AEBA-XDR a CyberSecAI company
Supported by patents · Industry first · Enterprise-ready

AEBA-XDR

Agent Event Behaviour Analysis

Extended detection and response for the autonomous AI workforce.

Enterprises deploying autonomous AI agents face a blind spot no existing security platform closes. AEBA-XDR provides cryptographically verified behavioural telemetry, continuous anomaly detection, and regulator-ready audit for every agent you run -- from first deployment to fleet scale.

Request datasheet
Supported by patents IETF standards-based On-prem · Private cloud · SaaS EU AI Act · SOX · DORA · SOC 2 · HIPAA
Powered by
Agent Trust Scoring with AgentPass + MCPS
The secure MCP protocol we built. Now in production. Every agent gets a trust score. Every message gets signed. Every action gets audited. No trust, no access.
AgentPass MCPS IETF Draft
Inside the console

A glimpse of the AEBA-XDR console

app.aeba.co.uk

Your AI agents are running in production. Who's watching them?

OPTION 1

Monitor nothing

Agents run blind. No behavioural baseline. No anomaly detection. No audit trail. When something goes wrong, you find out from your regulator.

OPTION 2

Build your own

6 months of engineering. Custom telemetry. Custom anomaly models. Custom compliance mapping. Then maintain it forever. While your agents keep shipping.

OPTION 3

AEBA-XDR

Runtime behaviour analysis for every agent. Anomaly detection in milliseconds. Cryptographic audit trail. Adaptive trust scoring. Live in 5 minutes. Not 6 months.

8
Dimensions analysed
<1ms
Detection latency
IETF
Internet-Draft published
22
Patents filed
Live
In production

Up and running in 3 steps

No infrastructure changes. No new databases. No agents to redeploy.

1

Connect your agents

Point AEBA at your MCP server, A2A endpoint, or agent framework. One config line. Works with any protocol.

2

AEBA learns behaviour

Baseline established automatically. Every agent interaction signed, logged, and analysed across 8 dimensions. No manual configuration.

3

Detect. Alert. Respond.

Anomalies detected in real-time. Trust scores adjust automatically. Rogue agents isolated. Full audit trail for compliance. Self-healing on compromise.

Works with every agent protocol
MCP A2A LangChain CrewAI Autogen Pydantic AI Custom HTTP
Designed for regulated, high-stakes AI deployments
Financial services Insurance Healthcare Government & defence Critical infrastructure Enterprise SaaS

What AEBA-XDR delivers

Board-ready outcomes across risk, regulation, and operating cost -- delivered by a single platform purpose-built for the AI agent estate.

A

Risk reduction

Continuous detection of prompt injection, credential abuse, tool misuse, and supply-chain compromise across every agent. Signed audit trail establishes accountability end to end.

B

Regulator-ready audit

Cryptographically signed, hash-chained event records meet the evidentiary bar of the EU AI Act, SOX, DORA, HIPAA, and SOC 2 out of the box.

C

FinOps governance

Per-agent budgets, daily spend attribution, runaway detection, and breach alerting stop AI cost overruns before they reach the board.

D

SOC integration

Feeds your existing SIEM, XDR, and SOAR platforms without re-plumbing. AEBA-XDR is additive -- it adds a dimension rather than replacing what you run.

Why this gap exists

Legacy security tooling is built on unsigned network and endpoint telemetry. AI agents live on neither. Their reality is tool calls, LLM prompts, MCP messages, payment rails and delegation chains -- and they have no cryptographic identity.

UEBA category

Users
Sees humans. Agents invisible.

EDR / XDR category

Endpoints
Sees processes. Misses in-agent reasoning.

NDR category

Network
Packets and flows, outside TLS.

AEBA-XDR

Agents
Signed events. Adaptive detection. Peer-group insight. Cost-aware. Regulator-ready.

Core capabilities

A single platform that combines verifiable observability, adaptive detection, and compliance-grade audit for the enterprise AI agent estate.

1

Verifiable behavioural telemetry

Every agent action is cryptographically signed at source and hash-chained into an append-only record. Tamper evidence by construction.

2

Adaptive detection

Continuous learning across your agent estate identifies novel threats, drift, and misuse without waiting for rule authors to catch up.

3

Regulatory alignment

Built-in mapping to EU AI Act, SOX, DORA, HIPAA and SOC 2. Findings are routed to the frameworks your auditors already use.

4

Economic governance

Per-agent budgets, per-tenant cost attribution, and breach alerting -- bringing FinOps discipline to the AI workload.

Not another dashboard. A runtime immune system.

Traditional monitoring

  • x Logs after the fact
  • x No agent identity verification
  • x No behavioural baseline
  • x No cryptographic proof
  • x No adaptive trust
  • x Manual investigation

AEBA-XDR

  • + Real-time detection in milliseconds
  • + Every agent cryptographically identified
  • + Behavioural baseline per agent
  • + Hash-chained tamper-evident audit
  • + Trust scores adapt automatically
  • + Self-healing on compromise

How you deploy

Zero network tap. Zero inline proxy. Zero kernel hook. One line of integration in your agent, or a lightweight sidecar alongside it. Events flow over TLS to your private hub.

🔌

One-line integration

Drop a single import into your existing agent. Works with LangChain, AutoGen, CrewAI, OpenAI, Anthropic, and MCP out of the box.

🏢

Your infrastructure

Run the AEBA-XDR hub in your own cloud, on-premises, or on our managed SaaS. Your data stays where you choose.

📡

Ships to your SIEM

Native forwarders for the major XDR and SIEM platforms -- no replumbing of your security stack.

MITRE ATT&CK + ATLAS mapped detections

Every detection rule maps to MITRE ATT&CK (enterprise threats) and MITRE ATLAS (AI-specific threats). 12 core rules. 29 total across all packs. Real technique IDs, not marketing labels.

MITRE ATT&CK

T1566 Phishing / Social Engineering
T1565 Data Manipulation
T1499 Endpoint Denial of Service
T1070 Indicator Removal
T1110 Brute Force / Probing
T1078 Valid Accounts / Privilege Abuse
T1020 Automated Exfiltration
T1036 Masquerading
T1059 Command / Script Execution
T1496 Resource Hijacking
T1578 Cloud Compute Modification

MITRE ATLAS (AI-Specific)

AML.T0051 LLM Prompt Injection
AML.T0048 Agent Goal Hijacking
AML.T0019 Poisoned Tool Definitions
AML.T0024 Exfiltration via ML Inference
AML.T0031 ML Model Integrity Erosion
AML.T0040 ML Inference API Probing
AML.T0043 Adversarial Replay Attack
29 detection rules across 6 packs (core, fintech, finserv, finops, insurance, EU AI Act)
Every alert includes the MITRE technique ID, severity, evidence, and remediation guidance

Built on open standards

AEBA-XDR is grounded in published standards work and patent-supported innovation by CyberSecAI Ltd.

📜

IETF Internet-Draft

The behavioural event transport is specified in an open IETF Internet-Draft, giving vendor-neutral interoperability.

⚖️

Patent supported

Our detection method is protected intellectual property of CyberSecAI Ltd.

🛡️

Aligned with OWASP

References the OWASP MCP Security Cheat Sheet and the OWASP MCP Top 10 recommended controls for agent-era security hygiene.

Compliance-aligned. Enterprise-grade.

AEBA-XDR is designed against the frameworks your compliance, risk, and audit teams already operate under. Findings map to the clause, article, or control your auditors expect.

EU AI Act
Art. 12, 13, 14, 15, 50, 72
PSD2 / SCA
Art. 97, RTS-SCA
SOX 404
Material-action audit
DORA
Art. 28, 30
Solvency II
Pillar 2 governance
SOC 2
Trust Services Criteria
HIPAA
PHI access logging
MITRE ATT&CK
TTP-tagged findings

Frequently asked

Do we need to change our agent code?

One line. import aeba; aeba.autocapture() monkey-patches your existing LLM and tool libraries (LangChain, AutoGen, CrewAI, OpenAI SDK, Anthropic SDK, MCP client). No agent rewrite required.

Where does our event data live?

Your choice. Fully on-premises in your VPC, managed SaaS in an isolated tenant, or hybrid with on-prem collector and cloud analytics. Demo environments use synthetic data only.

How does this differ from existing UEBA or XDR tools?

Existing UEBA and XDR platforms analyse unsigned user, endpoint, or network telemetry. AEBA-XDR operates on cryptographically-signed agent behavioural events, giving provable origin and tamper evidence. The method is patent supported.

GDPR? EU AI Act?

Covered. AEBA-XDR ships with an EU AI Act compliance pack mapping Articles 12, 13, 14, 15, 50 and 72. Signed audit logs meet Article 12 record-keeping by construction. Your data stays in your region (UK, EU, US) and never leaves.

SIEM integration?

Native forwarders for the major XDR and SIEM platforms, plus standard CEF, LEEF, and syslog RFC 5424. Your existing security stack stays in place; AEBA-XDR feeds it a new dimension.

Pricing?

Free evaluation tier for up to three agents. Commercial tiers priced per monitored agent. On-prem and SaaS. Contact contact@agentsign.dev for a quote.

Sign up for a free demo

Per-prospect sandbox. Synthetic data only. Auto-expires in 24 hours. We provision within one business day.

Or email us directly at contact@agentsign.dev