Skip to content
● 46 capabilities verified · one continuous loop from endpoint to cloud to runtimeCapability registry · verified 24 Aug 2026
The Araghatta AI Control Loop

Discover it. Understand it. Contain it. Prove it.

Shadow AI is not a single feature problem — it is a loop. Araghatta runs the whole loop for you: find every AI signal on endpoints and in the cloud, place it in an evidence-backed context, respond by real risk, test it before it ships, watch what it does at runtime, and govern it for conformity. Six stages, one platform, evidence at every edge.

CONTINUOUS AI Control endpoint · cloud · runtime Discover2 capabilities Context4 capabilities Respond2 capabilities Test3 capabilities Runtime1 capability Govern3 capabilities
STAGE 01
Discover

Find every AI signal — on the endpoint and in the cloud.

A single read-only sensor per host, plus read-only cloud connectors. Eleven signal classes on the endpoint; the AI agent joined to workload identity in the cloud.

Endpoint AI discovery GA

Eleven signal classes on the host — AI CLIs and agents, provider keys, MCP servers and tool scope, IDE assistants, skills, SDKs, installed apps, browser extensions, egress to AI endpoints, vibe-coded repos and non-human identities.

observe-only · secrets masked on the endpoint

Cloud CSPM AWS GA

Sensor-led cloud posture: the AI agent on the workload joined to workload identity, metadata-service exposure, storage and reachable services — and the attack paths that result. Azure and Google Cloud on connect.

config + runtime evidence · no credential retrieval
STAGE 02
Context

Turn raw signals into who-can-reach-what.

A conditional graph where every edge records its evidence, freshness and confidence — then the identities, data and changes that graph implies.

AI capability & attack graph GA

Device → agent → MCP → credential → egress → cloud data, step by step. Conditional edges: if a precondition is absent, the path is downgraded or closed.

reachability, not an observed exploit

Agent & NHI governance GA

Every AI agent, MCP server and machine key as a governed principal — effective reach (tools, credentials, egress, reachable data), owner, business-criticality and lifecycle. Recertify or schedule decommission.

decommission is a decision — the sensor doesn't revoke

AI data lineage & reach GA

For every cloud data store, which AI agents and workload identities can reach it and via how many attack paths, its worst severity and whether it's publicly exposed.

permission-permits-access · not observed retrieval

Change-risk simulator GA

Predict the security effect of a change — widen a workload's access, or expose a store publicly — on the live graph, before you make it. Before/after/delta blast radius.

a forecast · not a claim of exploitability
STAGE 03
Respond

Rank by real risk — and know exactly why.

A deterministic scoring engine you can tune and reproduce, sharpened by live threat intelligence matched to what you actually run.

Explainable, tunable risk scoring GA

A weighted-factor rubric behind every score — simulate a change to the weights against your open risks, then apply. One immutable rubric snapshot per revision.

no LLM in the score · fully reproducible

AI threat intelligence GA

Live NVD, KEV and OSV plus curated TTPs, correlated to MITRE ATLAS and ATT&CK and to the specific AI capabilities you run — a second, threat-aware severity axis.

advisory correlation · can't fabricate techniques
STAGE 04
Test

Prove the AI is safe before it ships.

A release gate over your AIBOM, adversarial packs against authorized targets, and AI-aware checks in the pipeline.

AI supply-chain trust GA

Every AI library, MCP server and skill on the fleet with a trust verdict — known-CVE, unpinned, untrusted source — and a fleet-wide approve/quarantine decision.

provenance + pinning + known-CVE · not a deep scan

Continuous AI red-team GA

A curated pack library aligned to OWASP LLM Top 10 and MITRE ATLAS — prompt injection, jailbreak, sensitive disclosure, excessive agency — run against an authorized target with pass/fail and regression.

no target = clearly-labelled sample · never fabricated

AI code & CI/CD gates GA

Per code location, the AI-specific issues a pre-merge gate catches — hardcoded AI secrets, vulnerable or unpinned AI deps, untrusted MCP and skills, AI-authored code pending review — with a pass/warn/block verdict.

wire into your pipeline via the API
STAGE 05
Runtime

See what the AI actually did.

Reconstruct an AI system's behaviour from the telemetry it emits — the AIDR view for investigation.

AI execution traces (AIDR) GA · observe

Reconstruct what an AI system did — user, prompt, retrieval, model, agent, tool, resource, outcome — from OpenTelemetry-GenAI spans, rendered as a step-by-step timeline for investigation.

observe mode · live response actions on the roadmap
STAGE 06
Govern

Classify it, prove it, keep it compliant.

Bridge what you discover to what you must govern — conformity classification, signed evidence and enforceable policy.

AI system register & EU AI Act GA

Every AI system in use, classified for conformity — EU AI Act risk tier, provider or deployer role, accountable owner and lifecycle. Audit-stamped.

an accountable human classification · not an automated legal determination

Compliance & signed evidence GA

Map controls to NIST AI RMF, ISO 42001, OWASP LLM Top 10 and the EU AI Act — with signed, verifiable evidence packs and a defensible denominator.

gaps shown as POA&M · not hidden

Approved-AI policy GA

Decide which AI tools and models are allowed in your organisation — allow, deny, or allow-with-acknowledgement — with versioned governance and rollback.

policy decisions recorded · sensor stays observe-only

The whole loop, on real evidence.

See Araghatta run every stage against your own estate — from the first endpoint signal to a signed EU-AI-Act evidence pack.