The flagship — full deployment

Your agent's next incident won't trip one alarm. It'll trip four — in four different tools — and nobody will connect them in time.

MCP Gateway catches the poisoned tool. Agent Guardrails catches the egress attempt. Probe Kit catches the agent that falls for a scam. Each one works, and each one only sees its own slice. The correlation — "this flagged tool call, from an agent that just tripped a rate limit, three minutes after a probe failure" — is exactly the judgment four separate dashboards can't make for you. Leviathan Platform is the one system that sees all of it at once, on your own infrastructure, and decides.

$35,000 pilot, then $3,500/mo — every product on this site, included

What it actually does

Five things happen, automatically, every time an agent tries to act.

Not a dashboard you have to learn. Not a pile of settings. Deploy it once, on your own infrastructure, and this is what's running underneath every agent from that point on.

It watches every action before it happens

Every tool call, every email sent, every shell command, every export — checked against policy in real time. Allow, confirm, or deny. Nothing runs by default, and nothing gets to explain itself after the fact.

It catches manipulation as it happens

Every tool description, every retrieved document, every instruction riding in on a tool result — scanned before your agent ever acts on it. The attack that would have worked gets caught at the door, not discovered in a postmortem.

It sets traps real attackers fall into

Fake credentials, fake keys, fake files, planted exactly where an attacker who's already inside would actually go looking. The moment one gets used — not just found, used — you know, in real time, with who and where.

It keeps proof nobody can quietly edit

Every meaningful action becomes a hash-chained, tamper-evident record. Something you can hand an auditor or an incident responder and trust — not a line in a log aggregator that anyone with the right access could have changed.

It attacks itself, continuously, so you don't find out the hard way

Not a one-time pentest that goes stale the week after you get the report. A standing harness that runs real social-engineering and injection attempts against your own deployed agents on an ongoing basis, automatically — so a gap that gets closed today can't quietly reopen six months from now without anyone noticing.

Pricing

One paid pilot month, then a flat rate. That's the whole ladder.

No per-seat fees, no per-node fees, no fake tier ladder designed to nudge you toward "Enterprise." A hands-on pilot deployed on your own infrastructure, then a flat monthly rate if you keep it. This isn't the cheaper option next to the point products — two of the five things it does aren't sold any other way, at any price.

Standard
$3,500/mo

Ongoing access after the pilot. Cancel anytime — no long-term commitment required.

Convert within 30 days of finishing the pilot and your first standard month is free.
Just want one piece? MCP Gateway, Decoy Kit, Agent Guardrails, Probe Kit, Bait-Mask, Amber-Freeze, and All-Stop each stand alone with their own license — see the full roster.
Card checkout: built for most products, temporarily paused during payment-processor identity verification. Reach out and we'll get a license or trial issued directly in the meantime.

Can I see it working before committing to a pilot?

Yes. The interactive demo runs real detection logic in your browser — not a video, not a mockup. The free SSH key trap is a real, working honeytoken you can deploy today, no signup, no cost.

Do we need Docker or Linux experience on our team?

The deployment is a docker-compose stack, and the pilot is hands-on — deployed together with you, not a file dropped in your lap and left. Some familiarity helps, but you're not doing this alone.

What does the pilot month actually involve?

Full platform access, deployed and evaluated against your own infrastructure, for one month. There's no rigid onboarding script — the specific plan gets worked out directly with you, based on your setup and what you're most worried about.

What if it doesn't work out?

If the platform genuinely doesn't do what this page says it does, tell us and the pilot gets refunded — that's the real refund policy, not a marketing line.

Northstar is one person — isn't that a risk?

Yes, and it's stated plainly, not hidden. What it means day to day: no support queue, direct access to the person who wrote the detection logic. What it means for risk: everything ships self-hosted — your deployment keeps running on your own infrastructure regardless of what happens on ours — and every release is GPG-signed, so what you're running is verifiable independent of anything else.