Gensee Crate Enterprise Company-wide AI security

See the full AI trajectory. Control every privileged effect.

Crate Enterprise uses the operation as the unit of security—binding intent, process lineage, temporary authority, observed effects, accepted output, and cleanup into one provenance-backed lifecycle. It enforces the narrowest viable capability path and preserves deterministic replay for long-horizon defense and forensics.

Operation-scoped authority. Cross-layer evidence. Deterministic replay.

One operation · exact authority · measured effects · accepted output
Isolated execution cells Scoped leases Transactional promotion

Connect what AI intended, requested, executed, changed, and retained—across layers and across time.

Quick answer

What is Gensee Crate Enterprise?

Gensee Crate Enterprise is an operation-scoped security control plane for AI across company systems. Each consequential operation receives a durable identity that joins admission, execution, authority, evidence, cleanup, and output promotion—under an enterprise policy ceiling the runtime can narrow but never exceed.

  • Cross-layer evidence Connects intent and tool context to the real process tree, identity, network activity, artifacts, and effects.
  • Long-horizon understanding Follows trajectories across sessions, persistent state, and delayed side effects.
  • Transactional enforcement Grants or mediates exact authority deltas, closes temporary authority, and promotes only accepted outputs.
  • Deterministic replay Normalizes and correlates retained evidence without re-executing commands or repeating external effects.
Early benchmark signal

Higher defense rates across AI threat types.

Preliminary AgentCanary Benchmark results show Gensee Crate improving defense rates across the evaluated threat types.

Memory poisoning

Baseline75%
With Gensee93.8%
18.8 pt lift

Long-horizon tasks

Baseline65.4%
With Gensee100%
34.6 pt lift

Prompt injection

Baseline77.8%
With Gensee93.5%
15.7 pt lift

Uber ADRBench

19.1% recall improvement by Gensee

Recall improvement
+19.1 pts
73.8% → 92.9%
False-positive reduction
−2.3 pts
13.8% → 11.5%
Accuracy improvement
+4.6 pts
84.5% → 89.1%
Runtime overhead 0.6%–1.2% · 10ms–400ms per request

* Results tested on macOS running Claude Code with the Qwen-3.5-397B model.

Why Crate

AI risk crosses layers. Security must connect them.

The consequential failures span AI reasoning, harnesses, identity, tools, runtime, networks, persistent state, artifacts, and outputs. Existing controls answer adjacent questions. Crate binds their evidence and enforcement to the same causal operation.

What breaks

Authority becomes ambient.

A broad credential or network path granted for one step can remain available to unrelated descendants and later work.

The real subject is several processes away.

Generated commands, package scripts, plugins, and child processes can perform effects far from the original request.

Success is not the same as acceptance.

A command can exit cleanly while creating unexpected files, external effects, or outputs that should not persist.

What Gensee Crate adds

One durable operation identity.

Connect the request and policy decision to process lineage, capability leases, measured effects, cleanup, and retained output.

Authority shaped to the effect.

Keep work local, broker a narrow action, isolate risky code, preserve state without adding privilege, or fail closed.

Evidence-backed persistence.

Close temporary authority, verify the exact product, and promote only the output accepted by enterprise policy.

Long-horizon defense

The dangerous action may happen three sessions later.

Risk can be planted in memory, hidden in a skill, carried through an artifact, and triggered days later by an ordinary task. Crate links persistence, execution, and side effects into one policy-aware trace.

Proprietary long-horizon intelligence correlates behavior across sessions to detect and prevent delayed attack chains before a later action becomes an incident.

One operation, five planes

Security that stays connected from request to retained result.

Crate separates the security decisions that are too often collapsed into one “allow.” Each plane narrows and checks the next while sharing the same operation identity.

01

Admission + policy

Normalize declared intent, apply deterministic company rules, and resolve an approved operation contract beneath the enterprise delegation ceiling.

02

Execution + isolation

Select the boundary that fits the effect: existing environment, trusted mediator, fresh capability cell, state-preserving path, or deny and approve.

03

Authority + effects

Bind the exact authority delta to the operation, process lineage, resource, action, budget, and lifetime while keeping broad credentials behind trusted boundaries.

04

Observation + evidence

Join AI context with independently observed process, filesystem, network, identity, provider, and lifecycle evidence—and make coverage gaps explicit.

05

Persistence + recovery

Separate command success from output acceptance, prove temporary authority is closed, and promote the verified product through a controlled commit.

Supported AI harnesses

Built for the AI harnesses teams already run.

Crate starts where AI risk becomes concrete: code workspaces, shell access, files, tools, memory, skills, and external network paths.

Codex
Claude Code
Claude Cowork
Cursor
GitHub Copilot
Antigravity
Omnigent
Execution-path selection

Choose the narrowest viable boundary for every operation.

Least privilege is not one sandbox. Crate evaluates the requested effect, current envelope, process lineage, and available enforcement boundary, then selects the path that adds the least new authority.

Path 01 · Local

Existing environment

  • Stay inside the current envelope or attach an exact local lease.
Path 02 · Brokered

Trusted mediator

  • Perform one constrained effect without transferring the broad credential.
Path 03 · Isolated

Fresh capability cell

  • Run risky code with selected inputs, exact leases, and separate output.
Path 04 · Stateful

Same-authority path

  • Preserve valuable live state without raising the privilege ceiling.
Path 05 · Fail closed

Deny or approve

  • Stage effects that cannot be named, bounded, or mediated safely.

Measure the operation

Compare process, file, network, identity, and provider effects with the authorized capability and expected manifest.

Close temporary authority

Require leases to be consumed, revoked, expired, or otherwise terminal before the transaction can close.

Promote accepted output

Commit only the verified product covered by policy and evidence; command success alone is never the acceptance decision.

Use cases

For AI that can change real systems.

Local AI harnesses

Keep Claude Code, Codex, and similar AI harnesses away from secrets, dangerous scripts, poisoned memory, and destructive commands.

Virtualized execution cells

Run risky work with selected inputs, scoped authority, separated outputs, mandatory mediation, and lifecycle-bound cleanup.

Internal AI platforms

Integrate runtime enforcement into existing AI systems, MCP gateways, code hosts, identity, and incident response workflows.

AI and cloud red teaming

Exercise adversarial paths through AI harnesses, cloud identity, secrets, networks, tools, persistence, and delayed effects—with ground-truth evidence for every step.

FAQ

Answers for teams evaluating AI security.

What does Gensee Crate Enterprise protect?

It protects company-managed AI operations across admission, process execution, file and network access, identity, credentials, external services, observed effects, and durable output.

Who is it for?

Companies adopting AI with access to code, credentials, files, memory, tools, or networked systems. Individual developers should use Gensee Crate Personal.

How is it different from point security controls?

Point controls observe one layer at a time—prompt text, endpoint events, identity, cloud, or network activity. Crate connects the full AI trajectory across these layers and across time, then enforces capabilities at the runtime transaction boundary.

What value does Crate Enterprise add?

It connects cross-layer observability and provenance, long-horizon trajectory understanding, transactional capability enforcement, and deterministic replay for investigation and forensics.

How does Crate fit existing systems?

Crate connects with existing policy, identity, alerting, code-hosting, incident-response, cloud and API gateways, secret brokers, browser gateways, database proxies, and AI-platform workflows.

Which AI harnesses are supported?

Claude Code is the current local hook focus; Codex, MCP, generic launchers, internal AI, and company-specific integrations are part of the broader direction.

How is privileged authority granted?

Enterprise policy sets an immutable delegation ceiling. For each operation, Crate grants or mediates only the exact authority delta needed—bound to the process lineage, resource, action, and lifetime—while broad credentials remain behind trusted boundaries.

What determines output promotion?

Promotion is a separate security decision based on policy, the exact product, verifier evidence, observed effects, and proof that temporary authority is closed—not on an AI harness's success claim.

What if some runtime evidence is unavailable?

Crate treats missing sensor or provider coverage as an explicit gap that policy, verification, and promotion can evaluate. It does not silently present incomplete telemetry as complete evidence.

Gensee Crate Enterprise

Give every AI operation an authority boundary and an evidence trail.

Talk to us about operation-scoped authority, cross-layer observability and provenance, long-horizon intelligence, transactional capability enforcement, deterministic replay, and company-wide policy.