Security
Clevername provides a layered security architecture that monitors, scans, and controls every AI agent interaction in real time. From content scanning to emergency kill switches, every action is auditable and governed.
Defense in depth
Security on Clevername is not a single feature — it is a set of interlocking systems that operate at every layer of the platform:
- CleverGuard scans all agent input and output for PII, prompt injection, secrets, and toxicity.
- Guardrail profiles restrict what tools, models, and APIs each agent can access.
- Audit trails log every action with hash-chain verification for tamper detection.
- Emergency controls let admins pause agents or revoke keys, with SignedApproval for dashboard/JWT flows when required and audited SOAR-key execution for permitted API calls.
- SOAR integration forwards security events to your existing SIEM/SOAR tooling.
The SOC Console
The Security Operations Center (SOC) console at /dashboard/security/soc is your single pane of glass for monitoring all agent activity. It shows live sessions, spend tracking, alert counts, DLP hits, and a real-time security event feed.
How it connects to Agent Review
The Agent Review defines what an agent should be allowed to do (via the questionnaire and guardrail profiles). The security layer enforces those rules at runtime and surfaces violations. Together, they provide governance from approval through execution.
Security capabilities
Live agent sessions, spend tracking, alert feeds, DLP event stream.
Content scanning, tool scope enforcement, rate limiting, budget caps.
Emergency controls, circuit breakers, key revocation, SOAR forwarding.