Product

Every connection gets an identity. Every identity gets a ledger.

Three products on one certificate-based zero-trust fabric — connectivity, DNS defense, and AI-agent security.

Broker

Zero-trust connectivity

Identity-based software-defined connectivity. Users and devices connect point-to-point to exactly the service they’re authorized for — the rest of the network is invisible. No VPN, no exposed attack surface, no extra client hardware.

  • Single admin console: global, real-time view of every connection with point-and-click grants
  • Distributed management — a plant manager can grant access to their own services, no IT ticket
  • Native MFA: mutual-TLS certificate plus password, no additional software
  • Point-to-point SSH to switches, routers, and IoT without full network exposure
Talk to an expert

Admin console — live connections

vendor-tech-04 → WTP-PLC-2
mTLS · active 12m
branch-ops → ATM-cluster-7
mTLS · active 3m
contractor-11 → HVAC-BMS
pending grant
unknown-device → *
denied · no cert

audit → syslog · who what when where why

Bouncer

DNS security

Encrypted DNS that checks every lookup against live threat intelligence, per identity. Ransomware callbacks, newly-registered domains, and command-and-control traffic die at the resolver — before a connection ever opens.

  • DNS-over-HTTPS with mutual-TLS client identity — policy follows the certificate, not the IP
  • Live entitlement checks: access ends the moment a subscription or grant does
  • Attach to any Broker or Bursar deployment today — standalone edition on the roadmap
Add Bouncer

DNS resolver — last 60 seconds

api.github.com
resolved
cdn.vendor-portal.net
resolved
x9f-payload.ru
blocked · NRD
c2.darkrelay.io
blocked · C2

DNS-over-HTTPS · per-identity policy · fail-closed

Bursar

AI agent security

AI agents now hold credentials, call tools, and touch production data. Bursar is the keeper of the keys: it issues each agent a cryptographic identity, brokers every access request, and keeps an immutable ledger of what happened.

$ claude mcp add bursar -- npx -y @blacksandscyber/mcp-server-bursar