Product
Every connection gets an identity. Every identity gets a ledger.
Three products on one certificate-based zero-trust fabric — connectivity, DNS defense, and AI-agent security.
Broker
Zero-trust connectivity
Identity-based software-defined connectivity. Users and devices connect point-to-point to exactly the service they’re authorized for — the rest of the network is invisible. No VPN, no exposed attack surface, no extra client hardware.
- Single admin console: global, real-time view of every connection with point-and-click grants
- Distributed management — a plant manager can grant access to their own services, no IT ticket
- Native MFA: mutual-TLS certificate plus password, no additional software
- Point-to-point SSH to switches, routers, and IoT without full network exposure
Admin console — live connections
audit → syslog · who what when where why
Bouncer
DNS security
Encrypted DNS that checks every lookup against live threat intelligence, per identity. Ransomware callbacks, newly-registered domains, and command-and-control traffic die at the resolver — before a connection ever opens.
- DNS-over-HTTPS with mutual-TLS client identity — policy follows the certificate, not the IP
- Live entitlement checks: access ends the moment a subscription or grant does
- Attach to any Broker or Bursar deployment today — standalone edition on the roadmap
DNS resolver — last 60 seconds
DNS-over-HTTPS · per-identity policy · fail-closed
Bursar
AI agent security
AI agents now hold credentials, call tools, and touch production data. Bursar is the keeper of the keys: it issues each agent a cryptographic identity, brokers every access request, and keeps an immutable ledger of what happened.
$ claude mcp add bursar -- npx -y @blacksandscyber/mcp-server-bursar