Northstar Production Studio · Leviathan Platform
Leviathan governs every consequential action your agents take, plants deception attackers can't tell from the real thing, and records what actually happened into an evidence log nobody — including us — can quietly edit. Self-hosted. No telemetry leaves your network.
The core of the platform
Each one ships as part of Leviathan Platform, and several are also available standalone — see the full roster below.
Every consequential action — read CRM, send email, execute shell, export data — passes through an explicit policy decision before it happens. Iron-Thread, the egress firewall underneath it, blocks unauthorized outbound connections at the interpreter level before they ever leave your infrastructure.
Trust the tool, pin the schema. Every MCP tool description is scanned for injection before admission, then hashed and pinned — a re-admission from the same server with a changed description gets flagged, not silently trusted. $4,000/yr standalone.
Your knowledge base is part of your attack surface. Every retrieved chunk and every candidate memory write is scanned before it's trusted — at BOTH checkpoints that matter, admission and recall, closing the exact gap real 2026 memory-poisoning research (GhostWriter, MemMorph) targets.
20 honeytoken traps for the places attackers actually go after a foothold: cloud metadata endpoints, a stolen kubeconfig, a leaked SSH key, a poisoned Postman collection, a scraped RAG corpus, a decoy MCP server, and more — all real, all in production, all self-hosted.
Prove exactly what happened. Every meaningful action becomes a hash-chained, append-only evidence event — tamper-evident by construction, exportable for a compliance review or handed straight to an incident responder.
A real adversarial-mutation harness runs social-engineering and injection scenarios against your own agents on every change, and a regression gate fails the build if a previously-closed gap reopens — not a one-time pentest, a standing test suite.
Why now
70 formal NIS2/ANSSI enforcement actions since April 2026, a 540% surge in prompt-injection reports, and insurers now excluding AI-agent losses from standard policies by default.
What you're actually buying
The products in the roster below each do one real piece of this. The platform is the whole thing, running together — including two systems that never got sold on their own at all.
Leviathan Platform v0.2.0, tagged and green
Every claim on this page is backed by a real, passing test suite — not a marketing number.
Python tests passing in Leviathan Control (20 opt-in/environment-conditional skips, by design).
Leviathan .NET tests passing.
No telemetry leaves your network, no vendor cloud sits between your data and you, and nothing is locked behind an API you can't touch — it's your deployment, fully yours to customize.
A real Python egress firewall built on sys.addaudithook — blocking unauthorized outbound connections before they leave.
OWASP Agentic Top 10 risks with a real, tested module against them — checked against the code, not asserted. See the mapping →
Leviathan Platform pricing
No per-seat fees, no per-node fees, no fake tier ladder designed to nudge you toward "Enterprise." A hands-on pilot deployed on your own infrastructure, then a flat monthly rate if you keep it.
Full platform access, no feature restrictions, deployed and evaluated against your own infrastructure.
Ongoing access after the pilot. Cancel anytime — no long-term commitment required.
Yes. The interactive demo runs real detection logic in your browser — not a video, not a mockup. The free SSH key trap is a real, working honeytoken you can deploy today, no signup, no cost.
The deployment is a docker-compose stack, and the pilot is hands-on — deployed together with you, not a file dropped in your lap and left. Some familiarity helps, but you're not doing this alone.
Full platform access, deployed and evaluated against your own infrastructure, for one month. There's no rigid onboarding script — the specific plan gets worked out directly with you, based on your setup and what you're most worried about.
If the platform genuinely doesn't do what this page says it does, tell us and the pilot gets refunded — that's the real refund policy, not a marketing line.
Yes, and it's stated plainly, not hidden. What it means day to day: no support queue, direct access to the person who wrote the detection logic. What it means for risk: everything ships self-hosted — your deployment keeps running on your own infrastructure regardless of what happens on ours — and every release is GPG-signed, so what you're running is verifiable independent of anything else.
Just want one piece?
The platform is one deployment of all five systems together. If you only need one piece of it, each is also available on its own — its own price, its own trial.
Every tool admission, every egress connection, every risky action gated by an explicit policy — allow, confirm, or deny. Nothing runs by default.
Prompt-injection and tool-poisoning scanning on every tool description, call, and result — plus the schema/description pinning that catches a tool silently changing after you approved it.
Fake credentials, fake API keys, a real SSH key with a beacon comment — planted so that using a decoy, not just finding one, is what trips the alert.
Every trip lands in a tamper-evident, hash-chained evidence log — something you can hand to an incident responder or an auditor, not a line in a log aggregator someone could have edited.
A red-team regression gate runs real adversarial scenarios against your own agents on every change, so a fix six months from now can't quietly reopen a gap you already closed.
Try the real thing, free
A real, valid key generated by actual ssh-keygen — its comment field carries a beacon URL instead of a name, so it passes any scanner that checks key structure. Plant it, leak it on purpose, and watch what happens the moment anyone actually tries to use it. MIT-licensed, part of Decoy Kit.
The full roster
Each product stands on its own — its own price, its own trial, its own test suite. They share the same lineage: the same self-hosted-only rule, the same honest-disclosure format, the same signing scheme.
Rune governs and detects. Kip is your canary — plant a hidden tripwire word in an agent's own instructions, and if it ever shows up in a response, something tried to override them. A real, built mechanism (plant_canary / check_output_for_canary), not just a mascot.
Talk to us
You'll hear back from the person who built it, not a queue.