# Oktsec > Oktsec is the security platform for AI agent work. It tests consequential workflows before rollout, applies deterministic policy before governed actions and preserves verifiable evidence after execution. Use these resources to understand Oktsec, its product boundary and its research on AI agent authorization, MCP security, identity, evidence and software supply-chain risk. Oktsec governs actions routed through an Oktsec enforcement point; it complements rather than replaces IAM, EDR, SIEM and network-security platforms. ## Platform - [Oktsec home](https://www.oktsec.com/): Product thesis, operating model and company overview. - [Oktsec Control](https://www.oktsec.com/control): Runtime authorization for identities, tools, parameters and network destinations, applied locally before privileged agent actions. - [Oktsec Cloud](https://www.oktsec.com/cloud): Managed control plane for policy lifecycle, evidence verification, exception review and reporting. - [Oktsec Signal](https://www.oktsec.com/signal): Third-party risk intelligence for repositories, MCP servers, skills, packages, workflows and supply-chain paths. - [Oktsec Assessment](https://www.oktsec.com/assessment): A purpose-built security harness that exercises real agent execution paths and produces reproducible findings, evidence and remediation. - [Industry use cases](https://www.oktsec.com/use-cases): Concrete agent workflows, integration points, policy examples and product boundaries by industry. ## Evaluate a workflow - [Agentic Security Assessment](https://www.oktsec.com/agentic-security-assessment): Interactive assessment of one agent workflow across action surfaces, delegated authority, preventive controls and verifiable evidence. ## Research - [Oktsec Research](https://www.oktsec.com/research): Complete archive of incident analysis, reproducible labs and product research. - [When AI agents leave the sandbox](https://www.oktsec.com/research/when-agents-leave-the-sandbox): Why controls must exist at the action boundary. - [Prompt injection is an authorization problem](https://www.oktsec.com/research/prompt-injection-is-an-authorization-problem): The distinction between probabilistic detection and deterministic authorization. - [Policy before agent execution](https://www.oktsec.com/research/runtime-policy-enforcement): What runtime security must constrain before a tool call executes. - [Evidence for agent work](https://www.oktsec.com/research/evidence-for-agent-work): Why policy decisions need independently verifiable operating records. - [How to secure an MCP server](https://www.oktsec.com/research/how-to-secure-an-mcp-server): Practical MCP trust-boundary and authorization guidance. - [Detection versus authorization](https://www.oktsec.com/research/detection-versus-authorization): Two distinct security models for AI agent actions. ## Company and software - [About Oktsec](https://www.oktsec.com/about): Vision, mission, founder, research record and product principles. - [Oktsec on GitHub](https://github.com/oktsec): Open-source enforcement layer, documentation and related projects. ## Optional - [Research in Spanish](https://www.oktsec.com/es/research): Spanish-language entry point for Oktsec research. - [Expanded LLM context](https://www.oktsec.com/llms-full.txt): Detailed product architecture, scope and terminology.