The Immune Mesh

Seven immune products. One AIDR platform.

The Immune Mesh is ImmuneWorks’ AIDR platform — from the hardened kernel to the gateway and browser, it delivers AI Detection & Response at every layer where AI meets the business, evolving together as one.

ImmuneWorks · Immune Mesh · AIDR
GatewayPluginRuntimeIdentityBlockchainBrowserKernel
Secure AI Gateway

Immune Gateway

The firewall is built in, not bolted on.

A security-first gateway for enterprise LLM traffic. A memory-safe Rust core replaces the vulnerable proxy and folds injection, secrets and PII detection inline into every call — prompts never leave your boundary.

  • OpenAI-compatible API, multi-provider routing with fallbacks, virtual keys, budgets & rate limits
  • Inline prompt-injection / jailbreak detection, input-side secrets & PII detection
  • Response-side DLP, content moderation & malicious-URL checks (Enterprise)
  • Private data plane, in-process scanning, immutable audit, one-click bypass
immune-gateway · live
→ POST /v1/chat/completions model=gpt-4o
scan: injection · secrets · pii
✗ blocked prompt-injection (0.97)
"ignore previous instructions and…"
✓ pii masked ×2 · routed → provider-b
200 OK · 41ms · audit#a91f
Plugin Supply-Chain · AIDR

Immune Plugin

Every plugin your developers run is unvetted code with full access.

Plugin supply-chain security (AIDR) across IDE, browser and AI-agent ecosystems. A lightweight agent inventories plugins across the dev fleet, builds a Plugin SBOM, correlates threat intel, and enforces an allowlist before execution.

  • One agent across IDE / browser / AI-agent / MCP plugin classes
  • Detects malicious publishers, rug-pulls, typosquatting & over-privilege
  • MCP tool-poisoning, prompt-injection & credential-exfil detection
  • Privacy-first: metadata & SBOM only — source never leaves the device
immune-plugin · sbom
endpoints 312 · plugins 1,847 · open 12
✓ allow eslint-vscode publisher✔
! warn cursor-ext over-privileged
✗ block solidity-helper rug-pull
mcp://unknown-server quarantined
enforced at endpoint · pre-exec
Agent Runtime Protection

Immune Runtime

Runtime defense for autonomous agents and AI workloads.

AI is most dangerous at execution. Immune Runtime sandboxes agents, monitors tool calls and behavior in real time, blocks out-of-policy actions, detects anomalies and offers a kill-switch — stopping agents from doing harm and from being hijacked.

  • Sandboxed execution with least-privilege boundaries
  • Real-time monitoring & policy enforcement on tool / file / network actions
  • Behavioral baselines & anomaly detection with auto-isolation
  • Human-in-the-loop approval and one-click kill-switch
immune-runtime · agent-7
agent run · tools: shell, http, fs
✓ http GET api.internal allow
! fs write /etc/* needs approval
✗ shell "curl|sh" blocked
anomaly score 0.88 → isolate
kill-switch armed · audit#7c2
Identity for Humans & Agents

Immune Identity

Zero-trust for humans, agents and machine identities.

In the agentic era, the blind spot is "who acted". Immune Identity issues every agent a verifiable identity and scoped credentials, grants just-in-time access, and gives full attribution and audit for every AI action.

  • Verifiable identities & short-lived tokens for agents / services
  • Least-scope and just-in-time (JIT) access grants
  • Non-human identity (NHI) discovery, governance & lifecycle
  • Full attribution, audit and traceability of every AI action
immune-identity · attest
agent did:iw:agent/7c2 ttl 5m
✓ scope: read:tickets
✗ scope: write:prod denied
jit grant · approver: oncall
✓ attributed → user:alice
nhi inventory 1,204 · 18 stale
Web3 & Blockchain Security

Immune Blockchain

AI-driven audit workflow, expert-reviewed findings.

Blockchain security reviews and audits for Web3 teams. AI accelerates scope mapping, attack-surface inventory, tool orchestration, risk triage and reporting while experts own final severity and remediation — plus tamper-evident on-chain attestation for AI actions.

  • Smart-contract audit (Solidity/EVM, access control, accounting)
  • Protocol risk review; rollup / bridge / validator / governance security
  • Chain security drills & launch-readiness review
  • Tamper-evident attestation of AI actions (immune memory)
immune-blockchain · audit
scope: 14 contracts · 2 bridges
● critical reentrancy Vault.sol:142
● high access-ctrl Bridge.sol
● medium oracle-staleness
✓ expert-reviewed · retest passed
attested → 0x9f…2c immutable
Secure Enterprise Browser

Immune Browser

The secure enterprise browser for the AI era.

The browser is the front line where people meet the web and AI tools. Immune Browser isolates AI-assisted browsing, governs extensions, blocks injection from web content, applies DLP to data pasted/uploaded into AI tools, and governs agent-driven web automation.

  • AI-assisted browsing isolation & extension governance
  • Blocks prompt injection from web content
  • DLP on copy / paste / upload into AI tools
  • Governs agent-driven web automation with session recording
immune-browser · policy
tab: chat.vendor.ai managed
✗ paste blocked secret detected
! upload customers.csv pii ×312
✓ extension allowlist enforced
web-injection neutralized ×3
session recorded · audit#bb1
Immune Kernel · Hardened Linux

Immune Kernel

Counter AI with immunity — stay ahead of the bugs and the hackers.

The foundation of the Immune Mesh: a hardened kernel on Linux 6.6.129 LTS that — without source changes, through kernel configuration alone — neutralizes the exploit paths of known CVEs (copy.fail, dirtyfrag variants) and shrinks the surface for rootkits and backdoors. Install once, stay immune — ahead of the patch cycle, without sacrificing stability.

  • Neutralizes known CVE exploit paths via configuration alone — no source changes
  • Shrinks rootkit / backdoor surface; sharpens EDR/HIDS signal
  • lite / pro / promax — graduated immunity tiers
  • Compatible with major distros & apps; one-command install (GPG/SHA256 verified)
immune-kernel · 6.6.129-lts
kernel 6.6.129-immune tier: promax
✓ cve copy.fail neutralized
✓ dirtyfrag-* neutralized
✗ rootkit load denied
attack surface −63% · edr signal ↑
install once · set & forget

Build the immune system for your enterprise AI.

See the Immune Mesh in action. Private, self-hosted and air-gapped options available.