meilynx

Capability

Agents and tools, under the same audit chain.

Meilynx traces full agent execution, enforces tool allow/deny at the proxy boundary, detects when agents drift from their approved baseline, and gates high-risk actions behind fresh two-party approval — so every agent action lands in the same examination-ready audit trail as a plain LLM call.

At the boundary

Enforced at the boundary your traffic crosses.

Agentic workloads multiply the number of model calls and tool invocations behind a single user action. Meilynx governs the ones that cross the proxy boundary and records them in the same tamper-evident chain as everything else.

One traced run · one chain

  • user actionsummarize holdingstraced
  • agent · llm callgpt-4o · 2.1k tokensallowed
  • tool · portfolio_readallowlistedallowed
  • tool · send_emailnot on allowlistblocked
  • sub-agent · retry 1same policy, same chainallowed

every step sealed into the same examination-ready audit chain

Tool allow / deny

Permit or block specific tools and MCP calls per policy, at the boundary.

Destructive-command prevention

Stop dangerous tool actions before they execute.

Full-execution tracing

Capture retries, tool calls, and sub-agent invocations as one traced run.

Schema & message limits

Enforce structured-output contracts and cap multi-step message counts.
Drift & approval gates

Agents change. Your baseline notices.

An agent's system prompt and tool grants drift — a new tool appears, a mandate quietly widens. Meilynx detects drift from the approved baseline in observed traffic, flags it for review, and can hold high-risk actions until a second person approves — with grants that expire.

drift → gate → approval · one chain

  • baseline · approved12 approved toolsbaseline
  • tool grant added · wire_transferoutside approved baselinedrift
  • high-risk call · wire_transferheld for approvalgated
  • second approver · grant issuedexpires automaticallyapproved
  • action allowed · recordedsealed to the audit chainsealed

every finding, hold, and approval — attributed and tamper-evident

System-prompt drift

Detected from observed traffic against the approved baseline — a rewritten mandate is flagged for review before it becomes an incident.

Tool-grant drift

A new tool outside the approved set is flagged the moment it appears in traffic.

Two-party approval gates

High-risk tool actions wait for a fresh approval from a second person; grants expire, and the default is fail-closed.

Shadow-first rollout

Drift rules ship in shadow mode — observe findings on real traffic before any enforcement changes behavior.
Examination evidence

Every agent action, examiner-ready.

Traced runs, drift findings, gate holds, and approvals land in the same tamper-evident chain as every other event — and surface in the examination package your compliance team hands over.

In the examination package

The approval-grant lifecycle — who approved what, when, and when it expired — renders as examination evidence alongside the traced run, not as a separate log to reconcile.

Mapped to named controls

Drift and approval-gate rules map to named framework controls — model monitoring under the SR 11-7 lineage, supervisory review under FINRA, change management under SOC 2 — with the same control-to-evidence traceability as every other rule.
Honest scope

What we govern — and what we don't.

A sophisticated evaluator should know exactly where the boundary is. We'd rather earn trust with a scoped answer than lose it to an overclaim.

  • Agent and tool calls that transit the proxy are traced and enforceable.
  • Every governed action lands in the examination-ready audit trail.
  • Drift detection evaluates observed traffic at the data plane, from hashes — raw material never crosses the trust boundary.
  • Drift rules start in shadow mode — observe findings before any enforcement changes behavior.
  • In-tenant MCP routing that never crosses the proxy boundary is not intercepted.

Scope discipline

We claim the boundary-level controls above because they're what ships. When an agent action crosses the proxy, it is governed and recorded; when it doesn't, we say so plainly. We describe what ships as it ships — never before.

Get started

Bring agents into your audit trail

We'll walk through agent tracing, tool allow/deny, and exactly where the boundary sits.