Gensee Crate Enterprise Company-wide AI security

System-level AI security, built for every layer of your company.

Crate Enterprise gives companies a customized security and control layer across AI harnesses, developer endpoints, Linux execution, identity, network, secrets, cloud, and APIs. It turns company policy into distributed enforcement and telemetry-backed evidence at fleet scale.

Customized to your stack. Enforced across the system. Observable at company scale.

Decide local / cell / approve / deny
Broker short-lived authority
Mediate Linux + service boundaries
Verify effects before promotion
repo.writeisolated cell
cloud.roleapproval
output.promoteverify effects
Capability policy · brokered authority · mandatory mediation · effect manifests
Isolated execution cells Scoped leases Transactional promotion

Promotion follows the effect manifest and observed telemetry—not an AI harness's claim that a task succeeded.

Quick answer

What is Gensee Crate Enterprise?

Gensee Crate Enterprise is a customized, execution-aware security layer for AI across company systems. It turns declared intent, runtime evidence, and artifact provenance into policy decisions before risky actions complete.

  • Different layer Protects tool execution and side effects, not just prompt text.
  • Different evidence Correlates requests, commands, files, artifacts, risk tags, and alerts.
  • Different outcome Moves teams from after-the-fact logs to live allow, ask, or deny decisions.
Why Crate

Prompt guards miss the machine surface.

Once AI can use tools, access files, browse networks, write memory, and execute scripts, security has to follow the action path, not just the text prompt.

What breaks

Credentials move through tools.

Secrets, config files, and local credentials are exposed by reads and tool outputs, not only by prompts.

Actions outrun intent.

AI can install packages, run scripts, modify files, change permissions, or reach external networks.

Persistence hides in artifacts.

Poisoned memory, modified skills, shell scripts, and hooks can survive beyond the current request.

What Gensee Crate adds

Ground-truth provenance.

Track prompts, tool calls, file intents, observed effects, artifacts, risk tags, and lineage in a queryable provenance graph.

Prevention before damage.

Return allow, ask, or deny before tool execution; inspect assembled script content at execution time.

Deployable policy.

Use the same core controls wherever AI touches tools, files, credentials, memory, or network paths.

Layered defense model connecting human requests, AI actions, and system surfaces to Gensee Crate enforcement
Defense model · Follow the request, AI actions, and measured system effects across the full execution path.
Long-horizon defense

The dangerous action may happen three sessions later.

Risk can be planted in memory, hidden in a skill, carried through an artifact, and triggered days later by an ordinary task. Crate links persistence, execution, and side effects into one policy-aware trace.

Proprietary long-horizon intelligence correlates behavior across sessions to detect and prevent delayed attack chains before a later action becomes an incident.

Three-session security timeline showing poisoned memory planted first, used during a later task, and stopped before a risky system action
Risk lineage · Connect persistent state from an earlier session to the later action it influenced.
Product

Turn requested privilege into bounded capability.

Crate evaluates each privilege delta, attaches only the authority an operation needs, mediates the resulting effects, and verifies the evidence before outputs can be promoted.

01

Capability policy engine

Evaluate requested changes across files, networks, secrets, identity, cloud permissions, external APIs, side effects, and output promotion.

02

Four explicit decisions

Allow locally, delegate to an isolated cell, stage for human or policy approval, or deny before privileged execution begins.

03

Capability broker

Issue short-lived tokens, identities, certificates, handles, leases, and roles without exposing broad underlying credentials.

04

Mandatory mediation

Enforce decisions across OS, network, filesystem, cloud and API, secret, browser, and database boundaries.

05

Effect-based promotion

Reconcile declared capability use with observed effects, violations, and proposed outputs before promotion.

Supported AI harnesses

Built for the AI harnesses teams already run.

Crate starts where AI risk becomes concrete: code workspaces, shell access, files, tools, memory, skills, and external network paths.

Codex
Claude Code
Cursor
GitHub Copilot
Antigravity
Omnigent
Architecture

From requested capability to verified effect.

Enterprise operations move through a capability-aware control path. Authority is narrowed before execution, every privileged effect is mediated, and output promotion depends on measured evidence.

Requested Capability

  • Resources and data access
  • Identity and external effects

Policy + Broker

  • Decide where work runs
  • Issue least-privilege authority

Virtualized Execution

  • Isolate work and state
  • Capture observed effects

Mandatory Mediation

Carry policy decisions through the system boundaries where privileged effects occur.

Virtualization Execution Substrate

Run delegated work with isolated state, scoped authority, and complete lifecycle control.

Verified Promotion

Promote outputs only when policy, observed telemetry, and effect evidence agree.

Distributed enterprise deployment connecting developer-side Gensee enforcement with company policy, an MCP and skills gateway, and centralized dashboards
Deployment model · Connect distributed enforcement with company policy, AI harness gateways, and centralized evidence.
Effect manifest

Promotion follows observed effects.

Every privileged operation produces a structured record of requested authority, authority actually used, system effects, proposed outputs, and violations.

The manifest is reconciled with ground-truth telemetry before any output is promoted. A successful self-report from an AI harness is not sufficient evidence.

Policy decision + actual telemetry + effect manifest → promotion decision
{
  "operation_id": "op_123",
  "requested_capabilities": [],
  "capabilities_used": [],
  "files_read": [],
  "files_changed": [],
  "network_connections": [],
  "external_requests": [],
  "secrets_accessed": [],
  "processes_started": [],
  "outputs_proposed_for_promotion": [],
  "violations": []
}
Early benchmark signal

Higher defense rates across AI threat types.

Preliminary AgentCanary Benchmark results show Gensee Crate improving defense rates across the evaluated threat types.

Memory poisoning

Baseline75%
With Gensee93.8%
18.8 pt lift

Long-horizon tasks

Baseline65.4%
With Gensee100%
34.6 pt lift

Prompt injection

Baseline77.8%
With Gensee93.5%
15.7 pt lift
Runtime overhead 0.6%–1.2% · 10ms–400ms per request

* Results tested on macOS running Claude Code with the Qwen-3.5-397B model.

Use cases

For AI that can change real systems.

Local AI harnesses

Keep Claude Code, Codex, and similar AI harnesses away from secrets, dangerous scripts, poisoned memory, and destructive commands.

Virtualized execution cells

Run privileged work in isolated environments with scoped authority, separated state, mandatory mediation, and complete lifecycle control.

Internal AI platforms

Integrate runtime enforcement into existing AI systems, MCP gateways, code hosts, identity, and incident response workflows.

FAQ

Answers for teams evaluating AI security.

What does Gensee Crate Enterprise protect?

It protects company-managed AI execution paths: tools, shell commands, file access, memory artifacts, skills/plugins, network targets, and resulting artifacts.

Who is it for?

Companies adopting AI with access to code, credentials, files, memory, tools, or networked systems. Individual developers should use Gensee Crate Personal.

How is it different from prompt guards?

Prompt guards focus on input text. Gensee Crate watches what AI does to the machine and enforces policy before risky tool calls proceed.

What value does Crate Enterprise add?

It evaluates requested capability deltas, brokers short-lived authority, mediates privileged effects, and keeps the effect manifest, provenance, forensics, and replay trail needed for investigation.

How does Crate fit existing systems?

Crate connects with existing policy, identity, alerting, code-hosting, incident-response, cloud and API gateways, secret brokers, browser gateways, database proxies, and AI-platform workflows.

Which AI harnesses are supported?

Claude Code is the current local hook focus; Codex, MCP, generic launchers, internal AI, and company-specific integrations are part of the broader direction.

How is privileged authority granted?

The capability broker mints a narrow, short-lived token, identity, certificate, handle, lease, role, or signed commit token. The underlying broad credential is never copied into the execution cell.

What determines output promotion?

Promotion is based on the policy decision, effect manifest, and actual runtime telemetry—including violations and external effects—not on an AI harness's success claim.

Gensee Crate Enterprise

Enforce AI security across the environments your company already uses.

Talk to us about company-wide policy, distributed enforcement, long-horizon defense, forensics, replay, observability, provenance, and customer-controlled deployment.