Enterprise AI is here.
Agents move money, touch PII, call production tools, and change systems. Every non-human identity is a token; without a named owner, scoped permissions, expiry, and a kill switch, that token is governed too late.
Tokynd Security puts AI security colleagues inside the tools your developers and infrastructure teams already use. They review agent code, MCP, prompts and RAG, baseline runtime behavior, propose merge-ready patches, verify the rescan, and turn each approved fix into evidence — end to end across the AI-SDLC.
MCP tool granted write scope it never uses
The crm-lookup server holds crm.records.write and crm.records.delete, but the agent only calls read paths. Reachability analysis confirms no write call in 90 days of traces. Combined with an unvalidated prompt template, a single injected instruction could delete customer records.
Patch approved — local patch approved; simulated merge event recorded — no repository contacted.
Identity re-issued — long-lived key retired; scoped 15-minute token provisioned by Tokynd Birthright.
Finding re-verified — Wiz re-queried: exposure closed. Evidence written back to Wiz and your ticket.
Control evidence logged — SOC 2 CC6.1 / ISO 42001 A.6 evidence pack updated automatically.
Agents now take consequential actions in real systems. The security model has to govern the identity making the move, the path it takes, and the fix that follows — without turning innovation into another ticket queue.
Agents move money, touch PII, call production tools, and change systems. Every non-human identity is a token; without a named owner, scoped permissions, expiry, and a kill switch, that token is governed too late.
Direct and indirect injection, tool-description poisoning, MCP overreach, and noisy alert floods are already part of the operating model. Visibility matters; a governed response matters more.
Tokynd Security closes both through the Tokynd platform: Tokynd Birthright at creation, then see → fix → govern → prove across every action.
Unlike gateways, scanners, or dashboards, the Tokynd platform works where agents are built. Identity is minted at creation, fixes arrive as merge-ready patches a human approves, and evidence is generated by the fix itself.
Inventory every agent, MCP server, identity, and architecture gap — born at creation where possible, found fast where not.
Merge-ready fix patches a human approves — scope removals, IaC corrections, dependency bumps — never another ticket queue.
Verified rescans close the finding at the source, and every fix emits cross-framework evidence an auditor can follow.
Nine distinct products work as one colleague system. Each pillar has one operational job, one human gate, and one place in the Discover → Fix → Prove loop.
Tokynd Winnow turns scanner noise into one owned queue. Tokynd Pulse learns the deterministic baseline and surfaces deviations without claiming a live sensor.
Tokynd Pair produces the smallest reviewable patch, tests it locally, drafts the PR body, and waits for a human. Opening real repository PRs remains design-partner roadmap.
Tokynd Attavard tiers and maps. Tokynd Birthright creates the identity record. Tokynd Vestibule reviews MCP permissions. Tokynd Sparring exercises adversarial configurations.
Tokynd Dossier packages the approved fix and verified rescan. Tokynd Asbuilt compares architecture intent with deployed descriptors and emits the gap register.
No invented customer wall, no anonymous praise, no borrowed certification badge. Tokynd Security earns proof from reproducible artifacts and design partners willing to judge the fix.
One repo, one scanner export, one named security and engineering owner. The pilot is measured on accepted patches and verified closures — not alerts generated.
See the program →Finding → proposed patch → human decision → verification result. Internal merge-rate targets stay labeled as targets until they become measured outcomes.
See the moat method →A public benchmark repo is planned with planted vulnerable and hardened fixtures, deterministic expected outputs, and versioned rules. It is a plan, not a published benchmark today.
Track delivery →v0.4.0, 61 tests, commit 2c24c63. Every status on this page names what runs locally, what needs a design partner, and what remains roadmap.
Read the changelog →AI agents, MCP servers, and AI coding tools are shipping faster than security teams can review them. The incumbents respond with dashboards and alert queues. The work still lands on your developers — so it doesn’t get done, and the risk stays open.
Enterprise AI-security platforms sell to the CISO with six-month evaluations and quote-only pricing. The people who actually build agents — your developers — never touch them.
A finding in a console doesn’t say which agent, which pull request, or which engineer owns it. Without that thread from cloud finding to code, remediation stalls in triage.
SOC 2, ISO 42001, and EU AI Act evidence gets assembled by hand, after the fact, by people who weren’t in the room when the system was built. It’s slow, expensive, and always stale.
The gap is not a shortage of scanners. It is the onboarding tax paid again for every solution: another security review, contract, console, SSO/SAML app, SCIM mapping, API-key lifecycle, data schema, owner, renewal, and evidence pull. the Tokynd platform is the neutral layer across that sprawl — specialized agents that connect the tools, normalize the risk, assign the owner, ship the fix, verify closure, and prove the control. Platform vendors will not speed up onboarding for rivals’ tools. That is the opening, and the moat is what accumulates underneath it.
83 security solutions from 29 vendors in the largest recent enterprise survey (n=1,000 executives, 18 countries, Jul–Sep 2024); 52% said fragmentation limits their ability to deal with threats.
Source: IBM Newsroom — IBM IBV with Palo Alto Networks. Vendor-sponsored (PANW sells platformisation).
75% of organizations were pursuing vendor consolidation in 2022, up from 29% in 2020 — and Gartner advised planning at least two years for it. That two-year rip-and-replace horizon is the gap an hours-to-live fabric attacks.
Source: Help Net Security summarizing Gartner (n=418, Mar–Apr 2022). Analyst data, but dated.
Mean time to fix flaws rose to 252 days; 50% of organizations carry critical security debt older than a year, and 70% of that debt comes from third-party / supply-chain code. Detection is not the bottleneck — remediation is.
Source: BusinessWire — Veracode SoSS v15 telemetry (1.3M apps). Vendor telemetry; own-platform bias noted.
Machine identities outnumber humans 82:1; 70% say identity silos are a root cause of risk, and 68% lack identity security controls for AI. Human SSO is solved-ish — agent identity is not.
Source: BusinessWire — CyberArk 2025 (n=2,600). Vendor-sponsored. Higher ratios (109:1, 144:1) circulate but are unverified — we use 82:1.
How to read these numbers: they come from different populations and counting methods, so they must not be averaged into one “average tool count.” The direction is consistent across independent surveys; any single point estimate is definition-dependent.
Five compounding assets. Any one of them can be cloned in a quarter; the loop between them cannot. Code is copyable — a labelled corpus of what actually got merged, an identity graph born at creation, and merge rights earned team by team are not.
The flywheel, illustrated. Rotation is decorative; the compounding is the product strategy — each asset below names what accumulates and what would kill it.
Every finding → fix → merged-or-rejected → verified-closed outcome, labelled. The scarcest training signal in AppSec: not what scanners report, but what developers actually merge.
Ranking, patch synthesis, and won’t-fix detection all improve from merged outcomes — a competitor starting today gets our code’s shape, not our corpus. We hold ourselves to internal targets, labelled as targets — never presented as results:
Internal targets, not results: merged-fix rate ≥60% is the target; below 40% we stop and rethink the agent, not the metric.
Tokynd Birthright mints the identity record when the agent is created — named owner, scoped tools, expiry, kill switch — so provenance exists before the first API call, not after the first incident.
Discovery tools reconstruct intent after the fact; a graph born at creation is the intent. Every agent added deepens the registry of record — owner, purpose, scope, revocation — that switching away would mean losing.
One graph across Wiz, cloud, IdP, and code: assets ↔ identities ↔ findings ↔ fixes ↔ evidence, deduplicated and owned.
Entity-resolution rules and the weakness taxonomy sharpen with every confirmed cluster and owner. Suite graphs stop at the suite boundary; a neutral graph across rival clouds, IdPs, and scanners is the referee none of them can be.
A working taxonomy of agent-native weaknesses — over-scoped tools, description drift, retrieval ACL bleed, spec violations — mapped to canonical fixes.
Each reviewed MCP manifest and RAG pipeline extends the taxonomy where generic CVE data cannot follow. It is what lets Tokynd Pair review an agent the way a scanner reviews a package.
Forward-deployed engineers ship with design partners; field fixes become product; agents earn merge rights team by team through accepted PRs.
Merge rights are trust, and trust is not a feature launch. Teams widen what agents may propose only after a track record of merged, verified fixes — a track record that lives in the corpus (asset a) and cannot be bought.
Six places the per-tool tax compounds — and where a fabric, not another console, is the answer.
Each new solution re-triggers a security review, contract, console, agent, SSO/SAML, SCIM, API keys, schema, owner, renewal, and evidence pull. IBM/PANW found 41% say fragmentation raised procurement costs — the survey-level version of the same tax.
Every console needs its own IdP app, group mapping, role model, and token lifecycle. At the MCP boundary it gets worse: the human’s identity typically disappears, and the server sees an agent holding a static API key — making audit, least-privilege, and revocation structurally hard.
SAST, SCA, CSPM/CNAPP, EDR, and DAST each report the same CVE or misconfiguration under different IDs. One transitive-dependency weakness can surface as dozens of scanner alerts that collapse to a few real fixes once reachability and ownership are applied.
Reco’s State of Agent Security 2026 (vendor telemetry, via SC Media) found 80% of AI tools — including browser extensions and MCP servers — ungoverned, and of 500 MCP servers analysed, 50% enable shell execution, 82% local file read/write, and 73% outbound network calls.
Cycode’s State of ASPM work found 77% of CISOs say understanding who owns application security is challenging. “Assign to the repo owner from CODEOWNERS + cloud tag + IdP manager” is a product feature, not a report.
The same access review, vulnerability scan, or change ticket must be re-pulled from Okta, AWS, GitHub, Jira, and each scanner — per framework (SOC 2, ISO 27001, HIPAA, DORA), per quarter. Evidence is a graph problem, not a spreadsheet problem.
Ranked build bets — design-partner scope, not GA claims. The agent roster below is the product surface; the graph and fix corpus underneath are the moat. Anything here is copyable in code; the defence is proprietary data, neutrality, and sales motion.
One guided flow that onboards any security tool in hours: IdP app (SAML/OIDC), SCIM/groups, API/OAuth with rotation, webhook/ingest, schema mapping, owner, and renewal tracking — proven with a live test finding.
One graph: assets (repo, service, cloud resource, agent, MCP server) ↔ identities (human, machine, agent) ↔ findings (deduplicated) ↔ fixes (PR-ready diffs) ↔ evidence (controls/frameworks).
Reachability-aware fix patches — dependency bump, code patch, IaC correction, secret rotation — delivered as PR-ready diffs with tests, then automatic re-scan/retest that closes the finding everywhere it was duplicated.
Per-agent identity issued at spec/IDE time: scoped, short-lived credentials; human attribution propagated across MCP hops; allow-listed tools; instant revocation; full action log.
Continuous discovery (IdP logs, SCM, repo MCP configs, app catalogue) that finds unsanctioned scanners, SaaS, and AI tools, then routes each through a risk-tiered fast track: sanction, contain, or block.
Controls mapped once to graph nodes; evidence pulled continuously from source tools; one proof reused across SOC 2 / ISO 27001 / HIPAA / DORA with per-framework deltas only.
Security constitutions for Spec Kit / Kiro / BMAD-style flows: data classification, allowed tools/models, banned patterns, and required checks as executable gates from spec → PR → deploy, verifying the shipped artefact matches the spec.
Moat Starter, for design partners: connect the top 15 tools in hours, stand up the risk + evidence graph, fix SCA/secrets/IaC findings as human-approved, merge-ready patches with rescan-verified closure, and add the MCP identity gateway with a shadow-AI discovery report. Sold as a working session that ends in automation your team owns — not another console to onboard.
Ten agents, one job each. Design rules for all ten: typed inputs and outputs; a named human gate before any write to production, identity, or external systems; every output lands as a node or edge in the graph, so agents compound the moat instead of becoming ten new silos; and each agent is measured on one operational metric — never “alerts generated.”
Provisions a new tool end-to-end and proves it works, replacing the onboarding spreadsheet.
Continuously finds unsanctioned scanners, SaaS, AI tools, MCP servers, and agents hiding in your stack.
Collapses the same weakness reported by SAST/SCA/CSPM/CNAPP/EDR/DAST into one owned issue, maintaining the taxonomy that maps scanner IDs to canonical weaknesses.
Ranks canonical issues by reachability, exposure, exploit signals, data sensitivity, and owner capacity — and suppresses unreachable noise with auditable reasons.
Generates the actual fix — dependency bump, code patch, IaC correction, secret-rotation plan — and produces the PR-ready diff + PR body, with tests and a risk note (opening a real PR in your repo is the design-partner step).
Re-scans and retests the exact finding after merge/deploy, confirms closure in every tool that reported it, and reopens on regression.
Pulls control evidence continuously from source tools; maps once and reuses across SOC 2 / ISO 27001 / HIPAA / DORA, flagging stale or missing proof.
Issues and lifecycle-manages identities: human SSO/SCIM per tool, and per-agent scoped, short-lived credentials attributable to the authorising human — including across MCP hops.
Resolves who owns each asset and issue — CODEOWNERS, cloud tags, IdP manager, spec author — and routes it with an SLA, escalating anything unowned.
Enforces the security constitution inside the spec-driven SDLC: checks spec → plan → PR → deploy against data, tool, and banned-pattern rules, and verifies the shipped artefact matches the spec.
Four proprietary assets that get harder to copy with every connected tool, fixed finding, and verified closure.
Per-vendor normalisation quirks, pagination and severity mappings, asset-key joins, and failure modes — maintained and regression-tested like a product, not rebuilt per customer.
The rules that decide “these five scanner IDs are one weakness, owned by this team” — improving with every confirmed cluster and owner, across rival suites, IdPs, SCMs, and MCP registries.
Every finding → fix → verified-closed (or reverted) outcome, labelled. Tenant-isolated by default; any cross-customer learning only as privacy-preserving priors. This corpus is what makes the next fix faster and safer.
Which agents exist, who owns them, what they may touch, and every approval and revocation — the audit-grade system of record that switching away would mean losing.
Why incumbents leave this gap: platform consolidation (Palo Alto, CrowdStrike, Microsoft, Google/Wiz) is a two-year, rip-and-replace programme that ingests third-party scanner, IDE, and MCP data shallowly; ASPM (Cycode, OX, Apiiro) stops at AppSec and at the ticket; security data lakes store normalised data but are not the normaliser, the fixer, or the auditor; SOAR automates alert response, not AppSec fix/verification, agent identity, or audit evidence. A neutral, PR-native fabric over the stack you keep is the layer none of them can sell without conflict.
Evidence above is paraphrased from the October 2026 research pass; vendor sponsorship is flagged where it applies, and no figure here is presented as vendor-neutral unless the source is.
Open questions, stated plainly: no vendor-neutral census of security-tool counts for mid-market companies (200–2,000 employees) was found, so we publish no mid-market average; no vendor-neutral study measuring mean security-review / onboarding hours per tool was found — that is itself a data asset a fabric vendor could publish first; shelfware percentages in circulation are vendor-sponsored and dated, so they are not used as headline evidence here.
This is where Tokynd Security is investing: products mature enough that the solution itself is secure, the intellectual property inside it stays yours, and every agent has an identity you can prove. Our moat is one thread nobody else headlines — spec → identity → code → evidence. Anyone can scan. Fewer can prove who an agent is, what IP it touched, and ship the fix as a merge-ready patch.
We build products the way we ask customers to: spec-driven, secure by construction, and proven as they ship — not patched after an audit finds the gaps.
Your prompts, models, tools, and data are the product. Tokynd Security treats them as intellectual property with provenance — so you can prove what’s yours and spot when it leaks.
Agents multiply faster than the identities that govern them. The gap — ownerless agents, long-lived keys, scopes nobody remembers granting — is where incidents start. We close it at creation, not in cleanup.
Brought to you as services, not just software: a Secure Product Build Sprint (we build the agent with you, spec-first and born-secure), an IP Protection Review (provenance ledger, leak surface, and tenant-isolation proof for what you’ve already built), and an Identity Gap Closure engagement (NHI inventory, owner attestation, and spec-bound re-issuance as merge-ready fix diffs). Each ends in automation your team owns — see Services and Packages.
Every module reads from the same live graph — what agents exist, what tools and scopes they hold, who owns them, what data they touch, and which spec they were built from. That shared context is what lets an agent fix a problem instead of describing it.
A senior security reviewer on every pull request that touches agent code, prompts, tools, or retrieval — one that writes the fix, not just the comment.
Static MCP manifest scan in local v0 — rules TK-MCP-001..009, risk score + safer-manifest diff. Live server probing, registry, and CI blocking are roadmap.
Tokynd Birthright local v0: agent spec → Birth Certificate (JSON + Markdown) with owner fail-closed, expiry/rotation, and provenance hash. No credential is issued — just-in-time issuance is roadmap.
End-to-end risk across code → cloud → identity → AI, ranked by reachability so teams fix the 5% that matters first.
Tokynd Dossier local v0: auditor pack export (manifest / findings.md / controls.csv / evidence.json / zip) from verified closures, with the starter-mapping disclaimer in every export.
Our owned concept: agents and identities, code and PRs, MCP tools, cloud resources, data, controls, and evidence — one connected graph every product reads from and writes to. Hover or tap a node to trace its paths and see how its score is earned, what gaps it carries, which agent owns it, and how the fix lands. Illustrative demo with sample findings — not your estate.
Governance that ends in a merge-ready fix and a verified rescan, not a dashboard. Ten agents produce evidence by doing the work — inventory, tier, map, mint identity, test, remediate, evidence, third-party, drift, audit. Frameworks are named as mappings (EU AI Act, NIST AI RMF, ISO/IEC 42001, SOC 2, OWASP LLM) — never as certifications we hold. Tokynd Attavard lite, Evidence, Remediation, and the deterministic RT-P01..P06 adversarial probe pack now run locally in repo v0.4.0 · 61 tests; the full hosted fleet remains design-partner roadmap — not GA. Tiering and probe findings enter a risk register labeled screening heuristics, not a legal determination.
The existing Risk Graph module, surfaced for risk buyers: every agent, MCP server, repo, cloud resource, identity, finding, fix, and control in one queryable graph — so a CISO sees the reachable path, not four disconnected consoles.
Reachability (can anything actually invoke it?) × exploitability (known signals, exposure) × identity privilege (what its token can do) × data sensitivity (what it can read or exfiltrate). Each factor is shown with its reason — a score you cannot explain is a score an auditor will not trust.
The fleet turns that score into a PR-ready fix, a re-test, and an evidence record. Dashboards describe risk; this fleet is measured on reachable risk removed and controls proven.
Governance clarity without the committee fog. Every control, agent, and piece of evidence sits in one pillar — and accountability is a named owner, not a team. Continuous, not audit-season.
Lineage, PII/secrets in corpora, retrieval permissions, residency.
Inventory, specs, identity at creation, MCP topology, evals.
Tiering, control crosswalks, scoring with reasons, risk register.
Evidence packs, auditor answers cited to artifacts, disclosures.
Continuous tests, drift, incidents, verified rescans — always on.
Press run — a sample MCP over-scope finding travels Inventory → Tiering → Mapping → Remediation fix → Verification → Evidence pack.
Direct and indirect injection, tool-description poisoning, MCP overreach, exfiltration instruction, and hygiene checks. No model is queried; no payload is executed.
Each agent: one role, typed inputs/outputs, a named human gate, a buyer, and its framework mapping. Status labels are honest — Now = v0 in-build locally, Next = design-partner build, Later = roadmap.
File-in/file-out inventory slice for Tokynd Attavard lite: registers AI systems from local inputs — the register Tiering scores. Live cloud/IdP discovery stays roadmap.
Tokynd Attavard lite tiering validated on 3 sample systems — high / minimal / unacceptable-flag — with TAI-01..TAI-10 starter crosswalk. Screening heuristics, not a legal determination.
Maps each control once, then crosswalks it across four frameworks — per-framework deltas only, never four separate projects.
Identity minted at creation, not discovered later: named owner, scoped token, expiry, kill switch, and provenance from the approved spec.
Deterministic RT-P01..P06 probes cover direct and indirect injection, tool-description poisoning, MCP overreach, exfiltration instruction, and hygiene. The vulnerable sample fails 6/6 → high; hardened passes → minimal. No model is queried and no payload executes.
Turns a failed control into a PR-ready fix (diff + PR body) plus retest. Never auto-merges — the named owner merges, the agent proves.
Generates the audit-ready pack from fixes and verifications themselves. v0 exists in our repo (suite v0.4.0, 61 tests) — Tokynd Dossier local v0 exports manifest / findings.md / controls.csv / evidence.json / zip with the starter-mapping disclaimer in every export. SOC 2 / NIST AI RMF mapped today; ISO 42001 / EU AI Act labels are a starter mapping — not a compliance claim or certification.
Living risk register for vendors, model providers, and MCP servers — manifest permission audit included, GPAI supply chain in view.
Treats drift as an incident-in-waiting: posture drift, incident timeline, and the regulator-ready record assembled as it happens.
Answers auditor and questionnaire questions from the evidence graph, every answer cited to the artifact that proves it.
Honesty note: Inventory/Tiering slices (Tokynd Attavard lite), Evidence, Remediation, and RT-P01..P06 probes are local v0 (file-in/file-out, no network, credentials, model calls, or real PRs; 61 tests); the full hosted 10-agent fleet remains a design-partner roadmap beyond those slices. No agent confers certification, no badge wall, no framework logo implying endorsement. Framework names below are mappings we implement — when an independent auditor certifies something of ours, we will name it exactly.
Read across: what each Tokynd Attavard agent maps to in each framework. “—” means no honest direct mapping; we leave it blank rather than invent one.
| Tokynd Attavard agent | EU AI Act | NIST AI RMF | ISO/IEC 42001 | SOC 2 |
|---|---|---|---|---|
| 1 · Inventory | Art 49 registration prep | Map | §6.1 actions to address risks | CC6.6 boundary protection |
| 2 · Risk Tiering | Annex III tiers | Map · Measure | §6.1 risk assessment | CC3 risk assessment |
| 3 · Control Mapping | Crosswalk owner | Crosswalk owner | Crosswalk owner | Crosswalk owner |
| 4 · Identity Provisioning | Art 12 record attribution | Manage | §7.5 documented information | CC6.1 logical access |
| 5 · Continuous Test | Art 15 accuracy & cybersecurity | Measure | §9.1 monitoring & measurement | CC7.1 system operations |
| 6 · Remediation | Art 20 corrective actions (supporting) | Manage | §10.2 nonconformity & corrective action | CC7.1 / CC7.2 |
| 7 · Evidence | Art 12 / 19 record-keeping | Govern (evidence) | §9 performance evaluation | CC7 system operations |
| 8 · Third-Party & MCP | GPAI supply chain (supporting) | Map · Manage | §8.1 operational planning | CC9.2 vendor risk |
| 9 · Drift & Incident | Art 73 serious-incident reporting | Manage · Respond | §10 improvement | CC7.3 / CC7.4 incident response |
| 10 · Audit Copilot | Via crosswalk | Via crosswalk | Via crosswalk | Via crosswalk |
Your deployed estate, compared against your intended architecture — continuously. Six planes scanned, every gap turned into a prioritized PR-ready IaC fix, a verified rescan, and an evidence entry. Delivery: Scan → Gap Review → Fix Sprint → Verify + Evidence. Local v0 shipped (designed vs deployed drift, DR-001..010, gap register, golden test: exactly 5 planted drifts found, exit codes; file-in/file-out, no network/credentials/real PRs); live cloud connectors + .tf HCL adapter are roadmap — not GA.
Every incumbent scans, models, or collects. The Tokynd platform closes: gap → merge-ready fix → rescan → evidence.
Architecture intent lives in specs, IaC, and diagrams. Reality lives in cloud APIs. The Drift Detection Agent compares the two continuously and treats every delta as a finding with an owner — a manually-opened security group, a console-created key, an MCP server that never went through review.
Intent (spec / IaC) → Deployed (cloud APIs) → Delta (gap) → Merge-ready fix → Rescan → Evidence.
Toggle between the approved design and what is actually deployed. Drift lights up amber; click a gap (or its register row) to inspect it. Simulated architecture — illustrative, not a live scan.
| Gap | What drifted | Owner | Severity | Framework | Fix |
|---|---|---|---|---|---|
| G1 | Document store public-read ACL — design requires private + Block Public Access | Platform (named) | High | SOC 2 CC6.1 · CIS | IaC fix diff → rescan |
| G2 | Agent runtime uses a 214-day console-created key instead of a 15-min scoped token | IAM (named) | High | SOC 2 CC6.1 · EU AI Act Art 12 | Identity re-issue → revoke |
| G3 | crm-lookup MCP server unregistered, holding write scope it never calls | AI platform (named) | Medium | OWASP MCP · ISO 42001 §8.1 | Scope-removal diff → registry pin |
Simulated register with sample gaps. In the real scan, every row is generated from your IaC and cloud APIs, owned by a named person, and closes only on a verified rescan.
Data-residency and agent/MCP gaps are scored inside these classes (control-gap and identity subclasses), so the register never invents a fifth bucket. Outputs: Architecture Risk Graph, Gap Register (named owner · reachability/exploitability/privilege scoring · framework map), PR-ready IaC fixes (human merges, never auto-merge), rescan → verified_closed, and evidence exported to your Vanta / Drata / RegScale / ServiceNow.
The intent itself is missing a control: no private endpoint planned, no expiry policy for agent tokens, residency never decided.
Reality departed from intent: console edits, emergency changes never folded back into IaC, shadow resources.
Mapped to EU AI Act / NIST AI RMF / ISO 42001 / SOC 2 / CIS — a control with no implementation, or implementation with no evidence.
Standing privilege, unused scopes, orphaned keys, agents holding human-scale permissions.
Flows crossing regions or boundaries the design never approved; RAG corpora outliving their source ACLs.
Unregistered servers, drifted tool descriptions, agents with no named owner or no kill switch.
They extend the Tokynd Attavard fleet at the architecture layer — same rules: named owner, human merge gate, evidence by default.
Designed vs deployed drift in file-in/file-out local v0 (DR-001..010). Live cloud connectors + .tf HCL adapter are roadmap.
Compares designed intent to deployed reality; golden test finds exactly 5 planted drifts. Every delta becomes a typed, owned gap.
Writes the PR-ready IaC/config fix diff for an approved gap and verifies closure by rescan. Never auto-merges.
Ranked build order, capability-level only. Text names, no logos, no partnership or endorsement claimed. Vendors surfaced as targets until an integration is verified working in build.
Graph findings → fix → write-back verified status.
AWS-native default; Hub finding to verified closure.
Recommendations become evidenced PRs, incl. non-MS estates.
Build target only until API behavior is verified hands-on.
Ingest partners and watch-list in one — neutral either way.
Runners-up (evidence/inventory consumers): Drata · Secureframe · RegScale (OSCAL-shaped export) · Saidot. Threat-model ingest: IriusRisk · ThreatModeler Nexus · OWASP Threat Dragon JSON · Microsoft TMT — our position: threat models that end in merge-ready fixes. Category note: some platforms govern which agents and MCP servers may run; Tokynd Security’s differentiator is different in kind — identity minted at creation, merge-ready fix diffs a human merges, and a verified rescan that writes the evidence.
Your teams don’t need another console. Tokynd agents sit where the work already happens — the IDE, the pull request, the pipeline, and chat — and behave like the senior security engineer every team wishes it had.
Catches MCP, prompt, and RAG issues as your developers write them — inside Cursor, Copilot, Windsurf, and VS Code workflows.
Does: explains the risk, suggests the secure pattern, links the spec section.
Reviews agent changes like a staff security engineer — then drafts the fix as a PR-ready diff for a human to approve.
Does: PR-ready fix diffs with tests; learns from every accept and reject.
Fixes failing pipelines, flaky tests, and dependency or SBOM breaks instead of paging the team that owns them.
Does: root-cause, patch, re-run — pipeline green again.
Answers “how do I do this securely?”, scaffolds golden-path agents, and provisions identity on request.
Does: born-secure scaffolding with logging and guardrails included.
Agents propose. Humans approve. Everything is logged. No Tokynd agent merges, deploys, or changes cloud state without a human gate — and every action is written to your audit trail and mapped to the control it satisfies. That’s what makes the agents safe to give real work.
Spec-driven development is the backbone: the approved spec is the contract. Agents generate and check work against it at every stage, so what ships is mature and secure — not audited into shape afterwards.
The colleague journey: at every stage an agent guides — Tokynd Pair in the IDE and PR, CI Guardian in the pipeline, Infra Hardener at deploy, Platform Guide in Slack. Agents propose · humans approve · everything is logged. Step through it:
Spec Guard turns intent into a versioned spec: capabilities, tools, data access, identity, and guardrails — reviewable like code.
A named owner and a security reviewer approve the spec. Nothing is generated from an unapproved spec.
A signed spec version that every later stage — review, identity, evidence — traces back to.
The Golden-Path Agent scaffolds new agents from the spec with identity, logging, and guardrails already wired in.
Developers build features on the scaffold; deviations from the spec surface immediately, not at review time.
Agent code plus an identity record and a tool inventory, registered from the first commit.
The Review Colleague checks agent code, MCP configs, prompts, and RAG against the spec and live risk data — then writes the fix.
The agent owner approves or rejects each fix diff. Rejections teach the reviewer; nothing merges itself.
A reviewed, spec-conformant change with a full rationale trail an auditor can follow.
CI Guardian fixes failing builds, flaky tests, and dependency breaks, and generates the security tests the spec requires.
Teams approve generated tests once; the agent maintains them as the code evolves.
A green pipeline with test evidence bound to spec requirements.
Infra Hardener turns Wiz, Prisma Cloud, and scanner findings into PR-ready Terraform/CDK fix diffs, grounded in current AWS and Azure documentation.
Platform teams approve IaC changes in the normal PR flow — no console edits, no drift.
Compliant infrastructure as code, with the finding-to-fix thread preserved.
The Runtime SRE Agent watches for tool-abuse sequences, data drift, and identity anomalies across your agents.
On-call approves containment actions; the agent can freeze an agent’s identity instantly when policy demands it.
An incident timeline with every agent action and human decision recorded.
The Evidence Agent continuously tests controls and assembles auditor-ready packs for SOC 2, ISO 42001, NIST AI RMF, and the EU AI Act.
GRC reviews exceptions and risk acceptances; the agent never writes those off on its own.
Fresh, exportable evidence — generated in minutes, not assembled over quarters.
Like Cycode and OX, we aggregate application security posture — but we don’t stop at a dashboard. Today (v0, file-ingest) the Tokynd platform ingests SARIF, Dependabot-style, and Trivy-style exports from GitHub, GitLab, your pipelines, and your cloud scanners — live API connectors are roadmap integrations. It deduplicates and prioritizes by reachability, then turns the ones that matter into validated, merge-ready fix diffs with the exact line, owner, and patch a developer needs.
GitHub Advanced Security, Dependabot, CodeQL, GitLab SAST/Dependency Scanning, plus AWS Inspector, Azure Defender, Trivy, Semgrep, Checkov and your CSPM — as exported files today (SARIF / Dependabot-style / Trivy-style); API and webhook connectors are roadmap.
The same CVE from three scanners becomes one record. We correlate code → package → container → IaC → cloud asset → agent → owner, suppress unreachable code and accepted risk, and rank by exploitability + business context, not CVSS alone.
Each curated finding ships as a fix: bumped version, patched IaC, rotated secret pattern, or hardened config — as a PR-ready diff with tests and a rollback note. No ticket that just says “upgrade lodash.”
The Tokynd platform re-runs the source scanner and re-queries GitHub/GitLab, Wiz/Prisma, Inspector or Defender until the finding disappears, then writes the closure + evidence back to the ticket and the audit pack.
We integrate the scanners you already pay for and fill gaps with cloud-native or open-source tooling, wired into your pipelines as code.
The code platform stays your system of record for code findings — we curate and enrich, we don’t rip it out.
Cloud-provider findings correlated back to the repo and IaC that created the resource.
No license gaps. A proven open-source baseline we install, tune, and maintain in your CI.
Security shifts left, but not as noise. Every phase has a defined scan, a defined owner, and a defined fix path — so developers know exactly what failed, why it matters, and what to click.
Scans/checks: spec completeness, data classification, agent/tool inventory, threat model from spec.
Scans/checks: secrets, insecure patterns, MCP/prompt/RAG lint as the developer types.
Scans/checks: CodeQL/Semgrep (SAST), Dependabot/OSV (SCA + reachability), secret scanning, Checkov/tfsec on Terraform/CDK/Bicep.
Scans/checks: container image CVEs, SBOM generation, artifact signing, dependency provenance.
Scans/checks: CSPM / cloud config (public exposure, IAM, encryption, network), IaC drift vs. approved spec.
Scans/checks: runtime CVE exposure, DAST/API checks, agent tool-abuse sequences, identity anomalies.
What “clarity for developers” means here: every curated finding shows where (file:line / IaC resource / image layer), why it matters (reachable? exploitable? what can this agent actually reach?), who owns it, and the exact fix — diff, version bump, test result, and control it satisfies (e.g. SOC 2 CC7.1, CIS, OWASP). One queue across GitHub, GitLab, AWS, Azure, and open-source scanners, with SLAs by reachability — reachable criticals in days, unreachable noise never paging your team. Delivered as a service too: Pipeline Setup Sprint (we wire GitHub/GitLab + scanners + gates as code) and Vulnerability Curation Service (we run the queue with you until your team owns it) — see Services.
Every product reads from and writes to the Tokynd Assurance Graph. Status badges stay literal: Now · local v0 runs as a deterministic local simulation, Design Partner builds with partners, and Roadmap is planned — nothing here is quietly GA. All 9 suite products have working local code: Tokynd Pair, Tokynd Winnow, Tokynd Vestibule, Tokynd Birthright, Tokynd Attavard lite, Tokynd Asbuilt, Tokynd Dossier, Tokynd Pulse, and Tokynd Sparring — file-in/file-out, no network, credentials, model calls, or real PRs — repo v0.4.0 · 61 tests · commit 2c24c63.
Tokynd Winnow turns the scanner exports you already have into one reachable, owned queue. Tokynd Pair turns that queue into merge-ready patches with a human gate. When MCP, RAG, identities, and runtime behavior enter the stack, the same graph expands with you — no platform reset.
PR Review & Auto-Fix
Security review that ends in a merge-ready patch, not another ticket. The flagship: a senior security colleague in every pull request that touches agent code, MCP, prompts, or RAG.
MCP Permission Scanner
Every MCP server reviewed like code — tools, permissions, description drift — before it holds production scope.
Agent Identity Provisioning
Identity at creation, not discovered after the incident. Every agent is born with a named owner, scoped tools, an expiry, and a kill switch.
Generated locally in your browser from the v0 record schema (owner · scopes · provenance · kill-switch field). No credential is issued — just-in-time issuance is roadmap. Simulated artifact, not a live identity.
Vulnerability Curation
Five scanners, one weakness, one owner, one fix. Duplicate alerts collapse into a reachable, owned queue developers trust.
AI Governance Fleet
AI governance that produces remediation. The 10-agent Tokynd Attavard fleet: inventory, tier, map, mint, test, remediate, evidence, third-party, drift, audit.
Architecture Drift Scanner
Your diagram is the hypothesis; the API is the evidence. Design-vs-deployed drift across six architecture planes, continuously.
Compliance Evidence Pack
One approved fix testifies four times. Fix + verified rescan become auditor-ready evidence, cross-framework.
Agent Behavior Baselining
Know the normal path. Surface the meaningful deviation. Deterministic behavior baselining for agent tool calls, destinations, and policy decisions.
Adversarial AI Red-Teaming
Exercise the agent configuration before an attacker does. Deterministic probes surface injection paths, poisoned tool descriptions, excessive MCP scope, exfiltration instructions, and missing hygiene controls.
No model is queried and no payload is executed.
The nine products above are the public lineup. Everything else Tokynd Security builds lives here — capabilities, supporting agents, and roadmap — searchable and phased honestly. Now runs in v0 today (file-ingest where noted), Next builds with design partners, Later is roadmap. Live API connectors are roadmap integrations and are labeled as such, never implied as shipped.
Keep the CSPM contract and the tools your teams already know. The Tokynd platform ingests their findings, traces each one to the code and the agent behind it, ships the fix, and verifies the closure back in their console.
Findings, asset graphs, and AI inventories stream in from Wiz, Prisma Cloud, Orca, and your scanners via API and webhook.
Each finding is traced cloud → IaC → repo → agent → owner. Wiz says a bucket is public; the Tokynd platform says which agent, which PR, which engineer.
A validated remediation arrives as a PR-ready diff for code or Terraform/CDK — reviewed and approved by your team in the normal flow.
The Tokynd platform re-queries the source tool until the finding closes, then writes evidence back to it, your tickets, and your audit pack.
Tokynd agents don’t guess at cloud security. Their recommendations are grounded in current AWS and Azure documentation and checked against the frameworks your auditors already use.
Well-Architected security pillar, applied by agents that read the same docs your architects do.
Cloud Adoption Framework security guidance, enforced continuously — not just at landing-zone setup.
Every Tokynd agent action that touches AWS is grounded through AWS MCP servers — live documentation, IaC validation, current pricing, and Bedrock knowledge retrieval — so fixes cite real APIs, limits, and service behavior. We claim expertise, not certifications we haven’t earned: partner and certification status will be published here the day it’s real.
Products land faster with people who’ve done it before. Every Tokynd Security engagement ends in automation your team owns — never a runbook dependency on us.
Forward-deployed engineers embedded with your AI and platform teams, shipping secure agents into production alongside them.
A two-week assessment of agent code, MCP topology, identities, RAG permissions, and runtime assumptions — ending in a prioritized gap register and first merge-ready fix diffs.
Run the deterministic RT-P01..P06 probe pack against agent configs, review injection and tool-poisoning paths, then harden the spec and controls with your team.
Stand up an owned AI inventory, screening-heuristics risk tiers, starter control mappings, and a Tokynd Dossier evidence path — with legal and certification decisions kept visibly human-owned.
A two-week discovery of shadow IDE usage, unsanctioned AI tools, and unregistered MCP servers — with team-level productivity baselines, never individual surveillance.
Stand up the Risk & Compliance fleet on your real inventory: classification, control mapping, continuous testing, and evidence automation for SOC 2, ISO 42001, NIST AI RMF, or EU AI Act — frameworks as mappings, ready for your auditor.
The fleet, stood up small: Inventory + Classification + Evidence agents on your highest-risk agents first, with the unified risk graph as the CISO view.
Time-boxed remediation waves: our agents plus our engineers burn down your reachable-risk backlog as merge-ready fixes your engineers merge, measured weekly.
Training and pairing that makes your teams self-sufficient: spec-driven development, AI-DLC practices, secure MCP and agent patterns.
A named senior AWS/Azure security architect on call in your Slack — design reviews, threat models, and audit support without a full-time hire.
Oneleet and Noma both hide pricing behind a sales call. We won’t. Final numbers publish at general availability — the structure below is the contract shape from day one.
For startups facing their first enterprise security review.
For teams building agents, MCP, and RAG into real products.
For regulated and multi-cloud organizations.
No invented numbers: package pricing publishes at GA. Design partners lock launch pricing and shape the roadmap.
Scanner platforms find problems. Compliance platforms file paperwork. The Tokynd platform is built to do the work in between — and to sit on top of the tools you already own.
| Capability | Tokynd | AI-security platforms | Compliance platforms |
|---|---|---|---|
| Fixes delivered as merge-ready patches (human merges) | Yes — core product; opening real PRs is design-partner roadmap | Rarely — findings & tickets | No |
| Agent / MCP / RAG-native review | Yes — spec-driven | Partial — runtime focus | No |
| Agent identity provisioned at creation | Yes — system of record | Discovery only | No |
| Works with Wiz / Prisma you already own | Yes — ingest → fix → verify | Competes with them | Integrates for evidence only |
| End-to-end AI-SDLC (spec → prove) | Yes | No | No |
| Shadow IDE + team productivity | Yes | No | No |
| Human experts bundled (FDE, architect) | Yes | Enterprise tiers only | Partial — vCISO add-ons |
| Published pricing | At GA — structure public now | Quote-only | Quote-only |
No — deliberately. The Tokynd platform ingests findings from Wiz, Prisma Cloud, Orca, Snyk-style SCA, Semgrep/CodeQL, Dependabot, Trivy, and cloud-native scanners; traces each to the code, IaC, agent, and owner; deduplicates them into one owned queue; drafts the PR-ready diff + PR body; and verifies closure back at the source. Keep the scanners and CSPM contracts you trust. Tokynd Security closes the loop they leave open.
Three rules: agents propose and humans approve; every action is scoped by the approved spec and a short-lived identity; and every action is logged to your audit trail and mapped to a control. The Tokynd platform can draft a validated fix diff, tests, risk note, spec check, and PR body. Opening a real PR inside your repo ships with design partners; merging always stays with the human owner under normal branch protection. Agents cannot deploy, widen their own access, or delay revocation.
The spec — capabilities, tools, data access, identity, and guardrails — is written and approved before code is generated. It becomes the contract every later stage checks against: PR review, identity provisioning, testing, and evidence. Security stops being a review at the end and becomes a property of how the system was built.
Starter mappings cover SOC 2, ISO/IEC 42001, NIST AI RMF, the EU AI Act, OWASP LLM and MCP Top 10, and CIS Benchmarks. One control is tested once and mapped where it honestly applies; mappings are not certifications or legal determinations. AWS actions are grounded through AWS MCP servers for documentation, IaC validation, pricing, and Bedrock knowledge retrieval; Azure actions use current Microsoft documentation. Recommendations cite real APIs, limits, and service behavior, then tests and rescans validate the proposed fix.
Not yet. Nine products have working local code in v0.4.0; hosted connectors, live runtime sensing, and opening real repository PRs remain design-partner roadmap. A working session starts by inventorying agents, MCP servers, and shadow AI, curating one real queue, and drafting the first merge-ready fixes against your stack. Partners shape the roadmap, get FDE support, and move to launch pricing at GA. Register through Contact; the current form is a labeled preview and sends nothing.
The build focus is AWS and Microsoft Azure, GitHub and GitLab as code systems of record, and Okta and Microsoft Entra ID for identity. Connector depth is phased in the catalog. Customer code, prompts, tool definitions, and data are tenant-isolated and never train models without explicit opt-in; agents work from the minimum artifact needed, and every action is attributable to a human approver and a scoped identity.
Published structure, no invented numbers: Launch bundles platform + services for a first SOC 2 motion, AI-Native is per-developer platform pricing with optional FDE, and Scale is an annual agreement by deployment shape. Final numbers publish at GA; design partners lock launch pricing. See Packages.
We have no customer logos to show you yet — so we show the work instead: a public launch cadence, a benchmark anyone can re-run, a transparent fix corpus, and a design-partner program with the data-handling terms written down. This is a program we run monthly, stated as a commitment — not a fake launch history.
One shipped capability, demoed on a real sample finding — simulated data labeled as such.
Essays from the build, like the ones in the blog — arguments we use to make product decisions.
A reproducible measurement or a sourced research note — sponsorship and method stated on the page.
One checklist or template joins the library — usable without buying anything.
What shipped, what slipped, what we killed — in the changelog, with test counts.
A public, reproducible benchmark repo (planned): a corpus of finding → fix → verified-closed cases — SARIF in, diff out, rescan proof attached — that anyone can execute and grade. Methodology published before results; failures stay in the repo.
Status · Planned public repo — not live yetEvery corpus entry is a labelled outcome: finding, proposed fix, human decision (merged / edited / rejected), verification result. Tenant-isolated by default; cross-customer learning only as privacy-preserving priors, and your code never trains anything without explicit opt-in. Merge-rate figures are published as targets with a kill gate until they are measured results.
Status · Methodology live on this pageThe local front door to the fabric — runs on your machine, sends nothing anywhere:
How the products above get built: with a small number of teams, on their real stacks, against published terms.
Field notes, learning paths, practical checklists, and a changelog — written from the design-partner build, not copied from a launch template. If something is not live yet, it says so here.
Click any card to read the full note. Each one is a real argument we use to make product decisions — about identity, MCP, curation, merge-ready fixes, evidence, and why discovery alone arrives too late.
Short, applied lessons for engineers, platform teams, and GRC leads shipping agents. Lessons marked in build are outlined and being written with design partners — we will not pretend a lab exists before it runs.
For developers building their first production agent, MCP integration, or RAG feature.
For platform and security engineers who own pipelines, cloud accounts, and non-human identity.
For GRC, founders, and security leaders who need evidence that survives an auditor’s follow-up questions.
Filter by type. Every item below is a preview outline today — available at launch with design partners. No fake PDFs, no gated “reports” that do not exist.
Server inventory, tool-scope review, description-drift check, identity binding, and CI gate — the review we run on every MCP change.
A spec-to-identity template: owner, kind, purpose, tools, scopes, lifetime, revocation, and evidence fields for every new agent.
A redacted sample structure showing how one control maps to PR, identity, test, and re-scan evidence — sample only, no customer data.
System inventory, risk tiering, record-keeping, human oversight, and transparency prompts aligned to how engineering actually ships.
How to make remediation mergeable: small diff, tests, risk note, rollback, spec check, and verified closure — with examples from the build.
AWS and Azure patterns for agent identity, private networking, secrets, logging, and guardrails — grounded in current cloud documentation.
A live working format, not a slide webinar: bring one repo and one scanner export; leave with a curated queue and a draft merge-ready fix.
A minimal approved-spec template for agent capabilities, allowed tools/models, banned patterns, data classes, and required checks.
One row per AI system: owner, purpose, kind, tools/MCP, models, data classes, identity, tier, and evidence links — the input the Classification Agent expects.
Walk a system to unacceptable / high / limited / minimal with the scoring rationale (reachability, exploitability, privilege, sensitivity) an auditor can follow.
Per-server manifest audit: tools, scopes vs actual calls, description drift, identity binding, update channel, kill switch.
The creation record for every agent: named owner, kind, purpose, scoped token, expiry, provenance, and revocation path.
Sample pack structure: Art 12 records, tier rationale, crosswalk, fix + rescan trail — sample only, no customer data.
Incident record fields that satisfy both day-to-day record-keeping and serious-incident reporting drills.
Design-vs-deployed checks for AWS/Azure landing zones: identity, network, data residency, IaC drift, agent/MCP topology.
The Tokynd Asbuilt gap register: gap class, named owner, reachability/exploitability/privilege score, framework map, fix diff, verified_closed date.
A weekly design-vs-deployed review: IaC diff, console orphans, drift age, risk-acceptance expiries, rescan proof.
The sourced research themes already cited on this site — tool sprawl and the fix backlog — collected as reading notes with vendor-sponsorship flags intact.
The two public themes underneath the product — stated with the same sourcing discipline as the moat section above. No new numbers are invented here.
Every additional security tool repeats identity, schema, owner, renewal, and evidence work. See the sourced figures and caveats in The proprietary moat.
Detection keeps improving while remediation stalls. Our reading starts from the same on-page sources in The proprietary moat and DevSecOps.
Agents, MCP servers, keys, and workloads all become governable when each non-human identity has a kind, owner, scope, and expiry. See Build focus.
“Shipped locally” means it runs in our build environment and its tests pass. It does not mean GA, hosted, or available to click today.
Tokynd Pulse: deterministic TK-RG-001..007 baseline from a training trace; normal sample → 0 deviations / allow, attack sample → 5 deviations / deny for shell.exec, unknown tool, and exfiltration domain. Tokynd Sparring: deterministic RT-P01..P06 checks direct/indirect injection, tool-description poisoning, MCP overreach, exfiltration instruction, and hygiene; vulnerable sample fails 6/6 → high, hardened passes → minimal. No model queried, no payload executed, no performance or latency claims. Both are local simulations; live runtime sensors remain design-partner roadmap. 9 suite products now have working local code (file-in/file-out, no network, credentials, model calls, or real PRs). 61 tests passing. Commit 2c24c63 in github.com/amjdseyal007/tokynd.
Tokynd Asbuilt local v0: designed vs deployed drift (DR-001..010), gap register, golden test finds exactly 5 planted drifts, exit codes; live cloud connectors + .tf HCL adapter remain roadmap. Tokynd Attavard lite local v0: tiering for 3 sample systems (high / minimal / unacceptable-flag) with TAI-01..TAI-10 starter crosswalk — screening heuristics, not a legal determination; full 10-agent fleet remains design-partner roadmap beyond Inventory/Tiering slices. 7 of 7 suite products now have working local code (file-in/file-out, no network/credentials/real PRs). 45 tests passing. Commit 92a102e in github.com/amjdseyal007/tokynd.
Tokynd Vestibule local v0: static MCP manifest scan, rules TK-MCP-001..009, risk score + safer-manifest diff (over-scoped sample: 7 findings, 100/100; least-privilege: clean); live server probing is roadmap. Tokynd Birthright local v0: Birth Certificate JSON + Markdown, owner fail-closed, expiry/rotation, provenance hash — no credential issued. Tokynd Dossier local v0: auditor pack export (manifest / findings.md / controls.csv / evidence.json / zip) with the starter-mapping disclaimer in every export. 30 tests passing. Commit 0a749de.
ConnectorError exit codes so malformed finding files fail loudly instead of silently; a minimal local Discovery agent (file markers for MCP/agent surfaces — no network); the Identity record generator behind Tokynd Birthright (owner · scopes · provenance · kill-switch field, no credential issued); and starter ISO 42001 / EU AI Act evidence labels on top of the SOC 2 / NIST mapping — a starter mapping, not a compliance claim. 14 tests passing. Commit b25b877 in github.com/amjdseyal007/tokynd.
Normalized vulnerability record; curation, triage, fix, verify, and evidence flow; SARIF / Dependabot-style / Trivy-style inputs normalized into one record. 7 tests passing in the local build. Source: github.com/amjdseyal007/tokynd.
Tokynd Pair, Tokynd Winnow, Tokynd Vestibule, Tokynd Birthright, Tokynd Attavard, Tokynd Asbuilt, Tokynd Dossier, Tokynd Pulse, and Tokynd Sparring all have working local v0 code; hosted workflows and live integrations are being built with design partners. Phases elsewhere on this page stay labeled Now / Next / Later.
Planned, not shipped: hosted connector onboarding for the first tool set, MCP identity gateway hardening, evidence exports, and the learning-center labs. Listed here so the roadmap is inspectable — not presented as released features.
Docs are in build alongside the product. At launch, design partners get: getting started (connect a repo, ingest SARIF, curate a queue), identity provisioning, Tokynd Vestibule policy, evidence exports, and API/webhook references. Until then, the closest honest preview is the library and the changelog above.
Every non-human identity is a token — a service account, API key, workload credential, MCP server, or AI agent. Each token has a kind: what it is, who owns it, what it may do, and when it expires. Tokynd Security exists to govern agents by kind, and to turn security work into approved fixes with evidence attached.
The logo is the thesis, drawn in three strokes — in security terms.
Hover or focus a card to isolate its part of the mark.
The credential as an object: a thing that exists, that can be held, copied, and stolen. It is drawn as a ring because a token is only as strong as the boundary around it.
The policy inside the credential. The K sits within the ring the way a kind sits within a token — the classification that decides what the token may do. A ring without the K is just a coin: value with no rules.
Pinned at the junction of the K — the exact center of the token's scope: observed, owned, expiring. Amber, the color of a struck token — an identity under governance, not an alarm.
No shields, no padlocks, no fear. Tokynd governs identity — and a governed identity is a quiet one.
Help AI engineers ship agents secure by construction — and prove it. We put security agents inside the tools developers already use, so the secure path is the normal path: spec, identity, review, fix, verification, and evidence in one thread.
Agent sprawl is outrunning review. Teams are adding IDE agents, MCP servers, RAG pipelines, and model tools faster than security can inventory them — while machine identities already vastly outnumber human ones (sourced on this page). Discovery after the fact is too late; governance has to start at creation.
How we build, and how our agents are allowed to behave.
No agent merges, deploys, widens privilege, or changes cloud state without a human gate. Speed comes from a better proposal, not from removing the approver.
Every fix carries its spec version, tests, source finding, approval, and re-verification. If it cannot be shown, it is not done.
Keep Wiz, Prisma Cloud, Orca, GitHub, GitLab, AWS, and Azure. The Tokynd platform is the neutral fix-and-prove layer across the stack you already own.
Customer code, prompts, and data are not used to train models unless a customer explicitly opts in. Tenant isolation is a product requirement, not a policy footnote.
A security product has to be inspectable about its own handling. This is the standard we build to and will publish evidence against as the hosted product matures.
Tokynd Security is designed so trace telemetry and raw runtime events remain where they originate; the platform receives only the minimum approved findings or evidence artifacts needed for the workflow. Customer code, prompts, and data never train models without explicit opt-in.
Deployment shapes are documented roadmap options in v0.4.0, not hosted availability claims. Local v0 is file-in/file-out with no network or credentials.
Customer code, prompts, tool definitions, and retrieval sources are tenant-isolated and are never used to train models without explicit opt-in. Server-side, we aim to process the minimum artifact needed for the task — a diff, a finding, a spec — not a wholesale copy of your estate.
Connector quirks, ranking priors, and fix-corpus learnings that create the moat are kept as server-side trade secrets and privacy-preserving priors. They are listed here as capabilities — not published as recipes, and never as another customer’s data.
Releases are built to carry signed commits, an SBOM, and an AI-BOM (models, prompts, tools, and data sources) so a customer can verify what ran, what it touched, and which spec approved it.
Least-privilege, short-lived credentials; encryption in transit and at rest; regional handling where the deployment model requires it; and deletion on contract end. Private-silo and client-cloud deployment shapes are described in Packages.
Human and agent actions are attributable: who approved what, which identity acted, what changed, and how closure was verified. The agent identity registry is designed to be the audit-grade record of that activity.
Tokynd Security is not SOC 2 certified today, and we will not badge otherwise. Tokynd Dossier is built to produce SOC 2-style evidence continuously; our own SOC 2 programme is on the roadmap and will be stated here the day an independent auditor completes it.
Found a vulnerability in Tokynd Security itself? SECURITY.md lives in our repo — please report through GitHub’s private vulnerability reporting on amjdseyal007/tokynd. We do not have a monitored security mailbox yet, and we would rather say so than publish an address nobody reads.
Founding roles open with the design-partner phase. We are not posting fake jobs or collecting applications into a void — register interest through the same design-partner / waitlist route below and tell us which role family fits.
Owns curation, reachability, and verification quality across scanner sprawl. You have shipped AppSec tooling developers actually kept using.
Builds the agent fabric: typed agents, human gates, identity issuance, MCP policy controls, and the evidence graph underneath them.
Embeds with design partners, wires the stack in hours, and turns field pain into product. Ends every engagement in automation the customer owns.
Design partner, services, or learning — one route into Tokynd Security. This form is a front-end preview and is not connected yet: submitting shows what would be sent and does not transmit anything. Domain mail is being set up; [email protected] will be published here once it is live.
[email protected] is the intended address for tokynd.com (purchased Oct 10, 2026). It will be shown as live here only once domain mail is configured — until then, use the preview form to shape what you would send.
Code & changelog: github.com/amjdseyal007/tokynd
One email a month: what shipped, what we learned, and one practical checklist. Preview signup — not connected yet.
Start with the agents, MCP servers, and scanner exports you already have. Leave with an owned register, a prioritized fix loop, and evidence your team can reproduce.