Skip to content
covin.devRequest a demo

Collusion detection and deception for autonomous agents

Catch what guardrails miss.

Covin reconstructs what agents do across tools, identities and shared resources, then turns policy-crossing activity into evidence your team can investigate.

Right now Covin is looking for payroll opened by an agent that never needed it; data heading for an address nobody recognises; two agents hiding behind one login; a handoff between teams that never should have happened; a tagged file turning up outside.

  1. 01

    Controls draw the line

    Permissions, sandboxes and guardrails decide what your agents may do.

  2. 02

    An agent finds a way around it

    A shared login, a staging folder, a tool nobody is watching.

  3. 03

    We follow the trail

    Reconstruct the path, spring the bait, and keep the evidence.

We catch rogue agent collusion.

Agents working together is the point. Agents working together against you is the threat.

Covin tells the two apart across the whole fleet, and keeps the evidence. Intent is your investigator's call.

CONTROLLED

The 40-second version

Watch Covin catch a colluding agent.

Your agents can reach everything. What if they start colluding?

Meet Covin. Collusion detection for AI agents.

See every agent. Follow every handoff. Catch the collusion.

Trace the whole ring: the rogue agent is frozen, the agents its data reached are frozen and replaced, the rest keep running.

Stop the rogue agent. Catch rogue agent collusion.

Same pattern. Three different answers.

Your companyFinance teamData teamSales teamreport-writer — allowed: the reports folderReport writers3://reports/q3-summary.csvQuarterly reportreport-reader — allowed: the reports folderReport senders3://finance/payroll-q3.parquetPayroll filefin-recon-01 — allowed: the finance folderAccounts checkeretl-pipeline — allowed: the warehouseData loaderanalytics-01 — allowed: the analytics cacheAnalytics agentindexer-01 — allowed: reports and searchSearch indexers3://analytics-cache/*Cached data (12 files)analytics-02 — allowed: the analytics cache · shares a login with Analytics agentAnalytics agent 2s3://staging/tmp/a91fDrop-off folderrevops-lead-score-01 — allowed: the sales exports folderLead scorerrevops-quote-01 — allowed: the price listQuote writerexport-agent-7 — allowed: the sales exports folder · shared loginExport agent203.0.113.54Unknown address
Nothing unusual

The reporting agent saves the quarterly report.

  • Both agents allowed to touch this file (supported)

Sample fleet and events, shown to illustrate the product. Not customer data.

How it works

No agent is asked to report on itself.

  1. 01Watch

    We read the records your cloud already keeps.

  2. 02Connect

    They join into a picture of who handed what to whom.

  3. 03Check

    Anything odd is tested against each agent's job, and against other systems that saw it.

  4. 04Explain

    You get the story in order, and what it proves.

Every finding keeps what was seen apart from what was guessed.

Works where your agents already run.

Security and deployment

What leaves your account, and what access we need.

YOUR AWS ACCOUNTCOVINCloudTrailAgent gatewayCollectornormalizefingerprintmetadataDetectionInvestigationsDashboardBait workeroptional · approved separately
The bait worker uses its own scoped role, and only placements you approve.
  • Your raw logs and file contents stay in your account.
  • We receive activity metadata and fingerprints you approve.
  • Agent prompts and messages are never needed.
  • Monitoring access is read-only.
  • Bait is optional, separately permissioned, and approved by you.
  • A customer-hosted option keeps everything in your account.
What data does Covin need?

Which identity touched which resource, when, and with what result. That comes from cloud audit logs and, if you run one, an agent gateway. File contents are not required.

Does Covin read prompts or resource contents?

No. Findings are built from observed activity. Where a content signal helps, the collector fingerprints it in your account and sends only the fingerprint.

Where does Covin run, and what access does it receive?

A read-only collector runs in your AWS account and normalizes activity before it leaves. Detection runs in Covin, or in your account under the customer-hosted option. Bait is permissioned separately.

See what your agents are doing between prompts.

Book a 30-minute demo. Pick a time, leave an email, and that's it.

Pick a 30-minute slot, any day, 6am to 9pm. Or email us.