Skip to main content
WardenOpen-source AI scannerExplore →

For the CIO

Policy Bootstrap.
When we’ve seen enough.

You do not author the policies. Your agents run in shadow mode until WhiteFin has seen the full shape of what they do — measured by coverage of their behaviour, not by a calendar. Then you review the proposed rules in plain English against real recorded traffic, and enforce. The rules that ship are the ones you approved — derived from what your agents actually did, not a vendor's template.

How It Actually Goes

We watch until your agents stop surprising us. Then one review. Then the switch.

Phase one
Observe

WhiteFin sits inline on every agent-to-tool call. Nothing is blocked. Every call is recorded, labeled, and grouped. Your agents continue to run exactly as they did before; the only difference is that for the first time, you have ground truth about what they actually do.

Until it stops surprising us
Saturate

Observation does not end on a date. It ends when an agent stops showing us anything new — enough evidence behind every distinct behaviour, then a sustained run across multiple sessions in which no new behaviour appears. A busy agent gets there in days; a periodic one takes longer. Either way the answer comes from what we have seen, not from a calendar.

One sitting
Review

A proposed policy set is generated from everything observed. We sit with your team and walk through every rule. You see — in plain English, against real recorded traffic — what each rule allows, what it would have blocked, and what it would have escalated. You approve, edit, or reject before anything ships.

Your call
Enforce

You flip the switch. Deny-by-default goes live. Approved tool calls pass. Unapproved calls stop, or route to a human approval queue, depending on how you set the rule. There are no surprises, because the rules are the ones you approved.

If it never settles
Contained

Some agents keep broadening for as long as you watch them. Rather than wait forever, WhiteFin caps observation at a ceiling you configure and enforces against what was learned — and it labels that agent CONTAINED, not understood. Nothing it has never done is allowed: deny-by-default covers the rest. You get told which of your agents we know and which we are merely holding, because those are different claims and only one of them should let you sleep.

Two Ways to Deploy

Pick the one that matches your data-residency posture.

01

Self-hosted

You run the gateway inside your own cloud.

Your VPC, your network rules, your platform team's monitoring stack. WhiteFin ships the binary and the policies; the path stays inside your perimeter.

02

Air-gapped

No outbound dependency on WhiteFin infrastructure.

For environments where the gateway must operate without ever talking to a vendor. Policy updates and audit exports are explicit, manual operations. Right for the most sensitive deployments.

Deny-by-default, on rules you approved, as soon as we know your agents.

Start the conversation →

We use cookies for analytics to understand how visitors use our site. No advertising cookies. Privacy Policy