# Hanzo for cybersecurity — Hanzo AI

> Put agents on the queue — the triage, the investigation, the fix — on a platform whose own controls are written down mechanism by mechanism, with every agent action in the audit trail.

Solutions · Industries

# Hanzo for cybersecurity

Put agents on the queue — the triage, the investigation, the fix — on a platform whose own controls are written down mechanism by mechanism, with every agent action in the audit trail.

[Try Hanzo](https://hanzo.build)[Contact sales](https://hanzo.ai/contact-sales)

## What it does for you

Triage with the evidence attached

An agent reads the alert, pulls the related traces and logs, and writes up what happened with a link to every line it relied on. The analyst decides; the agent gathers.

From advisory to pull request

Hand a bot the CVE and the repository. It finds the affected code, makes the change, runs the tests and opens a pull request for review.

Reproduce it somewhere else

Run a proof of concept or open a suspicious file in a leased sandbox, a separate computer for the organization, and read the exit code, stdout and stderr back.

Guard the model boundary

Guard reads prompts on the way in for injection and pasted secrets, and replies on the way out for leaks — as a proxy, a CLI wrapper or a filter in front of an MCP server.

Identity your review can press on

PKCE with S256 only, argon2id password hashes, single-use refresh tokens that revoke their whole family on replay, and SCIM from your directory.

## What it runs on

The products underneath, on one account, one key and one bill.

[Hanzo GuardCatches prompt injection and pasted secrets going in, and leaks coming out.](https://hanzo.ai/guard)[Hanzo O11yTraces, metrics, logs and profiles in one place.](https://hanzo.ai/o11y)[Hanzo BotA teammate with its own computer that signs in to your tools and reports back.](https://hanzo.ai/bot)[MachinesSandboxes, metered machines and functions, each the organization’s own.](https://hanzo.ai/products/machines)[Hanzo IAMSign-in through your identity provider, SCIM provisioning and org-scoped roles.](https://hanzo.ai/iam)[Hanzo KMSSecrets held per organization, never in the code that uses them.](https://hanzo.ai/kms)

## Security and compliance

Controls you can read

The trust page describes each mechanism as the code implements it: sign-in, token verification, tenancy, the audit trail and key custody — including what is not built yet.

Frameworks

Our controls are built to be compatible with SOC 2 and audited internally, continually. The audit report is available on request.

Or keep it inside

The platform is open source and runs in your cloud, on your own hardware, or air-gapped, with Zen weights served on machines you control. Then nothing reaches us.

[How the controls work](https://hanzo.ai/trust)[Terms and data processing](https://hanzo.ai/legal)

## More industries

[Financial services](https://hanzo.ai/solutions/financial-services)[Healthcare](https://hanzo.ai/solutions/healthcare)[Law](https://hanzo.ai/solutions/law)[Retail](https://hanzo.ai/solutions/retail)[Government](https://hanzo.ai/solutions/government)[Education](https://hanzo.ai/solutions/education)[All solutions](https://hanzo.ai/solutions)

## Put it to work

Start in the builder today, or talk to us about your organization.

[Try Hanzo](https://hanzo.build)[Contact sales](https://hanzo.ai/contact-sales)
