85.1% agentic threat detection
across 10 attack categories. 510 tests passing.
47 real attack payloads tested against
api.intercis.io
— credential exfiltration, data exfiltration, encoded commands, supply chain attacks, container escape, persistence, and more. Zero code changes. The deny list has since grown to 110 patterns across 17 threat categories, including the July 2026 Windows and PowerShell set.
Payload benchmark run April 8, 2026. Suite and deny-list counts updated August 2026 — the full test suite (proxy, tenant isolation, and security boundaries) passes at 510.
2-minute security validation · 47 attack payloads · 10 threat categories · api.intercis.io · April 8, 2026
✓ Functional checks 510 tests passing
Latency benchmark
Cross-continental test: client in US East Coast, proxy in Railway europe-west4. Co-located overhead expected: 50–150ms.
What this validates
The agent SDK client was pointed at api.intercis.io instead of api.anthropic.com. No other changes to the agent codebase.
The rm -rf tool call was blocked before the agent received it — at intercept time, not after execution.
Events are written to an append-only Supabase table by the proxy. The agent process has no write access.
The bash tool was not blanket-blocked. Only commands matching the shell-rm policy were denied. Safe calls passed through unchanged.
Reproduce it yourself
Test scripts at
demo/smoke_test.py,
demo/agent_test.py,
demo/bench_latency.py.
INTERCIS_PROXY_KEY is your tenant access key (ik_live_…) —
generate one self-serve at
dashboard.intercis.io
(Settings → API Keys, or the onboarding wizard).
Ready to run this on your agents?
Design partner slots are available. One endpoint change, full governance layer, live in under 10 minutes.
Become a design partnerOr email: sales@intercis.io