Tokynd Security

Every machine identity, governed.

AI security colleagues that review agent code, fix what they find, and prove it closed.

Fix-firstFindings arrive as merge-ready patches, not tickets.
No rip-and-replaceWorks with the scanners you already trust.
Human-gatedAgents propose. People approve. Always.
Where we are: all 9 named suite products have working local code, file-in/file-out, no network, credentials, model calls, or real PRs. Repo v0.4.0 · 61 tests · 2c24c63. Hosted product and live runtime sensing remain design-partner roadmap. No customer logos, performance claims, or GA language here.
sample/support-agent · PR #482 tokynd-agent
Finding Simulated demo
High mcp/tools.json · server: crm-lookup

MCP tool granted write scope it never uses

Fix proposed pair-output/fix-482 · 2 files changed
Tests 41 passed Spec check v3 Human gate approval required

Patch approved: local patch approved; simulated merge event recorded. No repository contacted.

Identity re-issued: long-lived key retired; scoped 15-minute token provisioned by Tokynd Birthright.

Finding re-verified: exposure closed on rescan. Evidence written back to the source.

Control evidence logged: SOC 2 CC6.1 / ISO 42001 A.6 evidence pack updated automatically.

Controls mapped to
SOC 2ISO/IEC 42001NIST AI RMFEU AI ActOWASP LLM & MCP Top 10CIS Benchmarks

AI crossed from assistant to operator.

Agents now move money, touch customer data, and change production systems. The security model has to govern the identity making the move, not just the traffic around it.

01

Tokens are minted without kinds.

Every non-human identity is a token. Without a named owner, scoped permissions, and an expiry, that token outlives the project it was created for, with permissions nobody remembers granting.

Identity must be born with the agent.
02

Findings arrive without fixes.

Scanners enumerate; tickets accumulate. Injection paths, over-scoped tools, and drift sit in queues while the same reachable weakness survives another quarter.

Every finding needs an owner and a fix loop.
One cause
Agents act without governed identity and without a fix loop.

Tokynd Security closes both: Tokynd Birthright provisions identity at creation, then the platform runs see, fix, govern, prove across every action.

Four operating pillars.

Nine products work as one colleague system. Each pillar has one operational job, one human gate, and one place in the loop.

SEE

Every action, visible in context.

Tokynd Winnow turns scanner noise into one owned queue. Tokynd Pulse learns the deterministic baseline and surfaces deviations.

See it
FIX

Security that arrives as help.

Tokynd Pair produces the smallest reviewable patch, tests it locally, drafts the PR body, and waits for a human.

See it
GOVERN

Every token has a kind, owner, and boundary.

Tokynd Attavard tiers and maps. Tokynd Birthright creates the identity record. Tokynd Vestibule reviews MCP permissions. Tokynd Sparring exercises adversarial configurations.

See it
PROVE

Evidence generated by remediation.

Tokynd Dossier packages the approved fix and verified rescan. Tokynd Asbuilt compares architecture intent with deployed reality.

See it
The lineup

Nine products. One Assurance Graph.

Every product reads from and writes to the Tokynd Assurance Graph. Status labels stay literal: Now · local v0 runs as a deterministic local simulation, Design Partner builds with partners. Nothing here is quietly GA.

Security review that ends in a merge-ready patch, not another ticket.

Failure prevented

Agent changes merging with over-scoped tools, prompt-injection surface, and RAG permission bleed, found by an auditor or an incident instead of a reviewer.

Capabilities
  • Reviews agent code, MCP configs, prompts, and RAG in the PR
  • Generates the validated fix diff and PR body (v0, local)
  • Secrets and NHI-in-code checks folded into every review
Human gate

The agent owner merges. Tokynd Pair never merges, deploys, or widens its own access.

Five scanners, one weakness, one owner, one fix.

Failure prevented

The same CVE paged by three scanners under three IDs, owned by nobody, ageing past fix SLAs.

Capabilities
  • File-ingest v0: SARIF, Dependabot-style, and Trivy-style reports normalized
  • Dedupe, reachability ranking, and owner routing
  • Verified closure propagated back to every source (roadmap connectors)
Human gate

AppSec approves merges of critical duplicates. Suppression reasons stay auditable.

Every MCP server reviewed like code, before it holds production scope.

Failure prevented

An MCP server quietly holding write and delete scope it never calls: the standing privilege a steered prompt turns into data loss.

Capabilities
  • Static MCP manifest scan, rules TK-MCP-001 through 009 (local v0)
  • Risk score and safer-manifest diff per scan
  • Sample: over-scoped manifest yields 7 findings; least-privilege verifies clean
Human gate

Security approves every new server and every scope widening.

Identity at creation, not discovered after the incident.

Failure prevented

Ownerless agents running on long-lived keys nobody can revoke safely, because nobody recorded what they were for.

Capabilities
  • Birth Certificate JSON and Markdown: owner fail-closed, expiry and rotation, provenance hash (local v0)
  • Orphan and over-scope detection against the registry
  • Just-in-time credential issuance remains roadmap
Human gate

Named owner approves scopes. Revocation never waits for a gate. Missing owner fails closed.

AI governance that produces remediation.

Failure prevented

Governance theater: polished registers and heat maps while the same reachable weakness survives another quarter.

Capabilities
  • Attavard lite: tiering for sample systems (local v0)
  • Starter crosswalk across SOC 2, ISO 42001, NIST AI RMF, EU AI Act
  • Screening heuristics, plainly labeled as heuristics
Human gate

Named risk owner approves every tier. GRC approves every external answer.

Your diagram is the hypothesis. The API is the evidence.

Failure prevented

Architecture risk hiding in the distance between approved design and deployed reality: stray keys, public ACLs, shadow resources.

Capabilities
  • Designed-versus-deployed drift checks DR-001 through 010 (local v0)
  • Gap register with deterministic exit codes
  • Golden test: planted drifts found exactly
Human gate

Architecture confirms intent sources. Owners accept, fix, or time-box risk acceptance.

One approved fix testifies four times.

Failure prevented

Audit-season archaeology: reconstructing March in November from tickets and memory, four frameworks collected four times.

Capabilities
  • Auditor pack export: manifest, findings, controls, evidence (local v0)
  • Starter-mapping disclaimer in every export: a mapping, never a certification
  • Questionnaire answers cited to artifacts (roadmap)
Human gate

GRC reviews exceptions and approves the pack before any auditor sees it.

Know the normal path. Surface the meaningful deviation.

Failure prevented

An agent leaving its known tool path, reaching an unknown tool, or following an exfiltration instruction with no explainable deviation record.

Capabilities
  • Deterministic baseline learned from a training trace, rules TK-RG-001 through 007
  • Attack sample: deviations found and denied by policy
  • Normal sample: zero deviations, policy allows
Scope today

Local trace simulation only. No live sensor, network, credentials, or latency claims.

Exercise the agent configuration before an attacker does.

Failure prevented

A vulnerable agent configuration reaching production with nobody having exercised its instructions, tools, scopes, and exfiltration paths together.

Capabilities
  • Probes RT-P01 through P06: direct and indirect injection, tool-description poisoning, MCP overreach, exfiltration instruction, hygiene
  • Vulnerable fixture fails every probe; hardened fixture passes
  • Findings enter a screening-heuristics risk register
Scope today

Deterministic local configuration checks only. No model queries.

Identity, minted at birth.

Tokynd Birthright gives every agent a birth certificate: a named owner, scoped tools, an expiry, and a kill switch. Missing owner fails closed. Try it: mint a record and watch the kind attach to the token.

This is a local simulation of the v0 record format. No credential is issued, no network is touched.

Proof without theater.

No invented customer wall, no anonymous praise, no borrowed certification badge. Tokynd Security earns proof from reproducible artifacts and design partners willing to judge the fix.

01

Design-partner program

One repo, one scanner export, one named security and engineering owner. The pilot is measured on accepted patches and verified closures, not alerts generated.

02

Fix-corpus transparency

Finding, proposed patch, human decision, verification result. Internal merge-rate targets stay labeled as targets until they become measured outcomes.

03

Reproducible benchmark plan

A public benchmark repo is planned with planted vulnerable and hardened fixtures and deterministic expected outputs. It is a plan, not a published benchmark today.

04

Changelog in the open

v0.4.0, 61 tests, commit 2c24c63. Every status on this page names what runs locally, what needs a design partner, and what remains roadmap.

0Products with working local code
0Tests passing in the suite repo

Straight answers.

No, deliberately. Tokynd ingests findings from the scanners and CSPM you trust, traces each to the code, IaC, agent, and owner, deduplicates them into one owned queue, drafts the PR-ready diff and PR body, and verifies closure back at the source. Keep your contracts. Tokynd closes the loop your scanners leave open.

Three rules. Agents propose and humans approve. Every action is scoped by the approved spec and a short-lived identity. Every action is logged to your audit trail and mapped to a control. Tokynd can draft a validated fix diff, tests, risk note, spec check, and PR body; merging always stays with the human owner.

The spec, capabilities, tools, data access, identity, and guardrails, is written and approved before code is generated. It becomes the contract every later stage checks against: PR review, identity provisioning, testing, and evidence. Security stops being a review at the end and becomes a property of how the system was built.

Starter mappings cover SOC 2, ISO/IEC 42001, NIST AI RMF, the EU AI Act, OWASP LLM and MCP Top 10, and CIS Benchmarks. One control is tested once and mapped where it honestly applies. Mappings are not certifications or legal determinations.

Not yet. Nine products have working local code in v0.4.0. Hosted connectors, live runtime sensing, and opening real repository PRs remain design-partner roadmap. A working session starts by inventorying agents, MCP servers, and shadow AI, curating one real queue, and drafting the first merge-ready fixes against your stack.

The build focus is AWS and Microsoft Azure, GitHub and GitLab as code systems of record, and Okta and Microsoft Entra ID for identity. Customer code, prompts, tool definitions, and data are tenant-isolated and never train models without explicit opt-in.

Published structure, no invented numbers. Final numbers publish at GA; design partners lock launch pricing. Talk to us and we will walk through what fits your shape.

Tokynd Security: Token + Kind.

Tokynd (pronounced TOH-kind) is Token + Kind. Every non-human identity, a service account, an API key, an agent, a workload, an MCP server, is a token. And every token has a kind: a classification that says who owns it, what it is allowed to do, and how long it is allowed to live.

The fastest-growing attack surface in the enterprise is not malware or phishing. It is machine-identity sprawl: tokens minted without kinds. No owner. No scope. No expiry. Credentials that outlive the projects they were created for, with permissions nobody remembers granting.

Tokynd exists to end that. We govern identity at creation: every agent is born with an identity certificate naming its owner, scope, and lifetime. We enforce least privilege by kind. And we bind every token to a lifetime: credentials that cannot expire are credentials waiting to be stolen.

A token (the ring), governed by its kind (the K), with the identity pinned at the center in amber.

What you will not find here: no shields, no padlocks, no fear. Those symbols sell anxiety. A governed identity is a quiet one.

Contact

Tell us what you need.

Design partner, a question about the build, or a working session. One route in, and a human replies.

Prefer another channel?

Founder on LinkedIn:
linkedin.com/in/amjdseyal

We reply to every message personally, usually within one business day.