Whether through a bug, a prompt injection, or a malicious tool, an AI agent can end up sending your data somewhere it should not. RIL Warden is built to prevent and detect exactly that.
How Warden prevents exfiltration
Approved destinations only
Default-deny egress means data can only go to hosts you allow. An attacker's endpoint is blocked by default.
Blocked exfil + C2 channels
Known paste sites, webhooks, and command-and-control patterns are refused outright.
Decoy credentials (honeytokens)
Plant fake keys. If one is ever used or leaked, you know immediately that an agent was compromised.
Auto-jail on suspicion
Oversized responses, repeated denials, or swarm coordination can automatically quarantine the agent before more leaves.
Proof, not guesswork
Every request and every block is written to a hash-chained, Ed25519-signed log that is checkpointed on-chain, so you can prove what was and was not sent. That record is the difference between 'we think we are fine' and 'here is exactly what happened.' More in the agent audit log page.
Frequently asked questions
- How do you stop an AI agent from exfiltrating data?
- Restrict where it can send data (default-deny egress to approved hosts only), block known exfiltration and C2 channels, keep secrets out of the agent, and auto-quarantine on suspicious egress. RIL Warden does all of these and logs every attempt.
- What are honeytokens / decoy credentials?
- They are fake secrets planted so that if one is ever used, you know an agent or its output was compromised. Warden supports decoy credentials as a tripwire.
- Can I prove nothing was leaked?
- Warden keeps a tamper-proof, signed, on-chain-checkpointed log of every request and block, so you can demonstrate exactly what an agent did and did not send.
- Does this work for third-party or model-provider agents?
- Any agent whose traffic you can route through Warden is covered, including agents built on common frameworks and MCP clients.
Related
Put a wall around your agents in 5 minutes
Free tier: 3 agents, 25,000 gateway requests a month, full signed history.
Start freeRead the guide