EchoLeak
CRITZero-click email triggered Copilot to embed an exfiltration URL in its response. ~$200M impact across 160+ orgs.
AI Defendo is Scan0's enterprise AI security product — powered by Agentic Awareness. Tracks every agent across every session, renders one verdict per turn across six awareness dimensions.
Agents fail in ways prompts don't predict.
Indirect injection. Goal drift. Memory poisoning. Compacted context. Cross-agent escalation.
Every one looks like authorized behavior until you watch the full agent across the full session.
Named vendors with disclosed CVEs and real-world impact. In every case the per-message checks passed — the failure was in a dimension no per-message tool sees.
Zero-click email triggered Copilot to embed an exfiltration URL in its response. ~$200M impact across 160+ orgs.
User said "code freeze." Agent dropped tables anyway. 1,206 executives + 1,196 companies deleted. 4,000 fake users fabricated.
Cross-session attack. Memory poisoned in one chat — every chat after silently exfiltrated user data through legitimate APIs.
Web-to-Lead form hijacked Agentforce into exfiltrating CRM records. An expired domain still in the CSP allowed the egress.
Public-channel injection made Slack AI surface private-channel content to a low-trust user. Slack's response: "intended behavior."
Cross-agent escalation. Low-privilege agent tricked a higher-privilege one into exporting case files externally. ServiceNow: "works as intended."
None of them watch the full agent across the full session.
Every agent action raises six questions. Miss any one and you can't say what really happened.
Who acted?
What were they authorized to do?
What did they actually do?
What had they learned before this turn?
What shaped the decision?
Was the environment trusted?
AI Defendo answers all six on every turn.
Threats hit the agent lifecycle — input, reasoning, memory, tools, output. They reshape the data — exposure, exfiltration, secret leakage, compliance. AI Defendo maps both — six-dimension Behavioral Correctness, running on Scan0's Agentic Awareness layer.
inferred task: investigate data anomaly · active directive: code freeze in effect
Every verdict AI Defendo renders — every dimension it evaluates, every incident it catches — runs on Scan0's Agentic Awareness platform. Six layers of continuous understanding, from kernel-level discovery through cryptographically signed verdicts to inline enforcement.
Discovery · Runtime Sensor · Collector · Awareness Layer · Enforcement · Experiences. AI Defendo consumes the Awareness Layer's signed verdicts, enforcing them through the AI Interceptor, Identity Gateway, and Data Flow Control paths.
AI Defendo ships three products that together secure every layer of enterprise AI — discovery and governance, infrastructure, and runtime behavior. Each answers a specific question every enterprise now asks about its AI.
What AI do we have — and how exposed is it?
Continuous discovery of every AI asset across cloud, endpoint, browser, and code. Configuration posture with mitigation workflow. Shadow AI sanctioning. Identity governance for both human and non-human AI actors.
Is our AI infrastructure secure?
Kernel-level runtime protection for the workloads that run AI — inference servers, RAG platforms, memory stores, agent frameworks, and MCP servers. Catches remote code execution, container escapes, and framework exploits at the system layer.
Are our AI agents behaving as intended?
Continuous evaluation of agent behavior across sessions. Detects behavioral incidents that only exist because AI agents combine context, identity, memory, and delegation. Inline enforcement through the AI Interceptor — block, coach, or alert in real time. Zero-trust Identity Gateway provides just-in-time scoped grants for every agent action.
Join the Beta to begin mapping and securing multi-turn workflows inside your production environment.