Skip to main content
Announcement: Now accepting design beta partners · Read more
>

Know Every Agent, Govern Every Connection

Request a demo

See your agents named on the wire. We’ll reach out within one business day.

Maya overview

See every agent. Govern every connection.

Maya is AI agent governance on the wire. It sits inside your VPC, names every AI agent from the traffic it makes, payload-blindMaya never decrypts your network traffic, with zero agent code changeNo SDK, no sidecar, zero instrumentation, and enforces each agent’s mandate on every connection it opens. One place to see the fleet. One switch per agent.

One agent in a fleet of hundreds goes wrong.

Can you identify it? Can you stop it?

OpenAI / Hugging Face

Agents escaped an isolated evaluation environment and compromised external production systems.

The sandbox allowed exactly one egress. The agent found a zero-day in it, moved laterally, and broke into a third party’s production infrastructure.

Source: OpenAI disclosure, July 2026

Anthropic

Claude models gained unauthorized access to real third-party systems in four separate incidents.

Real credentials, real tools, and reach that was never in the mandate. The plot every incident write-up shares.

Source: the incident write-ups, collected on our blog

Agent governance is no longer optional. Imagine repeating the forensics for every misbehaving agent.

Existing controls do not govern the logical agent.

The missing layer is agent-aware enforcement on the network path: a single, universal kill switch.

Identity

Defines permitted access for the principal.

Does not govern the agent’s actions on the wire.

Firewall

Sees only the workload and the network flow.

Cannot identify or enforce the logical agent.

Observability

Reports instrumented agent activity after the fact.

Depends on agent or runtime instrumentation.

Agent runtime tools

Governs the agent from inside its own runtime.

One integration per framework, one footprint per host, no single point of control.

Introducing Maya

Maya makes every AI agent a governable unit.

Maya sees every agent on the wire and enforces its mandate on every connection.

  1. Declare
  2. Observe
  3. Detect
  4. Judge
  5. Enforce

Discover every agent

Every agent, including the shadow agents nobody declared, becomes visible.

Bind its mandate

You define an agent’s policy mandate once, centrally. It follows the agent.

Gather operational evidence

Every connection is attributed to the agent that made it. Shady agents are exposed here.

Control agent behavior

Allow, limit, or stop each agent precisely, or the individual flows inside its traffic.

The Maya console's Agents view. Fifteen agents grouped by host on the left, every resource they reached in seven days on the right: other agents, AWS databases and data stores, external endpoints and unknown resources. Two connections from it-helpdesk and hr-onboarding are drawn in red as deviations, and one to hr-db is marked blocked by rule.
Every curve is a connection that happened on the wire, attributed to the agent that made it. The red ones are the deviations.

Govern every agent. Keep the fleet running. On the wire. Per agent. Without decrypting traffic.

Coverage

Wherever the agent runs, the same name on the wire.

Where agents run

  • Remote workersAgents on laptops, anywhere they work.
  • Cloud agent runtimesBedrock, Vertex and container platforms.
  • Servers you runLinux VMs and Kubernetes in your VPC, in any cloud or on premise.

What they reach

  • ModelsLLM APIs and endpoints.
  • DataS3, databases, warehouses.
  • Tools and agentsMCP servers, SaaS, other agents.

Every fleet. Every destination. One place the evidence is made. Nothing changes inside the agent.

The fabric · one domain, every cloud, any location

From one host to a million agents in a single domain.

Maya runs in your own VPC, VNet or VCN, in any cloud. Cross-region, cross-cloud agent-to-agent traffic is governed and tunneled, never decrypted.

Where Maya's data plane runs: one Warp agent gateway per cloud region, in front of the compute and the managed agent runtime in that region.
Cloud Region Data plane Compute Managed agent runtime
AWS us-west · VPC Warp · agent gateway EC2 Amazon Bedrock
Azure eu-central · VNet Warp · agent gateway Virtual Machines Azure AI Foundry
GCP apac · VPC Warp · agent gateway Compute Engine, GKE Vertex AI
OCI us-east · VCN Warp · agent gateway Compute, OKE Agent runtime

Control plane

Loom, one global pane. Regional Weavers in us, eu and apac hold the domain together.

  • OTel telemetry export into the tools you already run
  • gRPC and REST API, and the console
  • Know every agent in the fleet. Govern every connection.

Judgment

Bring your own judgment to the deviations Maya raises.

  • Zoom, the autonomous agent monitor
  • BYoLLM, deep agent inspection with the model you choose
  • Or your OPA, your SIEM, or Maya’s built-in rules

One console for the whole fleet.

The Maya console dashboard. Fifteen agents observed in seven days, twelve active, one unknown agent blocked by rule, two open deviations awaiting review, 1.22 GB of AI egress across three providers, five rules in effect. Two deviations need review: an agent-to-agent connection with no rule, and an undeclared destination. Two connections were blocked in the period, and policy shows four rules such as env=dev may not reach env=prod, enforced.

Shadow and shady agents

Discovered and auto-blocked. An agent nobody declared is named the moment it opens a connection, and held until someone says otherwise.

One policy to rule them all

Write the mandate once and it reprojects onto every new agent that matches it. No per-host config, no per-framework integration.

Every connection, with the evidence

Agent to agent, and any agent to any destination. Both ends named, nothing decrypted, one audit trail.

Rides your identity provider: Okta, SPIFFE, cloud IAM. Without decrypting traffic. Nothing changes inside the agent. Available now on AWS and GCP · runs in your cloud account

See the product

The founders

Built by network and security experts.

Daljeet Singh

Daljeet Singh

Founder & CEO · dataplane and identity

Nearly three decades building forwarding planes, deep packet inspection, quality of service and control-plane security. Built Maya’s distributed fabric, its data plane and its agent identity model.

Cisco · Juniper · Brocade · IBM · OCI

Nine US patents.

Rajiv Raghunarayan

Rajiv Raghunarayan

Co-founder & CTO · security and product

Founding engineer of Cisco’s network infrastructure security group, then product and go-to-market leader across enterprise security, from early stage through IPO.

Cisco · FireEye · SentinelOne · Forcepoint · Elastic

Authored IETF RFCs. Four US patents. MBA, UC Berkeley Haas.

Meet the whole team

Now onboarding design and research partners.

A small number of teams running agents in their own cloud, with Maya on the wire beside them.

Email [email protected] to talk, [email protected] for the research and education program, or [email protected] to partner.

Start a conversation

Cookies

We use analytics cookies to see how this site is used so we can make it better. Nothing is stored until you say yes. See our privacy policy.