Ecosystem
Three Products, One Stack
Pre-deployment scanning, continuous threat intelligence, and runtime enforcement. Each product feeds the others. The result is a security loop that gets stronger with every deployment.
Aguara Scan
Scan before you deploy
- 217 detection rules across 16 categories
- NLP classifiers + taint tracking
- NFKC normalization
- OWASP Agentic 7/10
- Open source
Aguara Watch
Know what's out there
- 57,000+ MCP skills scanned across 7 registries
- Free online scanner via WebAssembly
- Threat intel feeds into detection rules
Oktsec
Enforce at runtime
- 10-stage security pipeline
- MCP + CLI dual channel
- Tamper-evident audit trail
- LLM threat intelligence
- Real-time dashboard
Feedback Loop
The Data Flywheel
Every threat discovered becomes a detection rule. Every rule runs in the runtime pipeline. Every confirmed threat generates new intelligence.
Watch discovers threat
Continuous scanning across the MCP ecosystem surfaces new risks before they reach your agents.
New detection rule
Threat patterns get codified as YAML detection rules and added to the Aguara rule engine.
Oktsec catches it
The runtime pipeline blocks the threat before it reaches your MCP servers or executes on disk.
LLM confirms + refines
Optional LLM analysis validates the detection and proposes rule refinements that feed back into the engine.
Every threat discovered by Aguara Watch becomes a detection rule. Every rule runs in Oktsec's runtime pipeline. Every confirmed threat generates new intelligence. This feedback loop gets stronger with every deployment.
Why This Matters
The flywheel compounds.
Integrations
Plugs Into Your Stack
SDKs, metrics, alerts, and CI/CD output. Oktsec fits wherever your agents run.
MCP Client Discovery
17 MCP clients discovered, 14 wrappable. Auto-configures gateway for Claude Desktop, Cursor, Windsurf, and more.
Go SDK + Python SDK
Native Go and Python libraries for programmatic access. Python on PyPI: oktsec
Prometheus Metrics
6 metric families exposed on /metrics. Plug into Grafana, Datadog, or any Prometheus-compatible stack.
Webhook Alerts
Configurable webhook notifications for threat events. Route to Slack, PagerDuty, or your own endpoint.
SARIF Export
Static Analysis Results Interchange Format output for GitHub Code Scanning. Integrates findings directly into your PR review workflow.