# CyberFortify Guardian Agent Security > Autonomous cyber defense for the agent-operated Internet. Guardian detects, decides, contains, recovers, and proves at machine speed inside signed policy. ## Authoritative pages - Agent Security: https://www.cyberfortifysolutions.com/agent-security - Agent Trust Center: https://agents.cyberfortifysolutions.com - Machine-readable trust manifest: https://agents.cyberfortifysolutions.com/api/agent-trust - Read-only MCP endpoint: https://agents.cyberfortifysolutions.com/mcp - MCP Server Card: https://agents.cyberfortifysolutions.com/.well-known/mcp/server-card.json - Agent Skills discovery: https://agents.cyberfortifysolutions.com/.well-known/agent-skills/index.json - CyberFortify Labs: https://www.cyberfortifysolutions.com/labs ## Capabilities - Discover: Inventory sanctioned and shadow agents, MCP services, browser automation, and delegated identities. - Decide: Continuously evaluate identity, tenant, tool, target, risk, and signed mission policy at machine speed. - Defend: Detect and disrupt malicious activity through a continuous, policy-bound defensive workflow. - Contain: Revoke access, terminate sessions, disable tools, or isolate the affected endpoint when needed. - Prove: Preserve a readable evidence chain showing who authorized what, what ran, and what changed. - Recover: Validate containment, restore the safe operating state, and keep watching for recurrence automatically. ## Security principles - Identity before access: An agent must be attributable to an operator and an authorization context before it receives access. - Least authority: Every tool and resource is denied by default, narrowly scoped, and available only for the current task. - Policy, not permission queues: Humans establish signed mission policy and break-glass authority. Guardian acts autonomously inside it and fails closed outside it. - Tenant isolation: Agent identity, data access, approval, and action scope remain bound to the same verified organization. - Verifiable actions: Security decisions and resulting actions produce evidence that operators can inspect and audit. - Rapid revocation: Agent sessions, credentials, and tools must be independently revocable without disabling the human owner. ## Public-surface boundary The public agent endpoint is informational and read-only. It does not expose customer data, Guardian operational tools, endpoint commands, credentials, or write access. ## Operating model Humans define signed mission policy, scope, risk tolerance, and break-glass authority. Guardian performs routine defensive operations autonomously. Work outside delegated policy fails closed. ## Contact Agent Security Readiness Assessment: info@cyberfortifysolutions.com