An AI security engineer on every machine.

We work in the kernel, below the reach of any AI, and stop harmful actions before they run.

Free for individuals. Linux today, Windows next.

agent · reading a protected keyDENIED
17 / 17
read paths blocked
catddpythongrepawkbase64tarmmapsymlinkhardlink+7 more

Every way in — symlink, hardlink and rename included — refused before a single byte is read.

One protected file, seventeen bypass attempts — all denied at the kernel

The blind-spot filler for your security stack

Endpoint tools see syscalls. Network tools see API traffic. Ring Zero sees the causal chain from a compromised prompt to a credential exfiltration — and blocks it.

Live Session — claude-code-session-42
2 agents • 3 blocked
127
Events
3
Blocked
62/100
Risk score
09:41:02Clauderead/src/auth/tokens.rslow
09:41:05Claudewrite/etc/passwdhighBLOCK
09:41:07Cursorexeccurl api.stripe.com/chargesmed
09:41:09Clauderead~/.ssh/id_rsahighBLOCK
09:41:12Cursorwrite/tmp/output.jsonlow
09:41:15Codexexecgit push origin mainmed

Real-time Agent Monitoring

Every active AI agent session — kernel events, prompt/response content, file access, network connections. Live dashboard for your security team.

Claude Code
Cursor
GitHub Copilot
OpenClaw
Claude Code
Cursor
GitHub Copilot
OpenClaw
Gemini
Windsurf
Devin
Codex
Gemini
Windsurf
Devin
Codex

Works with Any Agent

Claude Code, GitHub Copilot, Cursor, Codex, custom LLM agents. Ring Zero intercepts at the kernel — no SDK changes, no agent modifications.

2 divergences detected
claude-code · 09:41
Declared intentObserved behavior
read/src/auth/session.rs
write/tmp/output.json
execcargo build --release
read/src/auth/session.rs
+read~/.ssh/id_rsa
write/tmp/output.json
+execcurl -s http://169.254.169.254/latest/meta-data
execcargo build --release

Attack Chain Detection

Multi-step provenance graph correlates prompt injection with downstream OS actions. Detects chains that EDRs see as unrelated events.

JIT Access Requests
1 pending
Claude Codehigh
read ~/.ssh/id_rsa

Deploy script needs SSH key for remote push

Pending approvalTTL 120s
Cursormed
exec pg_dump production
Granted

Schema migration requires DB snapshot

Active grantTTL 300s
187s left
Codexmed
write /etc/hosts

Local dev domain routing

Expired

Vulnerability-Aware Enforcement

Real-time OSV vulnerability checking on package installs. Exploit context persists in the provenance graph for behavioral correlation.

Your EDR catches abnormal outbound traffic — meaning it detects the consequence after the injection already ran. Ring Zero detects the injection at the kernel layer before the exfiltration completes.

Ring Zero Security

AI Agent Runtime Security

See what your EDR misses.

Prompt injection, credential exfiltration, multi-step attack chains — detected and blocked at the kernel layer.

Kernel-enforced guardrails. Not another proxy.

Application-layer tools intercept via API proxies — effective until an agent spawns a subprocess or uses a path that bypasses the proxy. Ring Zero enforces at ring zero, where every process must pass.

ringzero-daemon — sudo
$ sudo rz setup
Installing eBPF kernel hooks...
Loading LSM programs (6 hooks)...
✓ ringzero-daemon.service active
$ sudo rz status
Driver● connected
Hooks6 / 6 active
Agents4 monitored
Events/s23
Blocked2 today
Ring level0 (kernel)
Intercepting at ring 0 — no workarounds possible

Kernel-Level Enforcement

Ring Zero sits at ring zero — the kernel. eBPF hooks intercept every file access, process spawn, and network connection before any application-layer bypass is possible.

Fleet · 3 orgs · 12 agents
live
claude-code
alice @ acme
allowed
312 ev
cursor
bob @ acme
blocked
87 ev
copilot
charlie @ beta
escalate
54 ev
codex
diana @ gamma
allowed
203 ev
windsurf
eve @ acme
allowed
441 ev
↑ real-time · updated 1s ago

Global Fleet Visibility

One dashboard for every agent session across your entire organization. On-prem, cloud, or air-gapped — no telemetry leaves the host unless you allow it.

Don't take our word for it — run it.

The enforcement claim is testable. Read every line, run the demo, and watch the kernel refuse.

Run the demo

$ bash examples/seventeen-read-paths.sh
cat id_rsa BLOCKED
dd id_rsa BLOCKED
python open() BLOCKED
symlink → id_rsa BLOCKED
hardlink → id_rsa BLOCKED
Blocked 17/17 read paths.

Seventeen ways to read one protected file — every one refused at the kernel, on your own machine.

See the demo scripts

Read every line

The whole product is open source — the kernel programs under GPL-2.0 and the daemon, CLI and app under Apache-2.0. Nothing to take on faith; the enforcement path is right there to read.

kernel · GPL-2.0userspace · Apache-2.0
Star on GitHub

Map it to your threat model

The enterprise-AI threat model — trust boundaries, the human-workflow and autonomous-agent threat tables, and the control mapping — as a shareable reference for your security team.

PDF · 11 pages · STRIDE, OWASP & MITRE ATLAS
Get the threat model

Frequently Asked Questions

Everything you need to know about Ring Zero Security.

Agent CTA Background

AI Agent Runtime Security

Get Early AccessFree download · Linux today · Windows next
Ring Zero SecurityNVIDIA Inception Program member

We work in the kernel, below the reach of any AI, and stop harmful actions before they run.

© 2026 NVIDIA, the NVIDIA logo, and NVIDIA Inception are trademarks and/or registered trademarks of NVIDIA Corporation in the U.S. and other countries.