9 seconds
A Cursor agent deleted a company’s production database and the backups stored with it, on a token made for managing domains.
The behavioral security platform for AI agents. Quint watches agents at the OS level, scores their actions in real time with no LLM in the path, and enforces the verdict at the edge, on the device itself.
Fleet-wide visibility into risk scores, behavioral baselines, and anomaly detection. One pane of glass.
Every agent narrates what it is about to do. The intent model compiles that narration into a grant on the device, watches what the process actually does at the operating system, and holds one to the other. Anything outside the grant is a divergence, scored as it happens.
How the grant gets compiledEvery statement the agent makes about what it is about to do is compiled into a grant: which capabilities it licensed, and how tightly.
The files, processes and connections the agent actually touched, read from the operating system.
Observed activity is held to the grant. Anything landing outside it is the signal, scored per action and ranked for review.
Agent tools see what the agent reports. Endpoint tools see what the machine did. Quint holds one to the other.
what is routed through it
what its own hooks and telemetry report
what the operating system did, with no idea what the agent meant
the files, processes and connections it touched, held to what the agent declared
On the Macs your agents work on, inside the agents you build, or against SaaS agents with nothing installed. Start with one and add the others as your agents spread.
A signed, notarized macOS package your MDM pushes. It records what each agent process on the Mac did, next to what the agent declared.
A hook inside the agent reports what it is about to do, before it does it. Claude Code and Cursor today.
Copilot Studio agents and the Power Platform environments around them, read through your tenant’s admin plane. No software on any machine. In development.
Quint records what an agent actually did at the kernel, next to what it said it would do, and shows you where those two diverge. Same install on every host, same evidence trail.
Every other tool asks the agent what it did. We watch the kernel and compare.
What Quint does
AI agent runtime security is the control layer that watches what an AI agent actually does while it runs: the tool calls it declares, the processes and files it touches, the connections it opens. Here is the definition, the three layers, why it is a new category, how it stacks with AI firewalls, gateways, EDR and red-teaming, and the five questions to ask any vendor.
Apr 30, 2026 · 10 min readBehavioral security for AI agents scores what an agent actually does at the OS level, as a sequence, against what it declared it was doing. Four sourced incidents where every single step was permitted and the sequence was still a breach, how the two-layer approach catches that, and where it sits next to prompt filters, gateways, and EDR.
Apr 30, 2026 · 10 min readAn MCP server runs with your shell, your keys, and your files, and its tool descriptions are read by the model, not by you. Ten checks to run before you connect one, each with the command that does the work.