# Wingback Security > Wingback Security is an AI security platform that provides Agent Detection & Response (ADR) across every layer of the enterprise stack: employee endpoints, cloud and SaaS infrastructure, and the software companies build themselves. It discovers, monitors, and defends AI agents, models, and MCP toolchains inline, while an attack is still running. Tagline: "Security that runs with your agents." ## What Wingback does - Discovers every AI agent, model, MCP server, and inference path across endpoints, cloud and SaaS, and first-party software. - Defends inline at runtime (Agent Detection & Response): blocks, sanitises, throttles, or terminates malicious agent actions, tool calls, and data exfiltration. - Red-teams agents, models, and RAG pipelines with an adaptive LLM-driven attacker, mapped to the OWASP LLM, Agentic, and MCP Top 10 and to MITRE ATLAS. - Governs and proves compliance against ISO 42001, NIST AI RMF, the EU AI Act, and more, with audit-ready evidence. ## Coverage - Endpoints: shadow-AI and agentic-tool posture on laptops (ChatGPT, Claude Code, Cursor, Copilot, local MCP servers) via a browser extension and native macOS and Windows agents. - Infrastructure: agentless discovery of AWS Bedrock, Azure OpenAI, Microsoft Copilot Studio, Salesforce Agentforce, RAG indexes, and vector stores. - Software: an AI gateway across model providers with inline guardrails, an MCP gateway, agent-session tracing, and per-agent policy. ## Key pages - [Wingback Security](https://www.wingback.ai/): Agent Detection & Response across endpoints, cloud and SaaS, and first-party software. - [Request a demo](https://www.wingback.ai/request-demo): Book a live walkthrough of the platform. ## Platform - [AI Surface Intelligence](https://www.wingback.ai/platform/discovery): Wingback continuously maps the agents, models, MCP servers, and inference paths in your AI stack, scores each for risk, and routes findings to owners. - [AI Runtime Defense](https://www.wingback.ai/platform/realtime): Wingback sits inline at the inference path, correlating multi-signal detection into one response, sealing data on the wire, and replaying every session. - [AI Red Teaming](https://www.wingback.ai/platform/red-team): Wingback runs continuous, adaptive red teams on your models, agents, and RAG pipelines, maps each finding to OWASP, NIST, and MITRE, and hardens the runtime. - [AI Risk & Compliance](https://www.wingback.ai/platform/compliance): Wingback maps runtime events, posture findings, and red-team results to ISO 42001, NIST AI RMF, the EU AI Act, and more, then exports the audit binder. ## Solutions - [Solutions](https://www.wingback.ai/solutions/): Security by use case. - [Security for autonomous AI agents](https://www.wingback.ai/solutions/ai-agent-security): Wingback secures AI agents at runtime: it discovers every agent, controls the tools and identities they use, and blocks malicious actions inline. Agent Detection & Response for LangChain, CrewAI, AutoGen, OpenAI Agents, and MCP. - [Security for AI coding agents](https://www.wingback.ai/solutions/coding-agent-security): Wingback secures AI coding agents on developer machines: Cursor, Claude Code, GitHub Copilot, Windsurf, and local MCP servers. Detect shadow AI, control tool and file access, and stop risky actions inline. - [Security for the AI you ship](https://www.wingback.ai/solutions/ai-application-security): Wingback secures the LLM features and agents your engineers build into your own products: an AI gateway across 12+ providers, inline guardrails, an MCP gateway, and adaptive red teaming, with no agent code changes. - [Security for AI agents inside your SaaS](https://www.wingback.ai/solutions/ai-saas-agent-security): Wingback discovers and governs the AI agents inside your SaaS: Microsoft Copilot Studio, Salesforce Agentforce, and Bedrock/Azure OpenAI deployments. Agentless discovery, exposure analysis, and risk scoring. - [One control plane for enterprise AI](https://www.wingback.ai/solutions/enterprise-ai-security): Wingback is an enterprise AI security platform: one place to discover, defend, red-team, and govern every AI agent, model, and MCP toolchain across endpoints, cloud/SaaS, and first-party software. ## Glossary - [Agent Detection & Response (ADR)](https://www.wingback.ai/glossary/agent-detection-and-response): The practice of detecting and responding to threats from AI agents at runtime. - [MCP security](https://www.wingback.ai/glossary/mcp-security): Securing the Model Context Protocol: the servers, tools, and transports that agents use to reach external systems. - [Shadow AI](https://www.wingback.ai/glossary/shadow-ai): AI tools and agents used inside an organization without security's knowledge or approval: personal ChatGPT accounts, unsanctioned coding assistants, local models, and self-serve SaaS agents. - [Prompt injection](https://www.wingback.ai/glossary/prompt-injection): An attack that hides instructions in content an AI model or agent will read (a document, a web page, a tool result) to hijack its behaviour. - [Jailbreak](https://www.wingback.ai/glossary/jailbreak): A prompt technique that bypasses a model's safety or policy guardrails to make it produce restricted output or take restricted actions. - [Agentic threats](https://www.wingback.ai/glossary/agentic-threats): Threats specific to autonomous agents rather than single prompts: goal hijacking, tool and function misuse, privilege escalation across agent-to-agent handoffs, cascading multi-agent failures, memory or context poisoning, and rogue or runaway agents. - [AI Bill of Materials (AIBOM)](https://www.wingback.ai/glossary/ai-bill-of-materials): A structured inventory of the AI components in a system: models, agents, datasets, and their provenance, versions, and risks. - [AI red teaming](https://www.wingback.ai/glossary/ai-red-teaming): Adversarial testing of AI systems (models, agents, and RAG pipelines) to find vulnerabilities before attackers do. - [Runtime AI defense](https://www.wingback.ai/glossary/runtime-ai-defense): Protecting AI systems while they run, inline, rather than only scanning code or configuration beforehand. - [Inference security](https://www.wingback.ai/glossary/inference-security): Securing the path a request takes through a model provider or inference endpoint: applying policy to every prompt and completion, protecting against injection and data leakage, and controlling which models and providers an agent may use and under what conditions. - [AI gateway](https://www.wingback.ai/glossary/ai-gateway): A proxy that sits inline between applications and model providers, applying a single security and governance policy to every prompt and completion: guardrails, PII and secret handling, provider allowlists, usage and cost controls, and audit logging. - [Tool poisoning](https://www.wingback.ai/glossary/tool-poisoning): An attack in which a tool or MCP server (its description, schema, or output) is crafted to manipulate an agent into taking harmful actions, such as leaking credentials or calling a dangerous tool. ## Blog - [Agentic Kill Switch: stop the next tool call before it lands](https://www.wingback.ai/blog/agentic-kill-switch-runtime-emergency-stop/): An Agentic Kill Switch is a runtime emergency stop for AI agents: external to the model, checked before tool execution, and fail-closed when the control plane is unavailable. Here is what security teams should demand, and how public ADR capabilities map to that stop. - [You cannot govern AI you have not inventoried](https://www.wingback.ai/blog/shadow-ai-inventory-before-governance/): CSA’s Invisible Enterprise research shows most AI tools and agents still run outside IT control. Here is why continuous AI asset inventory is the prerequisite for Agent Detection & Response, and for EU AI Act readiness. - [MCP tool poisoning needs runtime controls, not prompt filters](https://www.wingback.ai/blog/mcp-tool-poisoning-needs-runtime-defense/): OWASP’s MCP Top 10 and Invariant Labs’ tool-poisoning research show why approving an MCP server once is not enough. Here is what security teams should demand from Agent Detection & Response. - [Endpoints take the first hit: OWASP Agentic Top 10 for coding agents](https://www.wingback.ai/blog/coding-agents-inherit-your-credentials-owasp-agentic/): OWASP’s Agentic Top 10 and Microsoft’s 2026 guidance show why ASI02 tool misuse and ASI03 privilege abuse hit developer laptops hardest. Here is what fail-closed Agent Detection & Response looks like for Cursor, Claude Code, and Copilot. - [CISOs: You Don't Control the Frontier. You Do Control What It Deploys.](https://www.wingback.ai/blog/you-dont-control-the-frontier/): Three takes on pacing the frontier, from Amodei, Beri, and Arora, and why a security program shouldn't be built around any of them. The job is securing the adoption already happening inside your company. - [Why AI Security Requires a Multi-Layer Platform](https://www.wingback.ai/blog/ai-security-multi-layer-platform/): AI security is not a point problem. Learn why red teaming, runtime protection, shadow AI discovery, observability, and compliance must work together. - [Our Baseten connector: cover the models you host, not just the ones you rent](https://www.wingback.ai/blog/wingback-baseten-connector/): Wingback now discovers, guards, and red-teams the models you serve on Baseten (dedicated deployments, Model APIs, and Chains) with the same runtime coverage your frontier APIs get. - [Concurrency Is the Capability](https://www.wingback.ai/blog/concurrency-is-the-capability/): Unit 42's ten-hour intrusion, OpenAI's 1,200-agent swarm, and a git config bug. An investigation into what AI-assisted attacks actually changed, and what they did not. - [LiteLLM: a security scanner was the initial access vector for AI infrastructure](https://www.wingback.ai/blog/litellm-supply-chain-compromise/): A poisoned vulnerability scanner walked LiteLLM's PyPI tokens out of CI in March. The 153GB credential archive that surfaced this week shows what an LLM gateway concentrates, and where nobody was watching. - [Wingback joins Anthropic's Cyber Verification Program](https://www.wingback.ai/blog/anthropic-cyber-verification-program/): Verified access to Claude's high-risk cyber capabilities lets our adaptive red-team engine attack your agents the way a real adversary would, with the guardrails intact. - [Why we built Wingback](https://www.wingback.ai/blog/why-we-built-wingback/): AI agents now live in three places in your enterprise: on laptops, in your cloud, and inside your own software. Securing one layer isn't securing AI. ## Reference - [Platform one-pager](https://www.wingback.ai/one-pager): A one-page overview of the platform. - [Blog](https://www.wingback.ai/blog/): Research and analysis on securing enterprise AI. - [AI security glossary](https://www.wingback.ai/glossary): Definitions of the terms that come up when securing enterprise AI. - [How to evaluate an AI agent security platform](https://www.wingback.ai/compare/evaluating-ai-agent-security): A practical, vendor-neutral checklist for evaluating AI agent security and Agent Detection & Response platforms: coverage, enforcement, MCP support, red-team depth, framework mappings, and deployment. - [Platform capabilities](https://www.wingback.ai/capabilities): A factual reference for the Wingback Security platform: supported model providers, detection and red-team coverage, integrations, framework mappings, deployment models, and endpoint and MCP coverage. ## Company - [Partnerships and programs](https://www.wingback.ai/partnerships): Anthropic Cyber Verification Program, OpenAI Partner Program, NVIDIA Inception, CSA, OWASP. - [About Wingback](https://www.wingback.ai/about): Wingback is a forward-deployed AI security company defending agents on employee laptops, across cloud and SaaS, and inside the software you ship. - [Careers](https://www.wingback.ai/careers): Wingback is hiring founding engineers and a founding account executive to build the security control plane for AI alongside enterprise customers. - [Partnerships and programs](https://www.wingback.ai/partnerships): Wingback is verified in Anthropic's Cyber Verification Program, part of the OpenAI Partner Program, and builds with NVIDIA Inception, the CSA, and OWASP. - [Product demo](https://www.wingback.ai/demo): A two-minute video tour of Wingback's security control plane for agents and MCP toolchains, from discovery to runtime enforcement to audit-ready evidence. ## Full text - [llms-full.txt](https://www.wingback.ai/llms-full.txt): every glossary definition and post summary in one file. ## Company - Founded by Abhinav Singh and Bharath Kallur. Forward-deployed engineering model: our engineers embed with your team. - Contact: https://www.wingback.ai/request-demo - Security disclosures: https://www.wingback.ai/.well-known/security.txt