C

Ceros

by Beyond Identity

Governance & SecurityAI Agents & OrchestrationDeveloper ToolsEnterprise Platform

Bind every AI agent session to a real person on a verified device — and block what policy forbids

Contact for pricing · Freemium·Added Aug 21, 2026·Updated Aug 21, 2026
Share:
THE DAILY BRIEF
Ceros

by Beyond Identity

Governance & SecurityAI Agents & OrchestrationDeveloper ToolsEnterprise Platform

Bind every AI agent session to a real person on a verified device — and block what policy forbids

Contact for pricing · Freemium

Ceros is Beyond Identity's agentic AI trust layer: a middleware proxy that sits between AI agents and the LLMs, MCP servers and tools they call, binding each session to a named human on an attested device. It is aimed at security teams that have lost track of which agents run where, under whose credentials, and with what permissions.

At a Glance

Category
Governance & Security
Pricing
Contact for pricing, Freemium
Target Market
CISOs, CIOs, Identity and Access Management Teams, Platform Engineering Leaders, Enterprise Developers
Deployment
Cloud-first, API-based
Headquarters
New York, United States
Team Size
101-250

Key Features

  • Device-bound agent credentials
  • Context-aware proxy
  • Runtime policy enforcement
  • Cryptographic audit trails
  • Hardware API key vaulting
  • MCP and tool blocking
  • LLM failover
  • Two-command deployment

Capabilities

text generation
image generation
video generation
code generation
workflow automation
api access
audio generation
fine tuning
agent orchestration

Use Cases

  • Shadow agent discovery
  • Incident attribution
  • MCP server governance
  • Prompt injection containment
  • Compliance evidence for agentic AI

Ideal For

Best For

  • Inventorying and attributing shadow AI agents already running across developer laptops and CI environments
  • Enforcing which agents may invoke which MCP servers and tools, evaluated continuously rather than at login
  • Eliminating long-lived shared API keys by vaulting credentials in hardware and binding them to attested devices
  • Producing cryptographic audit trails of agent actions for compliance evidence and incident investigation
  • Blocking prompt-injection-driven tool abuse and malicious MCP servers at the proxy rather than after the fact

Not Ideal For

  • Organisations wanting a mature, proven control — it is a public preview launched in mid-2026 with no independent security audit published and analysts explicitly advising buyers to request more information before deployment
  • Teams with no existing device-trust or attestation posture: the security model depends on TPM, Secure Enclave or VM attestation, so value collapses on unmanaged hardware
  • Buyers who need published pricing and contractual terms today — no pricing has been disclosed for the commercial tier and the preview is free
  • Shops standardised on a competing identity fabric that already ships agent identity, where adding a second control plane duplicates policy

Market Analysis

Enterprise-gradeZero-trustDeveloper-first

Pros

  • Targets attack vectors that are real and under-addressed today: prompt injection, over-permissioned agent workflows and shadow agents running outside IT visibility
  • Hardware-bound credentials plus hardware key vaulting genuinely remove the stealable secret, rather than rotating it faster
  • Cryptographic per-session audit trails give incident response and auditors attribution that application logs cannot provide
  • Adoption cost is unusually low for a security control — an npm install and a wrapper command, with the vendor claiming useful audit data in under five minutes
  • Backed by an established IAM vendor with SOC 2 Type 2, GDPR, PCI DSS, NYDFS and FIDO2 certification rather than a first-time security startup

Cons

  • No independent security audit was available at launch, and analysts covering it recommended enterprises request additional information before deploying
  • Still a public preview rather than a hardened GA product, so it is an evaluation candidate and not yet a production control plane
  • No pricing, no published customer references and no named production deployments anywhere in the launch coverage
  • Documented agent support is thin and developer-centric — Claude Code and GitHub Copilot are named, but there is no published matrix of supported agent frameworks or runtimes
  • An inline proxy in front of every agent call is a new latency and availability dependency in the critical path, and the vendor has published no performance data
  • Crowded field: Okta, Microsoft, CrowdStrike and SecureAuth all shipped competing agent-identity controls within weeks of it in mid-2026

Pricing

Public Preview

$0

  • Free developer sign-up
  • Agent session logging and audit trails
  • Device-bound credentials
  • Policy enforcement
  • MCP and tool blocking

Enterprise

Contact for pricing

  • Organisation-wide rollout with automatic authentication prompts
  • Centralised policy administration
  • Beyond Identity platform integration

No commercial pricing has been published anywhere — not in the launch announcement, the vendor product pages, or any of the trade coverage. Ceros is currently free to sign up for as a public preview aimed at developers, and enterprise rollout is quoted by sales as part of the broader Beyond Identity platform. Treat the free preview as evaluation only: budget assumptions for a production deployment cannot be made from published information today, and buyers should expect per-identity or per-agent licensing consistent with the company's IAM pricing model.

Security & Compliance

soc2
gdpr
hipaa
iso27001
sso
data residency

THE DAILY BRIEF

Enterprise AI insights for technology and business leaders, twice weekly.

beri.net

Subscribe at beri.net/subscribe for twice-weekly AI insights delivered to your inbox.

LinkedIn: linkedin.com/in/rberi  |  X: x.com/rajeshberi

© 2026 Rajesh Beri. All rights reserved.

Ceros is Beyond Identity's agentic AI trust layer: a middleware proxy that sits between AI agents and the LLMs, MCP servers and tools they call, binding each session to a named human on an attested device. It is aimed at security teams that have lost track of which agents run where, under whose credentials, and with what permissions.

Ceros is an agentic AI trust layer from Beyond Identity, the New York identity vendor co-founded by Jim Clark and Tom Jermoluk and backed by more than $200 million in funding. Launched publicly on 16 June 2026 and currently open as a free developer preview, it extends the company's device-bound, phishing-resistant IAM model from human employees to AI agents. Architecturally it is a context-aware proxy positioned between agents and everything they call — cloud-hosted LLMs, MCP servers, local programs and SaaS assistants in tools such as Jira and Slack — intercepting every API call and tool invocation. Four mechanisms do the work: each agent runs with a cryptographic credential bound to specific hardware (a TPM chip, Secure Enclave or VM attestation module) rather than a shared API key; the proxy enriches every request with user, device and permission context before it reaches an AI service; security teams define runtime policies governing which agents may use which tools and under what conditions, continuously evaluated before and during a session; and every action produces a cryptographic audit trail proving who initiated it, from which device, under which policy. API keys are vaulted in hardware, which the company argues eliminates credential sprawl by leaving attackers nothing to steal, and the proxy blocks malicious tool use and hostile MCP servers in real time. It also fails over to an alternate model automatically when a primary LLM goes offline. Installation is deliberately trivial — an npm global install of the Ceros CLI then a single wrapper command around an agent such as Claude Code — with the vendor claiming full forensic audit trails within five minutes and no pipeline changes. Beyond Identity holds SOC 2 Type 2 and GDPR certification, alongside CCPA, PCI DSS, PSD2, NYDFS and FIDO2.

Ideal Buyer

CISOs and identity teams at enterprises where developers have already deployed coding agents and MCP servers faster than security can inventory them.

Key Benefit

Converts written AI policy into a runtime control, and turns "someone used an API key" into "this person, on this device, at this time".

At a Glance

Category
Governance & Security
Pricing
Contact for pricing, Freemium
Target Market
CISOs, CIOs, Identity and Access Management Teams, Platform Engineering Leaders, Enterprise Developers
Deployment
Cloud-first, API-based
Headquarters
New York, United States
Team Size
101-250

Key Features

  • Device-bound agent credentials

    Each agent runs with a cryptographic credential tied to a TPM, Secure Enclave or VM attestation module, so it cannot be stolen and replayed.

  • Context-aware proxy

    Sits between agents and AI services, enriching every request with user, device and permission context before it is allowed through.

  • Runtime policy enforcement

    Security teams define which agents may access which tools and data, evaluated continuously before and during every session.

  • Cryptographic audit trails

    Every agent action carries proof of who initiated it, from which device and under which policy, for compliance and forensics.

  • Hardware API key vaulting

    Keys are held in hardware rather than distributed to agents, removing the credential sprawl attackers normally harvest.

  • MCP and tool blocking

    Detects and blocks malicious tool use and hostile MCP servers in real time rather than reporting them afterwards.

  • LLM failover

    Automatically reroutes prompts to an alternate model when the primary LLM goes offline, reducing developer intervention.

  • Two-command deployment

    An npm CLI install plus a wrapper command around the agent, with no changes to existing developer pipelines.

Capabilities

text generation
image generation
video generation
code generation
workflow automation
api access
audio generation
fine tuning
agent orchestration

Use Cases

  • Shadow agent discovery

    Security teams find every AI agent already running in the estate, including who launched it and from which device.

  • Incident attribution

    When a suspicious file change appears, the audit trail names the agent, the human operator and the device involved.

  • MCP server governance

    Administrators allowlist which MCP servers and tools each agent group may call, blocking unapproved ones at runtime.

  • Prompt injection containment

    Injected instructions that try to invoke unauthorised tools or exfiltrate API keys are blocked by proxy-side policy.

  • Compliance evidence for agentic AI

    Cryptographic session records give auditors provable answers about agent access, replacing best-effort application logs.

Ideal For

Best For

  • Inventorying and attributing shadow AI agents already running across developer laptops and CI environments
  • Enforcing which agents may invoke which MCP servers and tools, evaluated continuously rather than at login
  • Eliminating long-lived shared API keys by vaulting credentials in hardware and binding them to attested devices
  • Producing cryptographic audit trails of agent actions for compliance evidence and incident investigation
  • Blocking prompt-injection-driven tool abuse and malicious MCP servers at the proxy rather than after the fact

Not Ideal For

  • Organisations wanting a mature, proven control — it is a public preview launched in mid-2026 with no independent security audit published and analysts explicitly advising buyers to request more information before deployment
  • Teams with no existing device-trust or attestation posture: the security model depends on TPM, Secure Enclave or VM attestation, so value collapses on unmanaged hardware
  • Buyers who need published pricing and contractual terms today — no pricing has been disclosed for the commercial tier and the preview is free
  • Shops standardised on a competing identity fabric that already ships agent identity, where adding a second control plane duplicates policy

Integrations

SDK Available
SDK:JavaScript

Deployment

On-Premise

Market Analysis

Enterprise-gradeZero-trustDeveloper-first

Pros

  • Targets attack vectors that are real and under-addressed today: prompt injection, over-permissioned agent workflows and shadow agents running outside IT visibility
  • Hardware-bound credentials plus hardware key vaulting genuinely remove the stealable secret, rather than rotating it faster
  • Cryptographic per-session audit trails give incident response and auditors attribution that application logs cannot provide
  • Adoption cost is unusually low for a security control — an npm install and a wrapper command, with the vendor claiming useful audit data in under five minutes
  • Backed by an established IAM vendor with SOC 2 Type 2, GDPR, PCI DSS, NYDFS and FIDO2 certification rather than a first-time security startup

Cons

  • No independent security audit was available at launch, and analysts covering it recommended enterprises request additional information before deploying
  • Still a public preview rather than a hardened GA product, so it is an evaluation candidate and not yet a production control plane
  • No pricing, no published customer references and no named production deployments anywhere in the launch coverage
  • Documented agent support is thin and developer-centric — Claude Code and GitHub Copilot are named, but there is no published matrix of supported agent frameworks or runtimes
  • An inline proxy in front of every agent call is a new latency and availability dependency in the critical path, and the vendor has published no performance data
  • Crowded field: Okta, Microsoft, CrowdStrike and SecureAuth all shipped competing agent-identity controls within weeks of it in mid-2026

Pricing

Public Preview

$0

  • Free developer sign-up
  • Agent session logging and audit trails
  • Device-bound credentials
  • Policy enforcement
  • MCP and tool blocking

Enterprise

Contact for pricing

  • Organisation-wide rollout with automatic authentication prompts
  • Centralised policy administration
  • Beyond Identity platform integration

No commercial pricing has been published anywhere — not in the launch announcement, the vendor product pages, or any of the trade coverage. Ceros is currently free to sign up for as a public preview aimed at developers, and enterprise rollout is quoted by sales as part of the broader Beyond Identity platform. Treat the free preview as evaluation only: budget assumptions for a production deployment cannot be made from published information today, and buyers should expect per-identity or per-agent licensing consistent with the company's IAM pricing model.

Security & Compliance

soc2
gdpr
hipaa
iso27001
sso
data residency

Connect

Sources

This page was written from 6 sources, 3 on domains other than beyondidentity.com.

  1. 1.beyondidentity.comintroducing ceros the agentic ai trust layer now open for puvendor
  2. 2.beyondidentity.combeyond identity opens early access for the ai security suitevendor
  3. 3.beyondidentity.comsecurity and compliancevendor
  4. 4.siliconangle.combeyond identity launches ceros ai agent security platform
  5. 5.scworld.combeyond identity launches ceros to secure enterprise ai agent
  6. 6.digitaltoday.co.krbeyond identity says ceros controls access up to ai agent op
Newsletter

Stay Ahead of the Curve

Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.

Subscribe