The roster
You talk to one. Dozens go to work.
Each agent is a specialist with a narrow job and real authority inside it. The Infosec Lead decides who is needed, dispatches them in parallel, and comes back to you with one answer.
Infosec Lead
Your single point of contact
Turns plain-language objectives into completed work — planning the job, directing the specialists, reporting back with evidence and recommendations.
Read the brief →
Plutus
Payment & wire-fraud defense
Independently verifies every wire against mandates pressure can't override — dual approval, callbacks, verified accounts — and holds the fraudulent transfer before money moves.
Read the brief →
Psycher
Intent & social-engineering defense
Reads behavioral baselines to catch phishing, pretexting, and BEC before they succeed — the earliest warning most breaches allow.
Read the brief →
Argus
Dark-web watch
Monitors criminal forums and leak sites for your credentials, data, and identity — so you hear about a breach before the attacker uses it.
Read the brief →
Sleight
Deception & counter-intrusion
Seeds convincing decoys through your environment; one touch is a high-confidence signal, and the intruder's toolset becomes your intelligence.
Read the brief →
Cerberus
Data loss & insider risk
Inspects every path out of your environment, recognizes regulated data and secrets, and stops the leak — accidental or intentional — before it leaves.
Read the brief →
Themis
Financial integrity & AML
Continuous anti-money-laundering monitoring, sanctions screening, and audit-ready filings — on a tamper-evident ledger an examiner can verify without touching your system.
Read the brief →
Judge
Continuous compliance
Measures your environment against SOC 2, HIPAA, PCI, and NIST control by control, and produces cited, reproducible, attestation-ready evidence on demand.
Read the brief →
Shield + SHADE
Detection & self-healing
Writes and tunes detections mapped to real attacker technique, then remediates the routine weaknesses automatically, so the window of exposure stays short.
Read the brief →
Growler
Forensics & evidence
Reconstructs exactly what happened, when, and how — assembling court- and board-ready evidence with chain of custody intact.
Read the brief →
Horsemen
Fleet-wide endpoint guard
Keeps every managed endpoint hardened and current, closing the routine weaknesses attackers rely on across the estate.
Read the brief →
Dewey
The recovery commander
Orchestrates response and restoration after an event — and drafts the regulator and law-enforcement filings, held for human approval.
Read the brief →
EVOLVE
The orchestration engine
Watches every agent's coverage, designs new capabilities where gaps appear, and makes the platform measurably stronger each quarter.
Read the brief →
Forge
The toolmaker
Builds, benchmarks, and cryptographically signs new tools when your environment needs a capability that doesn't exist yet.
Read the brief →
Librarian
The keeper of your environment
Maintains a living, sourced map of every host, service, account, and attack path, so the whole fleet reasons from current facts.
Read the brief →
Relay
The connector fabric
Integrates Aktoh with the systems you already run — monitoring, ticketing, email, banking, accounting — with nothing torn out.
Read the brief →
Pulse
The intelligence gateway
Scores global threat intelligence against your specific assets, so you hear about the threats that actually reach your environment — early.
Read the brief →
Verification & Response
Offensive verification
Turns 'detected' into 'confirmed' — safe, scoped probes that return a confidence-scored verdict with evidence in minutes, not days.
Read the brief →
Scout
Attack-surface discovery
Maps your external attack surface and finds the assets you forgot you had — before someone else finds them first.
Read the brief →
Hunter
Vulnerability discovery
Finds weaknesses across code, applications, and infrastructure, ranked by real exploitability and business cost — not raw scores.
Read the brief →
Lancer
Structured red team
Methodology-driven penetration testing with reproducible exploit chains — every finding paired with its fix and the detection that should catch it next time.
Read the brief →
00x
The offensive specialist
Handles the novel work playbooks don't cover — PoC development, sandboxed exploit engineering, insider simulation — under per-action authorization.
Read the brief →
Spark
Privacy & AI governance
Runs the governance program end to end — policy drafts, privacy impact assessments, DSARs, AI-regulation classification, every deadline tracked.
Read the brief →
InfraAsAI
Self-reconciling infrastructure
Detects drift from your declared infrastructure and plans safe, policy-gated, auto-rollback changes through your own pipelines.
Read the brief →
Every plan — including the free Adventurer tier — gets the whole fleet. Tiers change the pooled credits and the token rate, never which agents you're allowed to talk to.
Start free. Add credits only when the work justifies it.
Run the whole fleet across unlimited nodes at zero platform fee — you pay only for tokens. Move to a pooled plan when the usage justifies the lower rate.