Control & proof plane · operational

Security that proves itself.

Naos brings your AI agents under control and turns every action — and every incident across your estate — into evidence you can hand to a regulator, an insurer, or an auditor. Not one more alert in the pile.

01 Observe
02 Detect
03 Stop
04 Prove
Mapped to the frameworks your auditors already use
EU AI ActMITRE ATT&CKNIST CSFISO 27001SOC 2GDPREBIOS RM

Most tools tell you what happened. Naos lets you prove it — without asking anyone to take your word for it.

01 — The platform

One instrument. Three jobs.

The point is control over your AI agents — and proof that holds up afterwards. Detection feeds it, mapped to the techniques and frameworks your auditors already use. Honest about what it does and doesn't do.

In plain terms — Naos watches your systems and your AI agents, flags the attacks that matter, and produces a record of what happened that anyone can verify. Deploys as SaaS or self-hosted; ingests logs, endpoints, network and AI-agent telemetry via connectors.

Crow · detection engine
Detect · Crow

Find the chain, not just the event.

Real-time correlation across logs, endpoints and network. Every rule is tied to a known adversary technique, so a detection means something — and coverage is measured per technique, not asserted. Runs on its own, or alongside the SIEM you already have — Sentinel, Splunk, Elastic.

137 high-fidelity rules· mapped to MITRE ATT&CK· signal, not thousands of noisy alerts
Govern · Prism

Bring your AI agents under control.

Inventory every Copilot, ChatGPT and Claude agent, set policy, and hold a full signed record of what each did — separating what you observed from what you enforced. For agents routed through the Naos gateway (MCP), a tool-call is blocked before it runs; for the SaaS agents, inline enforcement rolls out provider by provider.

M365 Copilot·ChatGPT Enterprise·Claude Enterprise
naos — prism · agent inventory · Copilot / ChatGPT / Claude
Naos Prism agent inventory: Copilot, ChatGPT and Claude agents with risk scores, framework and kill-switch controls
02 — The difference

When it matters, you hand over proof — not a story.

A breach review. An insurance claim. A regulator saying “show me.” Most tools give you logs and hope. Naos gives you a record the other side can verify for themselves.

  • Independently verifiable. The recipient confirms it without trusting your word — or ours.
  • Tamper-evident & time-anchored. If a single byte changed, verification fails.
  • Honest by design. Naos records what it observed and what it enforced, separately.
eu-ai-act-report.pdf — signature valid
reportEU AI Act · control evidence
period2026-07-05 → 08-04
agents monitored1
high-severity events0
integritytime-anchored · verified
Verified · independently checkable
We don't pretend to stop every attack. Naos maps adversary behaviour to known techniques, measures coverage, detects chains, stops what it reversibly can — and is explicit about what it enforced in real time versus after the fact. It proves what happened, including what wasn't covered.
How the proof holds up
  1. 01Signedevery record is cryptographically signed at the source.
  2. 02Time-anchoredstamped against an independent authority — no quiet backdating.
  3. 03Verified offlinethe recipient checks it themselves, with a tool you don't control.
Don't trust us — check it yourself

The receipt, in your hands. Verify it offline.

When a client's AI goes sideways, this is what covers you. Download a real signed record and open the verifier — it runs entirely in your browser and never talks to us. Change a single byte and it fails.

Illustrative sample, not a real customer. It proves integrity, authorship by this key, and an independent RFC 3161 timestamp. It does not yet prove the key's real-world identity — that comes with a published production key and a qualified timestamp.

✓ VERIFIED · offline
Signed at the source — Ed25519
Independently time-anchored — RFC 3161
Tamper-evident — one byte changes, it fails
Checked with a public key — no secret needed
— Live product

Real screens. Not mockups.

Executive & readiness view from the running build — client readiness, operator readiness, and the evidence posture you present to a buyer or an auditor.
naos — executive overview · readiness command
Naos executive overview: client readiness, operator readiness and compliance evidence posture
For MSPs & MSSPs
03 — For MSPs & MSSPs

Say yes to your clients' AI — and keep the receipts.

Your clients want Copilot, ChatGPT and Claude. Say no and they find an MSP who won't gatekeep; say yes and you own the liability when it goes sideways. Naos lets you say yes safely — set the guardrails, keep a signed, verifiable record of what every agent did — under your own brand, as Managed AI. Multi-tenant, one console across your whole book.

Isolation
Multi-tenant

One console, every client. Enforced at the database, not just the UI.

Brand
White-label

Your portal, your reports, your Managed AI offer. Naos stays under the hood.

Price
~€500/mo

Built for the mid-market you serve — not enterprise-only.

Liability
Covered

When a client's AI goes sideways, hand them — or their lawyer — a signed record that holds. Your defense, and a reason to renew.

04 — Why now

The AI Act is turning AI governance into an evidence problem.

From August 2026 the rules start to bite, and the direction is clear: regulators, insurers and auditors increasingly want to see how your AI is governed — records, not reassurances. Naos was built for exactly that.

02 AUG2026 · enforcement
05 — Request access

See what Naos proves in your environment.

A short, technical walkthrough on your own data — no slideware. Bring your hardest “show me it actually works” question.

Built in Europe by a security engineer, MSP-first — early, and honest about it. Design partners & investors: reach the founder directly →

06 — FAQ

Questions, answered plainly.

What Naos is, who it's for, and how it fits the AI era — no jargon, no hedging.

What is Naos?

Naos is a security control and proof plane for the AI era. It watches what your infrastructure and your AI agents do, catches what matters, can stop risky actions, and turns events into a verifiable record — so you can show, not just claim, that your systems are under control.

What is a control & proof plane?

It's a single layer across your security operations and your AI-agent activity. Control means you set policy: for agents routed through Naos, unwanted tool-calls are blocked before they run; for SaaS agents like Copilot, ChatGPT and Claude, Naos detects and records what they did. Proof means the relevant events are recorded in a form you can hand to a regulator, an auditor or an insurer. Naos brings SIEM detection, AI-agent governance and evidence together.

Who is Naos for?

Naos is built MSP-first, for European SMBs. Managed service providers run it multi-tenant, under their own brand, across their whole client book. It also fits security teams that need to govern AI agents and demonstrate control.

How does Naos relate to the EU AI Act?

The EU AI Act pushes organisations to show — not merely assert — how their AI systems are governed. Naos records what your AI agents did, whether they were allowed to, and keeps a verifiable trail that supports accountability. Naos is a tooling layer; it doesn't replace your own legal compliance assessment.

Does Naos cover infrastructure or AI agents?

Both. On infrastructure, it's detection and response across logs, endpoints and network — a SIEM. On AI, it inventories your agents such as Copilot, ChatGPT and Claude, applies policy, and separates what you observed from what you enforced. Agents routed through the Naos gateway (MCP) are blocked inline before a tool runs; inline enforcement for the SaaS agents rolls out provider by provider.

How does Naos deploy, and where does it sit?

Naos runs as SaaS or self-hosted, with database-level multi-tenant isolation for MSP use. It takes in your logs, endpoints and network — and your AI-agent activity — through connectors for cloud, identity and SIEM sources and the major AI providers. For agents routed through its gateway, Naos sits in the path of their tool calls, so a policy can allow, flag or block an action before it runs. For SaaS agents like Copilot, ChatGPT and Claude, it reads the providers' compliance logs to detect and evidence what they did, so you can act in the provider's console. Everything relevant becomes a verifiable record you can hand to an auditor.