Documentation

The agent

One static binary, reporting every minute, verified by signature.

Identity

Binary
security-agent, a statically linked Rust binary of a few megabytes
Service
secai-agent
Runs as
root
Reports
Every 60 seconds: metrics, security events, inventory, findings and posture. Commands from the platform are fetched on the same cadence.
Version
security-agent --version; shown per server in the dashboard

Updates

The agent checks for a release once at start and about every 24 hours (plus or minus an hour). It downloads a manifest and binary, verifies size, SHA-256 and the Ed25519 signature with the key compiled into it, installs atomically and exits so systemd restarts it on the new version. The previous binary stays at /usr/local/bin/security-agent.prev. A failed check is retried after 2, 5 and 15 minutes. Releases go to a canary channel, which includes SecAI's own production server, before stable.

Commands

The agent only executes commands that arrive as envelopes signed by the platform (Ed25519) and verified locally; a replayed or altered command is dropped. What a command may do is bounded by the action policy: see Automatic mode and Approval mode.

Survival

A systemd drop-in keeps the agent out of the OOM killer's way. While the server is being exhausted or cannot reach SecAI, the agent records per-second kernel counters and, if the server is set to Protect, may cap, throttle or freeze the one process group responsible or drop a flooding source, and undoes it when the episode ends. Every server starts at Record only, which acts on nothing.

Reviewed against the implementation on 2026-09-20. Something wrong? Tell us.

Trust Center