What is Keystrike?
Keystrike is an intent-based security platform for governing AI agents and critical systems. The platform monitors access to protected resources, recording whether they are from approved employee workstations or unmanaged devices. Keystrike secures remote sessions, agentic work, and third-party access by blocking interactions to sensitive resources in real-time unless they have Proven Intent: actions, commands, or prompts that are cryptographically bound to the authorized person's input. Actions without Proven Intent are blocked.
Every governed action becomes tamper-evident, non-repudiable evidence that organizations compile into their compliance reporting.
Intent therefore isn't a guess
about what a user or agent meant to do; it's proof.
Was this action, command or prompt cryptographically bound to the authorized person's input?
Across everything that acts on your systems
One control — verify every action is bound to an authorized person — across remote sessions, agentic work, and third-party access. See the Platform →
| See | Control | Prove | |
|---|---|---|---|
| Remote sessions | Live view of remote access from client-enabled endpoints and unknown or unmanaged clients across documented supported protocols. | Physical-input verification, tripwire alert, and real-time blocking on supported interactive protocols. | Evidence of governed sessions and enforcement on supported paths, and patent-pending attestations of commands through per-keystroke cryptographic signatures. |
| Agentic work | Approved framework includes visibility into relevant chatbot and AI-agent activity on endpoints, including unsanctioned “shadow AI” use. | Require Proven Intent for governed actions, commands or prompts where enforcement is enabled. | Non-repudiable cryptographic evidence connects unwarranted agent authorizations to the input prompt and approvals by the authorized person. |
| Third-party access | Visualize how third parties behave in your network – live. | Govern third-party access at keystroke level through agents, or manage third party access agentless by bounding the servers, identities, time interval, and even applications they may use. | Non-repudiable evidence logs of remote access, and signed per-keystroke evidence from client-enabled governed sessions. |
Keystrike gives us greater confidence that privileged activity is being performed by an authorized person, not merely through valid credentials. It complements our existing identity, endpoint and privileged access controls with zero friction for the user, helping us demonstrate that sensitive actions originate from authorized workstations with verified human involvement.
Chief Information Security Officer, European Bank
What is the difference between Proven and Inferred Intent?
Keystrike is based on Proven Intent, a control that seamlessly integrates into and strengthens the rest of your security stack, across remote sessions, agentic work, and third-party access.
With Proven Intent we use the physical input that is already there to continuously
create device-bound cryptographic evidence.
- Proven Intent is not a guess about what a user or agent meant to do; it's proof. It's cryptographic (non-repudiable) evidence that a real, authorized person is behind each action, human or not.
- Inferred intent is a probabilistic guess about what a user or an agent meant, produced by a learning model watching behavior and context.
| Keystrike Proven Intent | Legacy approach Inferred Intent | |
|---|---|---|
| Basis | Cryptographic binding to the authorized person's input; device-bound evidence in supported contexts. | Behavioral and contextual signals. |
| The question it answers | Is this action, command, or prompt cryptographically bound to the authorized person's input? | Does this action look expected, normal, or acceptably low-risk? |
| Nature of the signal | Cryptographic evidence, not a behavioral estimate. | Probabilistic and risk-scored. |
| Enforcement | Block interactions and actions without Proven Intent; apply connection control where supported. | Alert, challenge, allow, or deny based on score and policy. |
| Evidence produced | Signed, tamper-evident, non-repudiable evidence from governed actions. | Events, decision logs, risk scores, and behavioral context. |
Keystrike mitigates the risks that ride authorized access
Prompt-injected agents are covered via the AI-agent early-access program. See the Platform →
How Keystrike completes
the security stack
Keystrike completes traditional security solutions by giving them the ground truth and session-level verification they were not built to provide.
| Tool | Gap for remote access | Keystrike fills | Why it works |
|---|---|---|---|
| PAM | Credentials managed, not continuously verified |
CONTROL: Cryptographic attestation beyond credential checkout. SEE: Live map surfaces all access paths outside PAM scope. |
PAM controls the vault. Keystrike verifies who controls every command inside the session and maps every access path your PAM doesn't manage. |
| IGA / MFA | Lifecycle focus; slow to detect privilege abuse |
SEE: Live map detects misuse across active sessions. CONTROL: Attestation blocks unauthorized commands in real time. |
IGA manages entitlements. Keystrike shows when those entitlements are being misused live and stops the damage before it occurs. |
| SIEM | Log aggregation; delayed alerts on past events |
SEE: Live topology as a new data source. PROVE: Every action inside the session is verified and enforced. |
SIEM correlates events after the fact. Keystrike feeds it binary cryptographic signals and live topology data that make every alert more accurate. |
| ZTNA | Verifies access at connection; cannot see inside the session |
SEE: Maps lateral movement inside the trusted perimeter. CONTROL: Extends continuous verification to command execution. |
ZTNA controls the door. Keystrike verifies every action taken inside the room and maps everything ZTNA can't see. |