dFence Runtime

Your agentic CISO,
always on.

dFence is a runtime AI guardrails platform for agentic applications. It observes every request, understands policy defiance, and intervenes with the right action when prompts, tools, data, or agent behavior become unsafe.

AIAgent
DFENCEPolicy active
APITool call
Unsafe action blocked
Runtime security

Protection that understands, then acts.

01

Protected by the 3S framework

Observe, understand, and intervene across every request flowing through your agentic application.

Explore more →
02

Intent-based access

Allow tools and MCP calls only when the live action matches the agent's declared happy path.

Explore more →
03

AI policy writer

Translate vulnerabilities and business boundaries into enforceable policies for complete security coverage.

Explore more →
Our foundation

Observe. Understand. Intervene.

dFence creates a closed decision loop around every agent request, from raw telemetry to autonomous action.

01ObserveEvery request, response, data source, and tool call
02UnderstandIntent, context, policy defiance, and business risk
03InterveneBlock, redact, constrain, alert, or allow autonomously
Intent-based access management

Access control for what the agent is trying to do.

Traditional access control asks whether a credential is allowed to call a tool. Agentic systems need one more question: does this specific action match the intended purpose of the interaction? dFence evaluates intent before sensitive tool and MCP calls, so an agent cannot use valid access for the wrong reason.

01

Declared happy path

Define what the agent is supposed to do in a workflow, including allowed goals, data boundaries, tools, and approval points.

02

Intent check

dFence compares the live request, context, tool choice, MCP call, and action parameters against the expected intent.

03

Trust-aware decision

Trusted low-risk calls can proceed. Untrusted, sensitive, or mismatched actions are blocked, constrained, redacted, or sent for approval.

Live example Customer support agent
Intent evaluation
Application Support agent Export all customer records
dFence Intent check
Allowed intent Billing support and account summaries Happy path
Observed action Bulk customer export via unrelated MCP Mismatch
Unrelated MCP Customer export Sensitive data destination
dFence decision Blocked: intent mismatch
Tool call stopped and audit event created

dFence does not rely only on static scopes. It enforces the reason behind the action.

Minimal latency, complete coverage

Get peace of mind with dFence.

Use more than 100 checks with policies deployed as enforcers or observers based on criticality—avoiding heavy, one-size-fits-all guardrails.

Get a demo
Runtime check suite 100+ controls
Live
Incoming agent action Summarize customer file, then call billing API
01 PII detection Redact
02 Excessive agency Constrain
03 Hallucination Verify
04 Unwanted tool call Block
Policy decision API call blocked until approval
Compliance at scale

Map every finding to the frameworks that matter.

Maintain audit trails for every request and map findings against OWASP Top 10 for LLMs, MITRE ATLAS, NIST, the EU AI Act, and more.

GDPR compliant
NIST
OWASP
MITRE ATLAS
dForge + dFence

Your complete AI security supertool.

Continuously red-team before deployment, convert findings into policies, and safeguard agentic applications at runtime.

Explore dForge