Thuban Intelligence

Trust distribution for every Shield instance.

Intelligence informs. Shield enforces.

In plain English: Intelligence is the detection brain. It watches for real, newly-reported AI agent incidents, works out which ones Thuban doesn't yet defend against, and triggers Forge to draft a rule and Crucible to prove it's safe — before that defence reaches your machine.

Get Started Free
KEEP YOUR STACK. ADD THUBAN.

Snyk's CVE feed tells you about known vulnerabilities. Thuban Intelligence tracks emerging AI-agent attack patterns — sandbox escapes, prompt-injection chains, MCP exploits — sourced and trust-tiered before they ever reach a rule.

Get Started Free

Your first 30 days of Thuban Individual is free. No card required, just a valid email address.

Shield — 5 Defence Layers

  • File Guard — pre-emptive snapshots, protected paths, overwrite prevention
  • Shadow Realm — sandboxed execution environment
  • Watchers — real-time filesystem monitoring
  • Execution Gate — command validation before execution
  • Audit & Recovery — hash-chained audit trail, instant rollback

Crucible

  • Adversarial mutation testing
  • Verifies defences catch known attack patterns

Scanner

  • All 69 detection rules
  • 10 language support
  • Hallucinated API detection
  • Dependency analysis
  • Trust Score

Forge

  • Builds defensive rules from real-world incidents
  • 5 signed rule packs shipped

Cost Guard NEW

  • Catches unbounded AI/LLM loops before they run away
  • Flags missing output token limits
  • Runs automatically in every scan — no flag needed

Additional

  • Blackbox explainability engine
  • Intelligence threat analysis
  • 8 Advisor modes (roast, rate, boost, risk, trend, benchmark, onboard, compliance)
  • CLI + MCP integration
  • Works with Claude Code, Codex, Cursor, Gemini CLI, any AI coding agent
  • 100% local — your code never leaves your machine
  • Community support
What It Is

The defence, shared with everyone

When a real AI-agent attack pattern shows up anywhere — a new jailbreak, a new exploit against Claude/Cursor/an MCP server, a runaway-spend incident — Intelligence is what notices it, decides whether Thuban already defends against it, and if not, hands it to Forge to draft a rule. Once that rule is proven safe (Crucible's adversarial testing, Shield's own attack/benign corpus, the full test suite), Intelligence is also what pushes it out — verified, signed, and trusted — to every Shield instance at once, not just yours.

Thuban Shield hardened AI agent protection displayed as a desk plaque

Intelligence informs. Shield enforces.

Why It Matters

Your protection is only as good as your latest rules

A single Shield instance can only see what happens on its own machine. Intelligence ensures every Shield instance has the latest defences the moment they're verified — not weeks later in a scheduled update.

Trusted indicator distribution

Verified indicators of compromise and behavioural rules propagate to every Shield instance across the Thuban ecosystem.

Real-time updates

No manual intervention. Once a rule is signed, it reaches every instance automatically.

Signed rule distribution

Every rule is verified and cryptographically signed before it is deployed to a single Shield instance.

Source Trust Tiers

Not every report is equal

Every signal entering the pipeline is classified before it can influence anything.

TIER 1 · AUTHORITATIVE

Vendor advisories, CVE/NVD, CISA, OWASP.

TIER 2 · REPUTABLE

Established publications, named researchers with evidence.

TIER 3 · UNVERIFIED

Social posts, forums.

Never triggers protection.

Anti-Poisoning

One invented story cannot become a protection rule

A malicious actor should not be able to invent a story and cause Thuban to block legitimate commands across thousands of machines. Confidence, not urgency, decides what ships.

One source
Observe
Multiple sources
Investigate
Vendor advisory
Generate defence
Crucible + Shield + Scanner + Cost Guard all pass
Release
Three Response Levels

Not every threat gets the same response

Confidence determines action. Nothing gets blocked on a hunch.

OBSERVE

Unconfirmed or poorly documented reports: add telemetry, increase logging. Do not block anything.

WARN

Credible but incomplete threats: alert the user, require approval, offer a temporary high-security mode.

BLOCK

Reproducible high-confidence threats: ship signed enforcement rules to every Shield instance immediately.

How It Connects

Part of the full pipeline

Intelligence is the distribution layer of the same pipeline that powers Forge and Crucible — new defences don't help you until they reach your machine.

Shield enforces. Forge learns. Crucible proves. Blackbox explains.

See how Thuban Forge generates candidate defences, how Thuban Crucible proves they hold up under attack, how Thuban Shield enforces them in real time, and how Thuban Blackbox records every outcome.

Want the full picture in one diagram? See the end-to-end pipeline on the Time to Defence page.

Every Shield instance, defended at the same moment.

Intelligence is built into every Thuban plan.

View pricing

New to Thuban? Read the full Getting Started Guide.

Thuban Help
Ask a question or pick a topic below.