Free trial
A free workspace can be created without a credit card, and a live attack run is blocked in the dashboard within seconds.
Learn moreSecurity gateway that gives AI agents short-lived identity and policy

AxioRank is a security gateway for AI agents. It issues short-lived identities, enforces default-deny policy, scores risk with 131 detectors and writes redacted audit logs in under 100 ms. It also verifies inbound agents visiting a website.
AxioRank is a security gateway that sits between AI agents and the systems they touch, including MCP servers, APIs and databases. Each tool call is routed through the gateway before it executes. The gateway verifies the agent's identity, scans the payload, evaluates policy, checks an allowlist and writes a redacted audit record, returning allow, deny or hold in under 100 ms. Identity is the starting point. An agent exchanges a static key or a federated identity for a short-lived signed token, 15 minutes by default, which verifies locally without a database round trip and cannot be replayed. Content inspection then runs 131 detectors across seven categories: secrets, malware, destructive operations, injection, financial data, PII and egress. Policies resolve under a deny-overrides model, and secrets are replaced in stored logs by an irreversible fingerprint, so the audit trail can show a key was present without keeping it. The product is aimed at engineering and security teams that give models real credentials and tools. Integration is through drop-in adapters for frameworks such as OpenAI Agents, Anthropic, LangChain, CrewAI, AutoGen, the Vercel AI SDK, LlamaIndex and Pydantic AI, plus a TypeScript SDK with calls such as toolCall() and enforce(). A browser-based live inspector lets visitors edit a tool call and see the verdict before signing up. Response rules can quarantine an agent, revoke keys or raise alerts, and can run in monitor mode first. Beyond outbound governance, AxioRank works in the other direction. Middleware verifies agents that visit a website, using Web Bot Auth signatures, with reverse-DNS and user-agent fallbacks, and returns allow, challenge or block. It tracks 65 agent protocols, 47 of them live in the gateway. Compared with general API gateways or prompt-level guardrails, it focuses on tool-call enforcement and verifiable receipts, including a Merkle transparency log. Teams that only need basic LLM output filtering may find it broader than necessary.
A free workspace can be created without a credit card, and a live attack run is blocked in the dashboard within seconds.
Learn moreThe homepage offers a free workspace with no credit card required and mentions Team and above plans, with monitor mode available on every plan. Specific prices are not stated on the homepage.
Learn moreThe homepage does not describe support channels. It links to a claims register in the docs and a machine-readable protocol coverage file.
Learn moreAdapters for OpenAI Agents, Anthropic, Google, LangChain, LangGraph, CrewAI, AutoGen, MCP, Vercel AI SDK, LlamaIndex and Pydantic AI. Alerts go to Slack, Teams and PagerDuty; Shopify, WordPress and HubSpot are also listed.
Learn moreShort-lived agent identity, a five-step gateway pipeline, deny-overrides policy engine, 131 detectors in seven categories, redacted audit log, automated response such as quarantine and key revocation, threat intelligence, Merkle transparency log and inbound agent verification.
Learn more




