Tokynd Security · Enterprise AI Security

Every action your agents take — seen, approved, and proven.

Tokynd Security puts AI security colleagues inside the tools your developers and infrastructure teams already use. They review agent code, MCP, prompts and RAG, baseline runtime behavior, propose merge-ready patches, verify the rescan, and turn each approved fix into evidence — end to end across the AI-SDLC.

Merge-ready patches, not findingsValidated remediation in code & IaC
No rip-and-replaceWorks with Wiz, Prisma Cloud, Orca
AWS + Azure depthGrounded in live cloud documentation
Where we are: all 9 named suite products have working local code — Tokynd Pair, Tokynd Winnow, Tokynd Vestibule, Tokynd Birthright, Tokynd Attavard lite, Tokynd Asbuilt, Tokynd Dossier, Tokynd Pulse, and Tokynd Sparring — file-in/file-out, no network, credentials, model calls, or real PRs; repo v0.4.0 · 61 tests · commit 2c24c63. Runtime sensor integration and hosted product remain design-partner roadmap; there are no customer logos, performance claims, or GA language here.
acme/support-agent · PR #482 tokynd-agent
Sample finding Simulated demo
High mcp/tools.json · server: crm-lookup

MCP tool granted write scope it never uses

The crm-lookup server holds crm.records.write and crm.records.delete, but the agent only calls read paths. Reachability analysis confirms no write call in 90 days of traces. Combined with an unvalidated prompt template, a single injected instruction could delete customer records.

Control SOC 2 CC6.1 Framework OWASP MCP Top 10 Reachable yes — tool layer
Fix proposed pair-output/fix-482 · 2 files changed
// mcp/tools.json — scope the server to what the agent uses - "scopes": ["crm.records.read", "crm.records.write", "crm.records.delete"] + "scopes": ["crm.records.read"] + "identity": "tokynd://agent/support/crm-lookup (15-min token)" // prompts/triage.md — bind tool calls to the approved spec + tool_policy: spec://support-agent/v3#tools.read-only
Tests 41 passed Spec check v3 ✓ Human gate approval required
✓

Patch approved — local patch approved; simulated merge event recorded — no repository contacted.

✓

Identity re-issued — long-lived key retired; scoped 15-minute token provisioned by Tokynd Birthright.

✓

Finding re-verified — Wiz re-queried: exposure closed. Evidence written back to Wiz and your ticket.

✓

Control evidence logged — SOC 2 CC6.1 / ISO 42001 A.6 evidence pack updated automatically.

Controls mapped to
SOC 2ISO/IEC 42001NIST AI RMFEU AI ActOWASP LLM & MCP Top 10CIS Benchmarks
Two problems. One cause.

AI crossed from assistant to operator.

Agents now take consequential actions in real systems. The security model has to govern the identity making the move, the path it takes, and the fix that follows — without turning innovation into another ticket queue.

01

Enterprise AI is here.

Agents move money, touch PII, call production tools, and change systems. Every non-human identity is a token; without a named owner, scoped permissions, expiry, and a kill switch, that token is governed too late.

Identity must be born with the agent.
02

Adversarial AI is here.

Direct and indirect injection, tool-description poisoning, MCP overreach, and noisy alert floods are already part of the operating model. Visibility matters; a governed response matters more.

Every deviation needs an owner and a fix loop.
One causeAgents act without governed identity and without a fix loop.

Tokynd Security closes both through the Tokynd platform: Tokynd Birthright at creation, then see → fix → govern → prove across every action.

The platform

Unlike gateways, scanners, or dashboards, the Tokynd platform works where agents are built. Identity is minted at creation, fixes arrive as merge-ready patches a human approves, and evidence is generated by the fix itself.

Verb 01

Discover

Inventory every agent, MCP server, identity, and architecture gap — born at creation where possible, found fast where not.

Verb 02

Fix

Merge-ready fix patches a human approves — scope removals, IaC corrections, dependency bumps — never another ticket queue.

Verb 03

Prove

Verified rescans close the finding at the source, and every fix emits cross-framework evidence an auditor can follow.

Platform loopTokynd Pair fixes → Verification proves → Tokynd Attavard maps → Audit Copilot answers
Gatewayroutes traffic
≠
Scannerfinds issues
≠
Dashboardorganizes risk
→
Tokyndgoverns identity, proposes the fix, proves closure
Four operating pillars

See the action. Fix the path. Govern the identity. Prove the outcome.

Nine distinct products work as one colleague system. Each pillar has one operational job, one human gate, and one place in the Discover → Fix → Prove loop.

SEE

Every action, visible in context.

Tokynd Winnow turns scanner noise into one owned queue. Tokynd Pulse learns the deterministic baseline and surfaces deviations without claiming a live sensor.

Tokynd Winnow · Vulnerability CurationTokynd Pulse · Agent Behavior Baselining
Explore See →
FIX

Security that arrives as help.

Tokynd Pair produces the smallest reviewable patch, tests it locally, drafts the PR body, and waits for a human. Opening real repository PRs remains design-partner roadmap.

Tokynd Pair · PR Review & Auto-Fix
Explore Fix →
GOVERN

Every token has a kind, owner, and boundary.

Tokynd Attavard tiers and maps. Tokynd Birthright creates the identity record. Tokynd Vestibule reviews MCP permissions. Tokynd Sparring exercises adversarial configurations.

Tokynd Attavard · Tokynd BirthrightTokynd Vestibule · Tokynd Sparring
Explore Govern →
PROVE

Evidence generated by remediation.

Tokynd Dossier packages the approved fix and verified rescan. Tokynd Asbuilt compares architecture intent with deployed descriptors and emits the gap register.

Tokynd Dossier · Compliance Evidence PackTokynd Asbuilt · Architecture Drift Scanner
Explore Prove →
Proof without theater

Show the method. Publish the benchmark. Let the work speak.

No invented customer wall, no anonymous praise, no borrowed certification badge. Tokynd Security earns proof from reproducible artifacts and design partners willing to judge the fix.

01

Design-partner program

One repo, one scanner export, one named security and engineering owner. The pilot is measured on accepted patches and verified closures — not alerts generated.

See the program →
02

Fix-corpus transparency

Finding → proposed patch → human decision → verification result. Internal merge-rate targets stay labeled as targets until they become measured outcomes.

03

Reproducible benchmark plan

A public benchmark repo is planned with planted vulnerable and hardened fixtures, deterministic expected outputs, and versioned rules. It is a plan, not a published benchmark today.

04

Changelog in the open

v0.4.0, 61 tests, commit 2c24c63. Every status on this page names what runs locally, what needs a design partner, and what remains roadmap.

AI security products

Nine products. One platform. One Assurance Graph.

Every product reads from and writes to the Tokynd Assurance Graph. Status badges stay literal: Now · local v0 runs as a deterministic local simulation, Design Partner builds with partners, and Roadmap is planned — nothing here is quietly GA. All 9 suite products have working local code: Tokynd Pair, Tokynd Winnow, Tokynd Vestibule, Tokynd Birthright, Tokynd Attavard lite, Tokynd Asbuilt, Tokynd Dossier, Tokynd Pulse, and Tokynd Sparring — file-in/file-out, no network, credentials, model calls, or real PRs — repo v0.4.0 · 61 tests · commit 2c24c63.

AppSec for every team

Start with your SCA/SAST backlog. Grow into agents.

Tokynd Winnow turns the scanner exports you already have into one reachable, owned queue. Tokynd Pair turns that queue into merge-ready patches with a human gate. When MCP, RAG, identities, and runtime behavior enter the stack, the same graph expands with you — no platform reset.

SCA / SAST→Tokynd Winnow→Tokynd Pair→Agent + MCP security→Tokynd Dossier

Tokynd Pair

PR Review & Auto-Fix

Security review that ends in a merge-ready patch, not another ticket. The flagship: a senior security colleague in every pull request that touches agent code, MCP, prompts, or RAG.

Design PartnerFix
Failure preventedAgent changes merging with over-scoped tools, prompt-injection surface, and RAG permission bleed — found by an auditor or an incident instead of a reviewer.
Capabilities
  • Reviews agent code, MCP configs, prompts, RAG in the PR
  • Generates the validated fix diff + PR body (v0, local)
  • Secrets & NHI-in-code checks folded into every review
OutcomeFindings leave as mergeable fixes with tests and a spec check — measured on merge rate, not alert count.
IntegrationsGitHub · GitLab · Cursor / Copilot / Windsurf (roadmap)
Platform loopReceives findings + spec from the Assurance Graph → sends fix diffs, merge outcomes, and corpus labels back.
Human gateThe agent owner merges. Tokynd Pair never merges, deploys, or widens its own access.
Try it: the live simulated PR at the top of this page — pick a finding, review the fix, approve the merge yourself.
Fix-loop in local v0Review commenting + opening real PRs in your repos = design-partner roadmap.Join design partners

Tokynd Vestibule

MCP Permission Scanner

Every MCP server reviewed like code — tools, permissions, description drift — before it holds production scope.

Now · local v0Discover
Failure preventedAn MCP server quietly holding write/delete scope it never calls — the standing privilege a steered prompt turns into data loss.
Capabilities
  • Static MCP manifest scan: rules TK-MCP-001..009 (local v0)
  • Risk score + safer-manifest diff per scan
  • Sample (repo): over-scoped = 7 findings, 100/100 · least-privilege = clean
OutcomeOver-scoped manifests caught before they hold production scope; least-privilege manifests verify clean.
IntegrationsMCP manifests (file-in/file-out in v0) · repo configs · IDE agent settings (roadmap)
Platform loopReceives manifests → sends scope findings and risk scores to the graph.
Human gateSecurity approves every new server and every scope widening.
Try it: run the live simulated demo at the top of this page.
Static manifest scan in local v0Live server probing is roadmap; registry + CI gates build next with design partners.Register interest

Tokynd Birthright

Agent Identity Provisioning

Identity at creation, not discovered after the incident. Every agent is born with a named owner, scoped tools, an expiry, and a kill switch.

Now · local v0Discover → Fix
Failure preventedOwnerless agents running on 214-day console keys that nobody can revoke safely because nobody recorded what they were for.
Capabilities
  • Birth Certificate JSON + Markdown: owner fail-closed, expiry/rotation, provenance hash (local v0)
  • Orphan + over-scope detection against the registry
  • Just-in-time credential issuance (roadmap — no credential is issued)
OutcomeEvery agent provable in one record: who owns it, what it may touch, when it expires, how it dies.
IntegrationsApproved specs (file-in/file-out in v0) · Okta / Entra (roadmap) · MCP manifests
Platform loopReceives the approved spec → sends the birth record into the Identity Graph every other product reads.
Human gateNamed owner approves scopes; revocation never waits for a gate. Missing owner fails closed.
Agent Identity Birth Certificate

Generated locally in your browser from the v0 record schema (owner · scopes · provenance · kill-switch field). No credential is issued — just-in-time issuance is roadmap. Simulated artifact, not a live identity.

Birth Certificate in local v0JSON + Markdown, owner fail-closed; no credential issued. JIT issuance + IdP wiring are roadmap.Register interest

Tokynd Winnow

Vulnerability Curation

Five scanners, one weakness, one owner, one fix. Duplicate alerts collapse into a reachable, owned queue developers trust.

Now · local v0Discover
Failure preventedThe same CVE paged by three scanners under three IDs, owned by nobody, ageing past the 252-day mean-time-to-fix baseline.
Capabilities
  • File-ingest v0: SARIF / Dependabot-style / Trivy-style reports normalized to one record
  • Dedupe + reachability ranking + owner routing
  • Verified closure propagated back to every source (roadmap connectors)
OutcomeOne canonical queue, reachable first — each item carrying file:line, owner, fix, and proof.
IntegrationsToday: exported finding files · Roadmap: live GitHub / GitLab / AWS / Azure APIs
Platform loopReceives scanner exports → sends canonical issues to Tokynd Pair (fix) and Tokynd Dossier (evidence).
Human gateAppSec approves merges of critical duplicates; suppression reasons stay auditable.
See it: the requests CVE sample in the hero demo — three scanner alerts curated into one owned issue.
File-ingest local v0 runs todayLive source connectors are roadmap integrations — labeled, not implied.See v0.3.0

Tokynd Attavard

AI Governance Fleet

AI governance that produces remediation. The 10-agent Tokynd Attavard fleet: inventory, tier, map, mint, test, remediate, evidence, third-party, drift, audit.

Now · local v0 (lite)Fix → Prove
Failure preventedGovernance theater: beautiful registers and heat maps while the same reachable weakness survives another quarter.
Capabilities
  • Tokynd Attavard lite: tiering for 3 sample systems (high / minimal / unacceptable-flag) in local v0
  • TAI-01..TAI-10 starter crosswalk; screening heuristics — not a legal determination
  • Full 10-agent fleet remains design-partner roadmap beyond Inventory/Tiering slices
OutcomeReachable risk removed and controls proven from the same loop — not two programmes duplicating each other.
IntegrationsThe full fleet below · EU AI Act / NIST AI RMF / ISO 42001 / SOC 2 mappings (starter)
Platform loopReceives the whole graph → sends tiers, control maps, fix diffs, and evidence to Tokynd Dossier.
Human gateNamed risk owner approves every tier; GRC approves every external answer.
Try it: run the live simulated demo at the top of this page.
Tokynd Attavard lite in local v0Tiering + crosswalk starter run today; full fleet is roadmap beyond Inventory/Tiering.Explore the fleet

Tokynd Asbuilt

Architecture Drift Scanner

Your diagram is the hypothesis; the API is the evidence. Design-vs-deployed drift across six architecture planes, continuously.

Now · local v0Discover
Failure preventedArchitecture risk hiding in the distance between approved design and deployed reality — console keys, public ACLs, shadow resources.
Capabilities
  • Designed vs deployed drift: DR-001..010, gap register, exit codes (local v0)
  • Golden test: exactly 5 planted drifts found
  • Live cloud connectors + .tf HCL adapter are roadmap
OutcomeDrift half-life measured in days: gap → PR-ready IaC fix → verified rescan → evidence.
IntegrationsDesigned/deployed descriptors (file-in/file-out in v0) · Terraform / CDK / CloudFormation / Bicep + AWS/Azure APIs (roadmap)
Platform loopReceives designed intent + deployed descriptors → sends gaps to Tokynd Pair / Infra Hardener fixes and closures to Tokynd Dossier.
Human gateEA confirms intent sources; owners accept, fix, or time-box risk acceptance.
Try it: run the live simulated demo at the top of this page.
Designed vs deployed drift in local v0DR-001..010 + gap register ship today; live connectors roadmap.See the scan

Tokynd Dossier

Compliance Evidence Pack

One approved fix testifies four times. Fix + verified rescan become auditor-ready evidence, cross-framework.

Now · local v0Prove
Failure preventedAudit-season archaeology: reconstructing March in November from tickets and memory, four frameworks collected four times.
Capabilities
  • Auditor pack export: manifest / findings.md / controls.csv / evidence.json / zip (local v0)
  • Starter-mapping disclaimer in every export — a mapping, never a certification
  • Questionnaire answers cited to artifacts (roadmap)
OutcomeEvidence as a byproduct of engineering: fresh, linked, exportable in minutes.
IntegrationsVerified closures (file-in/file-out in v0) · Vanta / Drata / RegScale evidence push (targets)
Platform loopReceives verified closures from every product → sends evidence packs + control status back to the graph.
Human gateGRC reviews exceptions and approves the pack before any auditor sees it.
Try it: run the live simulated demo at the top of this page.
Auditor pack export in local v0Disclaimer in every export. Starter mapping — not a compliance claim or certification.Register interest

Tokynd Pulse

Agent Behavior Baselining

Know the normal path. Surface the meaningful deviation. Deterministic behavior baselining for agent tool calls, destinations, and policy decisions.

Now · local v0Observe → Prove
Failure preventedAn agent leaves its known tool path, reaches an unknown tool, or follows an exfiltration instruction without an explainable deviation record.
Capabilities
  • Deterministic baseline learned from a training trace using TK-RG-001..007
  • Attack sample: 5 deviations; policy denies shell.exec, unknown tool, and exfiltration domain
  • Normal sample: 0 deviations; policy allows
OutcomeEach deviation becomes a reasoned finding that can enter Tokynd Attavard, trigger human review, and land in Tokynd Dossier.
Scope todayLocal trace simulation only — no live sensor, network, credentials, model calls, latency, or performance claims.
Platform loopReceives trace events → compares them to baseline → sends deviations and policy decisions to the Assurance Graph.
Human gateSecurity owns baseline approval and policy changes; runtime sensor integration is design-partner roadmap.
Local simulation · sample traces

Baseline / deviation check

ALLOW · 0 deviationsKnown tool sequence, approved destination, and expected scope. Deterministic sample; no model queried.
TK-RG-001..007 in local v0Runtime sensor integration is design-partner roadmap; this demo makes no latency or performance claim.Pilot Tokynd Pulse

Tokynd Sparring

Adversarial AI Red-Teaming

Exercise the agent configuration before an attacker does. Deterministic probes surface injection paths, poisoned tool descriptions, excessive MCP scope, exfiltration instructions, and missing hygiene controls.

Now · local v0Govern
Failure preventedA vulnerable agent configuration reaching production without anyone exercising the instructions, tools, scopes, and exfiltration paths together.
Capabilities
  • RT-P01..P06: direct/indirect injection, tool-description poisoning, MCP overreach, exfiltration instruction, hygiene
  • Vulnerable fixture fails 6/6 → high; hardened fixture passes → minimal
  • Findings enter a screening-heuristics risk register
OutcomeA reviewable adversarial gap list tied to the same owners, controls, fixes, and evidence as the rest of the platform.
Scope todayDeterministic local config checks only — no model queried, no payload executed, no live attack, and no claim that a model is attack-proof.
Platform loopReceives agent configs and policies → sends probe findings to Tokynd Attavard for tiering and Tokynd Pair for remediation.
Human gateSecurity defines the authorized probe scope, reviews every high finding, and approves the hardening change.
RT-P01..P06 · deterministic sample

Choose the agent configuration

No model is queried and no payload is executed.

HIGH · 6/6 probes failedInjection, poisoned description, excessive MCP scope, exfiltration instruction, and hygiene findings enter the risk register.
RT-P01..P06 in local v0Screening heuristics only; no model call, payload execution, or runtime protection claim.Explore the sprint
FAQ

Straight answers.

No — deliberately. The Tokynd platform ingests findings from Wiz, Prisma Cloud, Orca, Snyk-style SCA, Semgrep/CodeQL, Dependabot, Trivy, and cloud-native scanners; traces each to the code, IaC, agent, and owner; deduplicates them into one owned queue; drafts the PR-ready diff + PR body; and verifies closure back at the source. Keep the scanners and CSPM contracts you trust. Tokynd Security closes the loop they leave open.

Three rules: agents propose and humans approve; every action is scoped by the approved spec and a short-lived identity; and every action is logged to your audit trail and mapped to a control. The Tokynd platform can draft a validated fix diff, tests, risk note, spec check, and PR body. Opening a real PR inside your repo ships with design partners; merging always stays with the human owner under normal branch protection. Agents cannot deploy, widen their own access, or delay revocation.

The spec — capabilities, tools, data access, identity, and guardrails — is written and approved before code is generated. It becomes the contract every later stage checks against: PR review, identity provisioning, testing, and evidence. Security stops being a review at the end and becomes a property of how the system was built.

Starter mappings cover SOC 2, ISO/IEC 42001, NIST AI RMF, the EU AI Act, OWASP LLM and MCP Top 10, and CIS Benchmarks. One control is tested once and mapped where it honestly applies; mappings are not certifications or legal determinations. AWS actions are grounded through AWS MCP servers for documentation, IaC validation, pricing, and Bedrock knowledge retrieval; Azure actions use current Microsoft documentation. Recommendations cite real APIs, limits, and service behavior, then tests and rescans validate the proposed fix.

Not yet. Nine products have working local code in v0.4.0; hosted connectors, live runtime sensing, and opening real repository PRs remain design-partner roadmap. A working session starts by inventorying agents, MCP servers, and shadow AI, curating one real queue, and drafting the first merge-ready fixes against your stack. Partners shape the roadmap, get FDE support, and move to launch pricing at GA. Register through Contact below — messages go straight to the Tokynd Security team.

The build focus is AWS and Microsoft Azure, GitHub and GitLab as code systems of record, and Okta and Microsoft Entra ID for identity. Connector depth is phased in the catalog. Customer code, prompts, tool definitions, and data are tenant-isolated and never train models without explicit opt-in; agents work from the minimum artifact needed, and every action is attributable to a human approver and a scoped identity.

Published structure, no invented numbers: Launch bundles platform + services for a first SOC 2 motion, AI-Native is per-developer platform pricing with optional FDE, and Scale is an annual agreement by deployment shape. Final numbers publish at GA; design partners lock launch pricing.

About · Tokynd Security

Tokynd Security: Token + Kind.

Every non-human identity is a token — a service account, API key, workload credential, MCP server, or AI agent. Each token has a kind: what it is, who owns it, what it may do, and when it expires. Tokynd Security exists to govern agents by kind, and to turn security work into approved fixes with evidence attached.

What our mark means

The logo is the thesis, drawn in three strokes — in security terms.

Hover, focus, or tap a card to isolate its part of the mark.

The ring is the token

The credential as an object: a thing that exists, that can be held, copied, and stolen. It is drawn as a ring because a token is only as strong as the boundary around it.

The K is the kind

The policy inside the credential. The K sits within the ring the way a kind sits within a token — the classification that decides what the token may do. A ring without the K is just a coin: value with no rules.

The amber node is the identity

Pinned at the junction of the K — the exact center of the token's scope: observed, owned, expiring. Amber, the color of a struck token — an identity under governance, not an alarm.

No shields, no padlocks, no fear. Tokynd governs identity — and a governed identity is a quiet one.

Mission

Help AI engineers ship agents secure by construction — and prove it. We put security agents inside the tools developers already use, so the secure path is the normal path: spec, identity, review, fix, verification, and evidence in one thread.

Why now

Agent sprawl is outrunning review. Teams are adding IDE agents, MCP servers, RAG pipelines, and model tools faster than security can inventory them — while machine identities already vastly outnumber human ones (sourced on this page). Discovery after the fact is too late; governance has to start at creation.

Principles

How we build, and how our agents are allowed to behave.

Agents propose, humans approve

No agent merges, deploys, widens privilege, or changes cloud state without a human gate. Speed comes from a better proposal, not from removing the approver.

Evidence by default

Every fix carries its spec version, tests, source finding, approval, and re-verification. If it cannot be shown, it is not done.

No rip-and-replace

Keep Wiz, Prisma Cloud, Orca, GitHub, GitLab, AWS, and Azure. The Tokynd platform is the neutral fix-and-prove layer across the stack you already own.

Your code trains nothing without opt-in

Customer code, prompts, and data are not used to train models unless a customer explicitly opts in. Tenant isolation is a product requirement, not a policy footnote.

Status, plainly: Tokynd Security is in build with design partners, not yet GA. This site describes the real offer and labels phases honestly; it shows no customer logos, testimonials, metrics, or certifications we have not earned.
Tokynd Security · Contact

Tell us what you need.

Design partner, a question about the build, or a working session — one route into Tokynd Security. Messages go directly to the Tokynd Security team, and a human replies.

Prefer another channel?

Founder on LinkedIn: linkedin.com/in/amjdseyal

We reply to every message personally — usually within one business day.