CORPILUS
Coming soon · Qronos

When an AI agent acts on its own, the check has to come before the action

Qronos is a layer that continuously verifies whether an agent is still acting within what you allowed it to do. We're still building it, so don't count on it before it's ready.

Coming soon

Qronos — protection for agents that act on their own

Shield protects the door. Qronos watches what happens behind it.

What Qronos is not
  • It does not handle network attacks or link flooding — that remains the WAF's job.
  • It's not Shield in different packaging: Shield guards an application's entry point, Qronos the behaviour of whoever acts inside it.
  • It's not monitoring. Monitoring records what already happened; Qronos stops the action before it executes.
Direction

Towards extended protection for autonomous agents. This is a direction, not a finished feature — and we'll say it that way even when claiming more would sell better.

Why this is being built

Authorizing an agent once at the start isn't enough

Permission at the start of a task says nothing about where the agent will be several dozen steps later. The problem tends to be the whole, not any single step.

  1. 01
    The agent gets a task
    For example: prepare an overview and send it out. Permission is granted once, at the start.
  2. 02
    It breaks the task into steps
    Read the data, sort it, prepare the messages, send them. Each step looks harmless on its own.
  3. 03
    The last step has a consequence
    Sending hundreds of emails, rewriting records in a system, or a payment. At this point, knowing the agent was authenticated at the start isn't enough.
  4. 04
    This is where Qronos decides
    It decides before such a step runs — by a rule you can point to, and with a record.
Status

Qronos is in development. It isn't part of any plan, it can't be deployed today, and it doesn't appear in any price list. If you're interested, reach out and we'll let you know when it's ready.

More about Qronos

Five things Qronos is built on

Open whatever interests you. We describe design principles, not a finished product.

Confidence at every step an agent takes

Qronos assesses each step on its own, so the agent stays within the limits you gave it.

Qronos assesses every step, tool and document on its own while keeping an eye on where the whole task is heading. That way it also catches the case where steps that look harmless one by one add up to something you never intended. The limits you set for the agent at the start hold until the very last step — so you can hand it work with peace of mind.

A decision before execution

Qronos doesn't decide after the fact, but before the step.

An ordinary step can go through. A step that calls for closer attention is watched. A step with a real consequence, such as a bulk send, a write to a system or a payment, can wait for a person to confirm it. And a step that goes beyond what was allowed is stopped. The difference from after-the-fact review is timing: the step is decided on before it runs.

Decisions you can evidence

Not just that something was blocked, but why.

Every Qronos decision points to a specific rule and leaves a record behind that you can present at a review. Whoever later asks why the agent wasn't allowed to continue gets an answer they can cite, not just an outcome.

Relationship to Shield

Shield protects inputs, outputs and actions. Qronos continuously watches the agent's run.

Shield sits at the application: it assesses what goes into it, what comes out of it and which actions are triggered through it. Qronos looks from the other side, at an agent that is already working, and throughout the whole run watches whether it goes beyond what you permitted, even when nobody would otherwise notice a deviation. You can deploy Shield today; Qronos, not yet.

Architecture

Decision-making is a separate layer above the agent's steps, kept apart from the agent itself.

We're designing Qronos as a layered decision architecture. Keeping it separate from the agent is deliberate: whether a step may run isn't decided by whoever carries it out. Every decision is written to the audit log. The architecture is designed with the use of quantum computers in mind.

Who's behind it

There are people behind the product you can reach by name

A company doesn't buy a security layer from an anonymous vendor.

Daniel Hrivniak
Daniel Hrivniak
CEO / Founder · Chief AI architect of Corpilus and CREBISO.com products
Daniel Buchta
Daniel Buchta
Principal partner, project guarantor
LinkedIn profile