See the full AI trajectory. Control every privileged effect.
Crate Enterprise uses the operation as the unit of security—binding intent, process lineage, temporary authority, observed effects, accepted output, and cleanup into one provenance-backed lifecycle. It enforces the narrowest viable capability path and preserves deterministic replay for long-horizon defense and forensics.
Operation-scoped authority. Cross-layer evidence. Deterministic replay.
Connect what AI intended, requested, executed, changed, and retained—across layers and across time.
What is Gensee Crate Enterprise?
Gensee Crate Enterprise is an operation-scoped security control plane for AI across company systems. Each consequential operation receives a durable identity that joins admission, execution, authority, evidence, cleanup, and output promotion—under an enterprise policy ceiling the runtime can narrow but never exceed.
- Cross-layer evidence Connects intent and tool context to the real process tree, identity, network activity, artifacts, and effects.
- Long-horizon understanding Follows trajectories across sessions, persistent state, and delayed side effects.
- Transactional enforcement Grants or mediates exact authority deltas, closes temporary authority, and promotes only accepted outputs.
- Deterministic replay Normalizes and correlates retained evidence without re-executing commands or repeating external effects.
Higher defense rates across AI threat types.
Preliminary AgentCanary Benchmark results show Gensee Crate improving defense rates across the evaluated threat types.
Long-horizon tasks
Prompt injection
Uber ADRBench
19.1% recall improvement by Gensee
* Results tested on macOS running Claude Code with the Qwen-3.5-397B model.
AI risk crosses layers. Security must connect them.
The consequential failures span AI reasoning, harnesses, identity, tools, runtime, networks, persistent state, artifacts, and outputs. Existing controls answer adjacent questions. Crate binds their evidence and enforcement to the same causal operation.
What breaks
A broad credential or network path granted for one step can remain available to unrelated descendants and later work.
Generated commands, package scripts, plugins, and child processes can perform effects far from the original request.
A command can exit cleanly while creating unexpected files, external effects, or outputs that should not persist.
What Gensee Crate adds
Connect the request and policy decision to process lineage, capability leases, measured effects, cleanup, and retained output.
Keep work local, broker a narrow action, isolate risky code, preserve state without adding privilege, or fail closed.
Close temporary authority, verify the exact product, and promote only the output accepted by enterprise policy.
The dangerous action may happen three sessions later.
Risk can be planted in memory, hidden in a skill, carried through an artifact, and triggered days later by an ordinary task. Crate links persistence, execution, and side effects into one policy-aware trace.
Proprietary long-horizon intelligence correlates behavior across sessions to detect and prevent delayed attack chains before a later action becomes an incident.
Security that stays connected from request to retained result.
Crate separates the security decisions that are too often collapsed into one “allow.” Each plane narrows and checks the next while sharing the same operation identity.
Admission + policy
Normalize declared intent, apply deterministic company rules, and resolve an approved operation contract beneath the enterprise delegation ceiling.
Execution + isolation
Select the boundary that fits the effect: existing environment, trusted mediator, fresh capability cell, state-preserving path, or deny and approve.
Authority + effects
Bind the exact authority delta to the operation, process lineage, resource, action, budget, and lifetime while keeping broad credentials behind trusted boundaries.
Observation + evidence
Join AI context with independently observed process, filesystem, network, identity, provider, and lifecycle evidence—and make coverage gaps explicit.
Persistence + recovery
Separate command success from output acceptance, prove temporary authority is closed, and promote the verified product through a controlled commit.
Built for the AI harnesses teams already run.
Crate starts where AI risk becomes concrete: code workspaces, shell access, files, tools, memory, skills, and external network paths.
Codex
OmnigentChoose the narrowest viable boundary for every operation.
Least privilege is not one sandbox. Crate evaluates the requested effect, current envelope, process lineage, and available enforcement boundary, then selects the path that adds the least new authority.
Existing environment
- Stay inside the current envelope or attach an exact local lease.
Trusted mediator
- Perform one constrained effect without transferring the broad credential.
Fresh capability cell
- Run risky code with selected inputs, exact leases, and separate output.
Same-authority path
- Preserve valuable live state without raising the privilege ceiling.
Deny or approve
- Stage effects that cannot be named, bounded, or mediated safely.
Measure the operation
Compare process, file, network, identity, and provider effects with the authorized capability and expected manifest.
Close temporary authority
Require leases to be consumed, revoked, expired, or otherwise terminal before the transaction can close.
Promote accepted output
Commit only the verified product covered by policy and evidence; command success alone is never the acceptance decision.
For AI that can change real systems.
Local AI harnesses
Keep Claude Code, Codex, and similar AI harnesses away from secrets, dangerous scripts, poisoned memory, and destructive commands.
Virtualized execution cells
Run risky work with selected inputs, scoped authority, separated outputs, mandatory mediation, and lifecycle-bound cleanup.
Internal AI platforms
Integrate runtime enforcement into existing AI systems, MCP gateways, code hosts, identity, and incident response workflows.
AI and cloud red teaming
Exercise adversarial paths through AI harnesses, cloud identity, secrets, networks, tools, persistence, and delayed effects—with ground-truth evidence for every step.
Answers for teams evaluating AI security.
What does Gensee Crate Enterprise protect?
It protects company-managed AI operations across admission, process execution, file and network access, identity, credentials, external services, observed effects, and durable output.
Who is it for?
Companies adopting AI with access to code, credentials, files, memory, tools, or networked systems. Individual developers should use Gensee Crate Personal.
How is it different from point security controls?
Point controls observe one layer at a time—prompt text, endpoint events, identity, cloud, or network activity. Crate connects the full AI trajectory across these layers and across time, then enforces capabilities at the runtime transaction boundary.
What value does Crate Enterprise add?
It connects cross-layer observability and provenance, long-horizon trajectory understanding, transactional capability enforcement, and deterministic replay for investigation and forensics.
How does Crate fit existing systems?
Crate connects with existing policy, identity, alerting, code-hosting, incident-response, cloud and API gateways, secret brokers, browser gateways, database proxies, and AI-platform workflows.
Which AI harnesses are supported?
Claude Code is the current local hook focus; Codex, MCP, generic launchers, internal AI, and company-specific integrations are part of the broader direction.
How is privileged authority granted?
Enterprise policy sets an immutable delegation ceiling. For each operation, Crate grants or mediates only the exact authority delta needed—bound to the process lineage, resource, action, and lifetime—while broad credentials remain behind trusted boundaries.
What determines output promotion?
Promotion is a separate security decision based on policy, the exact product, verifier evidence, observed effects, and proof that temporary authority is closed—not on an AI harness's success claim.
What if some runtime evidence is unavailable?
Crate treats missing sensor or provider coverage as an explicit gap that policy, verification, and promotion can evaluate. It does not silently present incomplete telemetry as complete evidence.
Give every AI operation an authority boundary and an evidence trail.
Talk to us about operation-scoped authority, cross-layer observability and provenance, long-horizon intelligence, transactional capability enforcement, deterministic replay, and company-wide policy.