# Customer Deck: SealGate > Text mirror of the SealGate slide deck, generated from source for AI agents and readers who can't run the interactive deck. Slides are visual; this is their copy, in order. Regenerate with deck-assets/scripts/extract-deck-content.mjs. ## 1. Title - Reduce runtime risk of AI agents - Own & govern how agents touch your data, reduce risk, onboard & deploy agents faster - University of Oxford - Wayve - Citadel Securities - VMware - Synopsys Images: SealGate ## 2. Team - TEAM - Applying AI, Cyber, Infra experience from… - Previously built GPU-EVM: fastest VM execution in the world by 200x, via parallelization across 10,000 GPU cores. - Eito Miyamura - CEO / Member of Technical Staff - CS @ Oxford - Ilia Manolov - Member of Technical Staff - Dimitrios Karkoulis - Senior Engineer · 20+ yrs - University of Oxford - Wayve - Citadel Securities - VMware - Synopsys - LinkedIn Images: Oxford ## 3. Agent Bypass - PROBLEM - AI agents are already non-human actors inside your company, accessing data, calling tools, and taking action - Agentic AI breaks traditional data security: overprivileged, sprawling everywhere (shadow AI/connectors), no ownership, no activity trail, no unified controls. ## 4. Known Incidents - Track Record - Agents are already leaking data, causing havoc - Same root cause every time: an overprivileged agent, exposed to untrusted input, with a way to send data out. Researchers call it the lethal trifecta. - Read more - ChatGPT - Apr 2023 - Google Bard - Nov 2023 - GitHub Copilot - Jun 2024 - Microsoft Copilot - Aug 2024 - Slack AI - ChatGPT Operator - Feb 2025 - M365 Copilot - Jun 2025 - EchoLeak - ChatGPT Deep Research - Sep 2025 - ShadowLeak - Notion AI - Jan 2026 - Claude Cowork - agents.fail - Simon Willison - The Economist Sources: https://simonwillison.net/2023/Apr/14/new-prompt-injection-attack-on-chatgpt-web-version-markdown-imag/ , https://simonwillison.net/2023/Nov/4/hacking-google-bard-from-prompt-injection-to-data-exfiltration/ , https://simonwillison.net/2024/Jun/16/github-copilot-chat-prompt-injection/ , https://simonwillison.net/2024/Aug/14/living-off-microsoft-copilot/ , https://simonwillison.net/2024/Aug/20/data-exfiltration-from-slack-ai/ , https://simonwillison.net/2025/Feb/17/chatgpt-operator-prompt-injection/ , https://www.hackthebox.com/blog/cve-2025-32711-echoleak-copilot-vulnerability , https://thehackernews.com/2025/09/shadowleak-zero-click-flaw-leaks-gmail.html , https://breached.company/the-lethal-trifecta-strikes-four-major-ai-agent-vulnerabilities-in-five-days/ , https://agents.fail , https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/ , https://www.economist.com/leaders/2025/09/25/how-to-stop-ais-lethal-trifecta ## 5. Three Bad Options - ) : img ? ( - ) : bare ? ( IconCmp ? - : null ) : ( - Block Everything - AI policy: ask again in Q3 - Shadow agents spin up anyway, off the books. - Slack - GitHub - Outlook - Allow Everything - An agent just approved its own PR and merged to main - No guardrails, no accountability when it goes wrong. - Build it Yourself - 8 months in. Still no audit logs. - Retrofitted governance never catches up to the agents. - In your org, unmanaged - Running on personal keys, no audit trail, zero visibility - Which leaves you three bad options. ## 6. Agent Sprawl (Chaos) - Does your AI deployment look like this, creating risk? - Employees - Gemini - Internal Bot - Cursor - Claude - Engineering - Copilot - Codex - HR - Finance - IT ## 7. Agent Sprawl (SealGate) - SealGate unifies agent runtime control under one pane - Every agent routes through a single gateway with unified RBAC, audit logging, and kill switch - Employees - Gemini - Bot - Cursor - Claude - Engineering - Copilot - Codex - HR - Finance - IT ## 8. Product Screenshots - Session monitoring: metadata only, payloads never stored - The product - One pane, in practice Images: SealGate session monitoring: tool calls with status and data-access class ## 9. Stack Integration - Policy - tells the business what agents should do. - Runtime control - shows and enforces what they actually do. - AI governance - Policy · GRC · approved use cases - Your AI agents & copilots - Agent access - Tool use - Data movement - Runtime activity - in - out - Live - Planned - IAM - Identity in - SOC - Audit logs out - GRC - Compliance evidence - DLP - Egress signals - Where we fit - SealGate plugs into your stack, it doesn't replace it - policy in - every agent routes through - M4 6l5 -4l5 4 - M4 16l5 4l5 -4 Images: SealGate ## 10. Differentiation - Tool-level - Least privilege - Reduce blast radius - Deterministic enforcement - Why SealGate is different - Stop trading autonomy for security - Full autonomy has no guardrails. Gating every action brings approval fatigue. Network DLP can't parse agent tool calls. SealGate tunes how accurately each tool call is approved or blocked, so you choose your point on a better frontier. ## 11. The SealGate Effect - The SealGate Effect - Security that ships agents faster - What your security team, board, and auditors get. - Ship, don't stall - Agents reach production, with security's sign-off - Blocked in review → in production - Incident response - Lower MTTR - Weeks → minutes - Agent lifecycle - Onboard & offboard in minutes - Provision & revoke instantly - Visibility - Shadow tools surfaced - Shadow AI → inventoried - Interoperability - Any model, any agent - Swap agents, keep your tools ## 12. Agent Inventory Questions - SealGate lets you answer these Qs about agents - The questions a CISO should be able to ask about every agent, on demand - One pane. Every answer. - Answered on demand - Who owns it? - Ownership - What can it access? - Access - What tools can it use? - Tools - Whose authority is it acting under? - Authority - What changed its behaviour? - Drift ## 13. Proxy / Egress Boundary - quarantine daemon - Appendix - Server inventory & auto-quarantine - SOLUTION - SealGate controls how agents access your data - Secures and unifies agent data access. Stop data leaks before they happen for any agent, on any device. Images: SealGate server inventory with auto-quarantine and access control Sources: https://docs.sealgate.ai/en/docs/admin-guide/mcp-quarantine ## 14. Security - Credential encryption - Zero-knowledge: encrypted client-side and at rest. SealGate never sees raw secrets. - Flexible on-prem deployment - Self-hosted inside your boundary, or SealGate Cloud. Sensitive traffic never has to leave. - Deterministic enforcement - Blocked at the point of action, before it runs. Not flagged after the fact. - Metadata-only audit trail - Generated as agents act, available on demand. Who called what, when, allowed or blocked. Payloads never stored; streams to your SIEM. - Org-wide RBAC - Least-privilege tool access per user, group, and agent. - Kill switch - Cut any agent's access org-wide, instantly. - Security - Built to sit in your critical path - The controls you'd expect from something every agent routes through. ## 15. Where We Are - Scope - We govern agents that reach data through MCP connectors, deterministically. Direct API calls and raw shell don't route through us yet. - Why partner now - You shape our roadmap - Your gaps become our next quarter. - Direct line to founder & founding team - No support tiers. You talk to the people writing the code. - Runs in your boundary - Self-hosted deployment. - Where we are - Narrow today. Your roadmap tomorrow. ## 16. Agent Coverage - On your devices - Vendor-hosted (cloud) - Live = covered by end-to-end tests. Beta = supported, less coverage. New clients land as fast as they ship an MCP config. - Live - Beta - Claude Code - Cursor (incl. plugins) - VS Code / Copilot - Codex CLI - Claude Desktop / Cowork - Windsurf · Zed · JetBrains - Devin CLI - ChatGPT / Gemini (web) - M365 Copilot - Slack AI · Devin web - MCP tool calls - Shadow-MCP enforcement - Raw CLI / shell - Coverage - Which agents SealGate governs today - What we govern today, agent by agent. ## 17. CTA - Your agents are loose in your org right now - Deploy SealGate in minutes. Full visibility, deterministic policy enforcement, zero trust for AI agents. - Book a demo Sources: https://cal.com/eito80/demo ## 18. Discovery - New extension caught on the device: add to SealGate, or it stays quarantined - SOLUTION - Shadow MCP Discovery - MCP (Model Context Protocol) is the standard way agents connect to tools and data. SealGate sweeps each client config and inventories every MCP connector, each with an allow / block verdict. Images: SealGate dialog: new AI extension detected, add to SealGate or auto-quarantined ## 19. Quarantine - Admin overview: quarantined server awaiting approve / reject - SOLUTION - Automatic Quarantine - Rogue MCP servers detected and quarantined before they can exfiltrate data Images: SealGate admin overview: quarantine request pending approve or reject ## 20. Org MCP Push - The employee's view: org-approved servers, ready to use - SOLUTION - Org-Wide MCP Deployment - Admins toggle approved MCP servers in the gateway. Every employee laptop gets them instantly. Images: SealGate My MCPs: the employee's view of org-approved servers, ready to use ## 21. User Accountability - SOLUTION - User Accountability - Auto-deny risky actions or route approvals to the responsible human. Every agent action has an accountable owner. ## 22. Desktop Install - Every AI client on the device, detected & connected - SOLUTION - Frictionless Desktop Install - One-click install, guided setup wizard. Agents are protected in under a minute. Images: SealGate desktop app with every AI client on the machine connected ## 23. Prompt Injection - THREAT - The Lethal Trifecta - AI agents with data access + untrusted content + external comms = data exfiltration ## 24. Trifecta Defense - The gated call: egress held for approval, auto-denied on timeout - SOLUTION - Trifecta Defense - Without SealGate, a poisoned email exfiltrates data. With SealGate, the leak is blocked. Images: SealGate approval dialog blocking an email send after the agent handled secret data ## 25. Emerging Threats - Threat Landscape - Security threats are emerging already - Not lab hypotheticals. These are working exploits against real, shipping AI products - demonstrated publicly by our founder, and going viral because the attacks actually land. - tweet - linkedin - On X · 1.5M views - Perplexity Comet's AI Agent just bankrupted your company - Eito Miyamura - On LinkedIn · 1,265 reactions - Clawdbot just injected malware into your code - Eito Miyamura - On LinkedIn · 928 reactions - Real, shipping products - Zero-click data exfiltration - Prompt injection in the wild - Happening right now - dark ## 26. Threat Videos - Threat Landscape - See the attacks in action - Recorded exploit demos against real, shipping AI products. - Coming soon - youtube - link - placeholder - SpXUPto90IA - On YouTube - accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture ## 27. Further Reading - Appendix - Further Reading - blog - notebook - Agentic AI Disrupts Traditional Data Security - 3 min - Interactive visual - Blog post Sources: https://edisonwatch.substack.com/p/agentic-ai-disrupts-traditional-data ## 28. Appendix - Appendix