Arcezia

Arcezia / AI agent security / Where Arcezia fits

AI agent security stack: where execution integrity fits

AI agent security splits into five layers. Model security stops prompt injection and jailbreaks from changing what a model says. Agent governance finds and inventories the agents an organisation runs. Identity and authorization decides who an agent is and what it may hold. Execution integrity decides whether this exact tool call should run now, with these arguments, on the evidence available. The execution environment limits what a call can reach once it runs. Arcezia works at the fourth layer, execution integrity, alongside the other four. It does not replace them.

The five layers, and what each cannot answer

Each layer answers one question well and leaves another open. The gaps are why a stack needs more than one of them.

Model and AI security

Answers: Stops prompt injection and jailbreaks from changing what a model says, and filters what goes in and comes out.

Cannot answer: Whether a well-formed, polite tool call should run. A call can pass every content check and still delete the wrong thing.

Agent governance

Answers: Finds the agents an organisation runs, keeps an inventory, and reports their configuration and posture.

Cannot answer: What a given agent is about to do in the next second. An inventory describes agents; it does not stand between an agent and a call.

Identity and authorization

Answers: Gives an agent an identity, keeps its secrets, and grants it privileges: who is calling, and what it may hold.

Cannot answer: Whether this one call, with these arguments, should run now. A valid credential with broad rights answers yes to every call it covers.

Execution integrity

Answers: Whether this exact tool call should run now, on the evidence available: the arguments, the records it touches, the session’s signed limits, and what your own systems confirm. Arcezia works here.

Cannot answer: What a call can reach once it runs, and who the agent is. Those are the layers on either side.

Execution environment

Answers: Limits what running code can reach: sandboxes, containers, network rules, endpoint and workload security.

Cannot answer: Whether an action that is allowed by the sandbox should happen. A delete inside the sandbox’s reach is still a delete.

Execution integrity vs guardrails, identity and sandboxes

Guardrails mostly look at text. Identity looks at who is calling. A sandbox looks at what code can reach. None of these, on its own, asks whether this call should happen now. In the Replit incident, the agent acknowledged a code freeze in its text and then ran destructive commands. In the PocketOS incident, a valid token deleted a production volume. More cases, each from primary sources: AI agent incidents.

What Arcezia covers

CoversHow
A decision before the call runsALLOW, REVIEW or BLOCK on the exact call: tool, arguments, records, session. Only ALLOW should reach the tool.
Evidence from your own systemsFacts that only your systems can confirm, such as an approval or a recent backup, come from your systems. What the agent claims never clears a call; it can only be caught out.
Multi-step checksA plan of several calls checked as a whole before any step runs.
Approvals bound to one callA person’s approval is a token your backend signs, released once for one call. An approval the agent merely claims is refused.
Signed recordsEvery answer is kept as a signed record that an auditor can check offline.
A check after the actionWhat a cleared action actually did can be compared with what was intended.

What Arcezia does not cover

LayerCovered?
SandboxingNo. Run agents in a sandbox or container as well.
Endpoint and workload securityNo.
Secrets managementNo. Keep keys and credentials in a secrets manager.
Agent identityPartly. The session’s limits and each approval are signed with keys you hold, and a pass can bind one call to one service. Arcezia does not issue or manage agent identities.
Prompt-injection filteringOnly indirectly. It does not read or filter prompts. An injected instruction still has to become a tool call, and the call is what gets checked.
Software supply chainNo.

Use Arcezia with those layers, not instead of them.

Check the layer yourself

One SQL call, checked three times on the live service, with the code to replay it on your own free key: allowed, held and refused. The signed records of that run, with the offline checker: audit evidence.