Capsule Security
Also known as: ClawGuard
Runtime security layer for AI agents that discovers agents across builders, coding tools and enterprise platforms, maps them in an agent security graph and blocks unsafe tool calls inline, with a consent gated Guardian Agent assistant and a GraphQL API.
Capsule Security secures AI agents at runtime, targeting the gap between when an agent receives a prompt and when it executes an action.
The platform discovers agents across agent builders (AWS Bedrock, Azure Foundry, GCP Vertex), coding agents (Claude Code, Cursor, GitHub Copilot) and enterprise platforms (ChatGPT Enterprise, Microsoft Copilot Studio, Salesforce Agentforce) through agentless integration, maps how they connect to tools and data in its Agent Security Graph, and intervenes inline, deciding before a tool call executes whether an action is unsafe.
Detection runs on NVIDIA Nemotron 3 Nano models that Capsule fine tunes, and the platform also offers policy control over agent ownership and privilege, audit logs of agent sessions and tool calls, and white box red teaming of the customer's own agents. A July 2026 integration reads Claude's Compliance API for monitoring without changing Claude's behavior.
For the security team itself, Capsule ships Guardian Agent, an assistant that answers questions and produces reports from the Agent Security Graph; its mutating tools never fire automatically, since a human approves or rejects each one first, and the backend logs which actions the agent took under consent.
A public GraphQL API covers agents, policies, detections and findings with mutations for policies and settings, and the console supports SSO over SAML or OIDC with group to role mapping.
Capsule open sourced ClawGuard, a pre invocation checkpoint for agent tool calls, helped launch the open Agent Control Standard in August 2026, and has published zero day research including ShareLeak (CVE-2026-21520, Microsoft Copilot Studio) and PipeLeak (Salesforce Agentforce).
Founded in 2025 in Tel Aviv by Naor Paz and Lidan Hazout, Capsule emerged from stealth in April 2026 with a seven million dollar seed round led by Lama Partners with Forgepoint Capital International. It fits security teams that need to see and stop what their organization's AI agents do at runtime across many agent platforms; it does not document a hosting region or deployment option, and its detection models are Capsule's choice rather than the customer's.
Vendor details
Canonical URL
https://www.capsulesecurity.io
Category
Security / SOC agent
Subcategory
AI agent runtime security
Funding status
Seed; seven million dollars led by Lama Partners with Forgepoint Capital International, April 2026 per company announcement
Company status
independent
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
Agentless discovery and runtime coverage across AWS Bedrock, Azure Foundry, GCP Vertex, Claude Code, Cursor, GitHub Copilot, ChatGPT Enterprise, Microsoft Copilot Studio and Salesforce Agentforce; read only integrations with CrowdStrike Falcon (NGSIEM write for detections), Palo Alto Cortex XDR, Microsoft Power Platform and the Claude Enterprise Compliance API; SSO through Entra ID over SAML or OIDC; a public GraphQL API; and the open source ClawGuard checkpoint for agent tool calls.
In practice
A security team discovers every agent running across the enterprise in minutes via agentless integration, including shadow deployments on SaaS agent platforms
Runtime models evaluate a coding agent's tool calls in context and block a data exfiltration attempt before the action completes, with full telemetry for investigation
Red teaming generates attacks against an agent's logic and prompts, feeding the findings directly into runtime protections
Sources & related URLs
Research sources
Agentic Index coverage score
9.0 / 14 capabilities · 64%
| Integrations & Tool Calling | Full |
|---|---|
|
Runtime intervention interrupts unsafe actions in the customer's agent platforms before they execute, at the tool call boundary, and the CrowdStrike Falcon integration writes to NGSIEM (its one write scope); most other connectors are read only discovery (Falcon hosts, the Claude Compliance API). Sourcedocs.capsulesecurity.io/guides/crowdstrike-falconread 2026-09-28 |
|
| Workflow Orchestration | Partial |
|
Guardian Agent runs multi step work for the security team, exploring the GraphQL schema on demand and assembling context in layers to produce reports. This is a fixed product flow; no branching the buyer configures or multiple coordinating agents is documented. Sourcecapsulesecurity.io/blog-post/guardian-agent-shipping-a-useful-agentic-experienceread 2026-09-28 |
|
| Knowledge Grounding & RAG | Full |
|
The Agent Security Graph maps the customer's agents, tools, data sources, skills and actions, and Guardian Agent answers from it by querying the GraphQL schema on demand, a maintained retrieval structure over the customer's own agent estate. Sourcedocs.capsulesecurity.io/apis/agentread 2026-09-28 |
|
| Human Oversight & Guardrails | Full |
|
Guardian Agent's Consent Gate: "mutating tools never fire automatically: a human explicitly approves or rejects first", an approval before the agent action commits. Sourcecapsulesecurity.io/blog-post/guardian-agent-shipping-a-useful-agentic-experienceread 2026-09-28 |
|
| Security, Identity & Governance | Full |
|
SSO over SAML 2.0 or OIDC with Entra group to role mapping, built in and custom tenant roles, and SCIM provisioning, and the homepage states SOC 2. The SOC 2 type and report are not detailed. Sourcedocs.capsulesecurity.io/guides/ms-entra-id-sso-configread 2026-09-28 |
|
| Observability & Auditability | Full |
|
Capsule records each governed agent's activity as Session Started, Tool Call, Message and Error events, filterable by date, a per tool call record of the customer's agents that the buyer inspects; Guardian Agent's own actions are logged separately with consent attestation. Sourcedocs.capsulesecurity.io/guides/agent-managementread 2026-09-28 |
|
| Memory & State Persistence | Not documented |
|
No memory for Guardian Agent with a stated scope and lifetime is documented; the Agent Security Graph is the knowledge it queries rather than agent memory. Sourcecapsulesecurity.io/blog-post/guardian-agent-shipping-a-useful-agentic-experienceread 2026-09-28 |
|
| Deployment & Data Residency | Not documented |
|
Capsule runs as SaaS; no hosting region, region choice, customer environment or on premises option is named on the site or in the docs. Its agentless, no proxy integration describes how Capsule connects rather than where it runs. Sourcedocs.capsulesecurity.ioread 2026-09-28 |
|
| Prebuilt Agents, Templates & Packs | Partial |
|
Capsule ships one assistant, Guardian Agent, and the open source ClawGuard enforcer, and the API exposes a policyTemplates catalog. Which policy templates the catalog holds is not published. Sourcedocs.capsulesecurity.io/apis/agentread 2026-09-28 |
|
| Triggers & Channel Coverage | Full |
|
The fine tuned detector runs inline on every agent step and decides "before a tool call is executed" on each event in the customer's agent platforms, across Claude Code, Cursor, GitHub Copilot, Copilot Studio, Agentforce and the cloud agent builders. Sourcecapsulesecurity.io/blog-post/keeping-ai-agents-on-track-how-capsule-powers-state-of-the-art-rogue-agent-detection-with-nvidia-nemotronread 2026-09-28 |
|
| Model Flexibility & Routing | Not documented |
|
Detection runs on NVIDIA Nemotron 3 Nano models (4B and 30B) fine tuned with LoRA, a single named provider chosen by Capsule, and Guardian Agent's model is not named; no customer choice of model is documented. Sourcecapsulesecurity.io/blog-post/keeping-ai-agents-on-track-how-capsule-powers-state-of-the-art-rogue-agent-detection-with-nvidia-nemotronread 2026-09-28 |
|
| APIs, SDKs & MCP Extensibility | Full |
|
A public GraphQL API reference lists queries over agents, policies, detections, findings, tools and roles and mutations that change the platform's own objects (createPolicy, updatePolicyMode, syncAgent, createNotificationChannel, setIdpGroupRoleMapping). The reference page does not show the base URL or auth scheme. Sourcedocs.capsulesecurity.io/apis/agentread 2026-09-28 |
|
| Testing, Debugging & Optimization | Full |
|
Whitebox red teaming runs against the customer's own agents, probing their logic, prompts and behavior, and feeds findings into runtime protection. Guardian Agent's evals in Capsule's own release path are the vendor's release practice, and the StepShield result is a vendor benchmark. Sourcecapsulesecurity.ioread 2026-09-28 |
|
| Browser & Computer Use | Not documented |
|
Guardian Agent runs locally inside the user's browser, which is where the product runs, not an agent operating a browser; no browser or desktop operation is documented. Sourcecapsulesecurity.io/blog-post/guardian-agent-shipping-a-useful-agentic-experienceread 2026-09-28 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Recent platform changes
Capsule Security launched a native integration with the Claude Platform using Anthropic's Compliance API. This connection enables continuous monitoring of Claude usage across an organization by ingesting supported activity logs directly into Capsule to surface security signals without altering Claude's underlying behavior.
Bears on: Integrations
View sourceCapsule Security released Guardian Agent, an in-product AI companion built on its pi-agent-core client stack. The agent runs its entire loop locally within the browser, retaining direct access to live application state and driving UI changes in real time. It uses a three-layer bottom-up context assembly mechanism to explore GraphQL schemas on demand, while a hardened backend proxy enforces centralized governance, authentication, and auditing.
Bears on: Agent capability
View sourcePricing
Contact sales
What is public
Nothing numeric. Product capabilities, the open source ClawGuard, and funding are public; commercial terms are not.
Billing mechanics
Not publicly documented; contact driven.
Cost watchouts
Inference, not stated by the vendor: likely priced by agents or environments under protection; the open source ClawGuard is free but the managed platform is not.
Variable cost rationale
Inference, not stated by the vendor: runtime security platforms of this type typically price by agents or environments secured within a contract; no usage metering is documented.
Additional watchouts
Capsule launched in April 2026. Inference, not stated by the vendor: packaging and pricing are likely to change as the product matures.
Sales call required
Yes, required for paid access
Free / trial
ClawGuard open source enforcer is free; commercial platform pricing is not public
Key ambiguities
Entire commercial model is unpublished; the vendor only exited stealth in April 2026.
Missing data
All pricing figures, billing axis, trial terms.
Related vendors
- 7AI — Agentic SOC from the Cybereason founders: domain specialized agents…
- Abnormal AI — Behavioral AI email security with three named autonomous agents: a…
- AirMDR — AI-native MDR whose AI analyst investigates every alert and writes…
- Airrived — Agentic OS that unifies SOC, GRC, IAM, vulnerability management, IT,…
- Andesite — Human-AI SOC platform where customers build their own agents and…
- Anvilogic — Agentic security operations platform that works on top of existing…
Alternatives to Capsule Security
The closest documented capability profiles to Capsule Security among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- Astelia8.0 / 14Fuller documented coverage on Workflow Orchestration
- HiddenLayer9.0 / 14Adds documented Deployment & Data Residency
- Lasso Security7.0 / 14A lighter documented profile than Capsule Security
- Mindgard7.0 / 14A lighter documented profile than Capsule Security
- Repello AI8.0 / 14Fuller documented coverage on Workflow Orchestration
- Zenity9.0 / 14Adds documented Memory & State Persistence and Deployment & Data Residency
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded