated continuously rather than at login
- ✓Eliminating long-lived shared API keys by vaulting credentials in hardware and binding them to attested devices
- ✓Producing cryptographic audit trails of agent actions for compliance evidence and incident investigation
- ✓Blocking prompt-injection-driven tool abuse and malicious MCP servers at the proxy rather than after the fact
Not Ideal For
- ✗Organisations wanting a mature, proven control — it is a public preview launched in mid-2026 with no independent security audit published and analysts explicitly advising buyers to request more information before deployment
- ✗Teams with no existing device-trust or attestation posture: the security model depends on TPM, Secure Enclave or VM attestation, so value collapses on unmanaged hardware
- ✗Buyers who need published pricing and contractual terms today — no pricing has been disclosed for the commercial tier and the preview is free
- ✗Shops standardised on a competing identity fabric that already ships agent identity, where adding a second control plane duplicates policy
Integrations
Deployment
Market Analysis
Pros
- ✓Targets attack vectors that are real and under-addressed today: prompt injection, over-permissioned agent workflows and shadow agents running outside IT visibility
- ✓Hardware-bound credentials plus hardware key vaulting genuinely remove the stealable secret, rather than rotating it faster
- ✓Cryptographic per-session audit trails give incident response and auditors attribution that application logs cannot provide
- ✓Adoption cost is unusually low for a security control — an npm install and a wrapper command, with the vendor claiming useful audit data in under five minutes
- ✓Backed by an established IAM vendor with SOC 2 Type 2, GDPR, PCI DSS, NYDFS and FIDO2 certification rather than a first-time security startup
Cons
- ✗No independent security audit was available at launch, and analysts covering it recommended enterprises request additional information before deploying
- ✗Still a public preview rather than a hardened GA product, so it is an evaluation candidate and not yet a production control plane
- ✗No pricing, no published customer references and no named production deployments anywhere in the launch coverage
- ✗Documented agent support is thin and developer-centric — Claude Code and GitHub Copilot are named, but there is no published matrix of supported agent frameworks or runtimes
- ✗An inline proxy in front of every agent call is a new latency and availability dependency in the critical path, and the vendor has published no performance data
- ✗Crowded field: Okta, Microsoft, CrowdStrike and SecureAuth all shipped competing agent-identity controls within weeks of it in mid-2026
Pricing
Public Preview
$0
- ✓Free developer sign-up
- ✓Agent session logging and audit trails
- ✓Device-bound credentials
- ✓Policy enforcement
- ✓MCP and tool blocking
Enterprise
Contact for pricing
- ✓Organisation-wide rollout with automatic authentication prompts
- ✓Centralised policy administration
- ✓Beyond Identity platform integration
No commercial pricing has been published anywhere — not in the launch announcement, the vendor product pages, or any of the trade coverage. Ceros is currently free to sign up for as a public preview aimed at developers, and enterprise rollout is quoted by sales as part of the broader Beyond Identity platform. Treat the free preview as evaluation only: budget assumptions for a production deployment cannot be made from published information today, and buyers should expect per-identity or per-agent licensing consistent with the company's IAM pricing model.
Security & Compliance
Connect
Sources
This page was written from 6 sources, 3 on domains other than beyondidentity.com.
- 1.beyondidentity.com — introducing ceros the agentic ai trust layer now open for puvendor
- 2.beyondidentity.com — beyond identity opens early access for the ai security suitevendor
- 3.beyondidentity.com — security and compliancevendor
- 4.siliconangle.com — beyond identity launches ceros ai agent security platform
- 5.scworld.com — beyond identity launches ceros to secure enterprise ai agent
- 6.digitaltoday.co.kr — beyond identity says ceros controls access up to ai agent op
Stay Ahead of the Curve
Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.
SubscribeRelated Products
Noma Security
Discover, govern and defend every AI agent and MCP server in the enterprise — from inventory to runtime enforcement
NVIDIA OpenShell
Open-source, kernel-isolated sandbox runtime for autonomous AI agents
OpenAI Daybreak
Vetted-access frontier AI for cyber defenders, with a purpose-built offensive-security model
Zenity
Runtime AI agent security that blocks a harmful agent action before it executes