Skip to main content

Crawdad

Crawdad is a local-first security platform that protects AI agents by intercepting API calls between agents and their model providers through a transparent HTTP proxy. It detects prompt injection, credential theft, and data exfiltration using seven detection layers, with all content remaining on-device by default. The platform runs as a lightweight Rust binary with sub-millisecond checks and includes a public, reproducible benchmark of 497 real attacks.

  • Artificial Intelligence
  • AI Agents
  • Cybersecurity
  • Software Only
HQ unknown
210+ followers
Updated 3 days ago

Funding

Funding rounds are not available yet.

Founders

Founder details are not available yet.

Product

Problem

AI agents operate with user credentials and access within an organization's trust boundary, yet traditional security tools like EDR, DLP, and identity providers cannot see or govern agent actions. This leaves organizations vulnerable to prompt injection, credential theft, and data exfiltration that occur silently when agents follow hidden instructions embedded in retrieved documents or other inputs.

Solution

Crawdad provides a local-first AI agent security platform that runs as a transparent HTTP proxy on the user's machine, intercepting API calls between AI agents and their model providers. The platform governs what each agent is allowed to do based on its purpose, judging observed actions rather than claimed intent, and blocks or flags threats in real time. It uses seven detection layers including pattern heuristics, machine learning classification, and an optional LLM critic, with all inspection happening on-device so prompts, responses, and tool calls never leave the machine. Crawdad operates in monitor mode by default, allowing users to observe agent behavior before opting into enforcement, and includes contextual agency governance through operator-defined charters that set per-agent autonomy ceilings and tool access rules.

Target Audience

Primary customers are managed service providers, managed security service providers, enterprises, and regulated industries that deploy AI agents and need to secure agent actions within their trust boundaries, as well as developers building agent-based applications who require local-first security controls.

Features

  • Transparent HTTP proxy intercepting API calls for Anthropic, OpenAI, Google, xAI, and NVIDIA providers with no SDK or code changes required
  • Seven detection layers including pattern/heuristic scanning, ML classifier, and optional LLM critic for ambiguous content
  • Credential protection through a hardened key store where agents carry placeholders that only authenticate through Crawdad, making credential exfiltration architecturally impossible
  • Contextual Agency Governance with operator-defined charters that enforce per-agent tool, data, and effect boundaries based on observed actions
  • Signed, hash-chained audit log with standalone verifier for independent integrity checking
  • Graduated trust policy with three tiers (Attack, Ambiguous, Allow) and configurable detection modes (Block, Flag, Log, Off)
  • Written in Rust with zero unsafe code, single ~14MB binary, and sub-millisecond checks with no GPU required
  • Local posture sharing and fleet telemetry that send only metadata, never content, with optional cloud LLM backend off by default
This profile is AI-generated and may contain inaccuracies.