rogue agents and prompt injection are currently considered the biggest unresolved threat in security.
picture this: you ask claude code to review a PR, the agent reads a compromised package and gets tricked to exfiltrate your environment keys.
we are building cyber defense to solve this exact kind of problems. Clarion can ingest any kind of telemetry, integrate with platforms, triage and resolve issues at machine speed.
in this example Clarion is set up to ingest agent telemetry. the developer was using Claude Code and a prompt injection made the agent post his AWS keys to a remote attacker server. the attacker then logged into his AWS account using that same key.
Clarion is able to correlate actions across different environments and take action. here it detected the exfiltration via Claude telemetry, confirmed the abuse by correlating CloudTrail with auth from a differnet IP, contained the host using CrowdStrike Falcon, blocked the attacker address and escalated the issue.
all this in ~6 minutes. a human operator alone would have not found out in weeks.
We spent years finding vulnerabilities before attackers did. That was the easy part.
Teams already know what's broken. Nobody has the bandwidth to close it.
Today we raised $16.5M to make Cantina the security workforce for your security workforce.
What's the most expensive place to find a bug in financial infrastructure?
The bridge. @MezoNetwork just opened a $500,000 bug bounty on Cantina, and the cross-chain bridge is one of four special focus areas.
Full program details: