03 · Capabilities
From correlated signal to enforced action — and the evidence in between.
Five capabilities that turn the identity graph into something a CISO can act on, a CFO can price, and an auditor can read. Each grounded in live data, not slideware.
001 · INLINE ENFORCEMENT
Block the prompt before it reaches the model.
Point an agent's provider base URL at ModelCop. Every request is classified and checked against your policy before it's forwarded — a policy-violating prompt is blocked, the agent receives a native API error, and a forensic record is written. OpenAI- and Anthropic-compatible today.
Governs traffic routed through ModelCop · transparent network enforcement available per environment
002 · ATTACK PATH & BLAST RADIUS
Trace an event to the identity — and the human who owns it.
Every AI security event traces back to the non-human identity that executed it and the accountable human chain behind it: owner → manager → department. Kill-chain, force-graph, and blast-radius views make the attribution legible in seconds.
Event → NHI → human owner · forensic detail on every node
003 · CROWN JEWELS
Identify the assets that actually matter — for your team to confirm.
ModelCop flags likely-critical assets from the sensitive data interacting with them, then traces which non-human identities can reach each one. A preliminary identification for your SMEs to validate — not an autonomous determination — so the human judgment stays where it belongs.
Correlation-driven · SME-validated · priced against the value you set
004 · RISK IN DOLLARS
Rank exposure by what it would cost — not by a severity label.
Every NHI and data class is priced to a dollar-denominated risk figure. Instead of a wall of "high / medium / low," your board sees exposure ranked by what a breach of each identity would actually cost — the language risk committees and CFOs already speak.
Per-identity · per-data-class · board-ready
005 · ATTESTATION CENTER
Every control assertion, backed by live evidence you can show.
Attestation status across your controls, each row linked to the source data that proves it — not a spreadsheet someone updated last quarter. Walk an auditor through exactly how a control is satisfied, where the gaps still are, and export the whole thing as audit-grade evidence packs mapped to the frameworks that matter.
Live evidence · control-to-source linkage · regulator-mapped export
006 · PAYS FOR ITSELF
Five live savings engines — not an estimate, the actual number.
ModelCop computes your savings from live data, not a spreadsheet: dormant agent retirement (access you're paying for but not using), LLM model-downgrade recommendations (same output, lower-cost tier), denied-prompt waste recovery (blocked calls that consumed tokens anyway), over-permissioned agent rightsizing (privilege overhead flagged per identity), and cyber-insurance premium reduction from eliminated orphan exposure. Each figure updates as you act on it — so the "ModelCop cost recovered" counter ticks up in real time.
5 saving mechanisms · live audit-event data · per-provider economy tiers · insurance premium impact · no competitor does all five
Correlate the signal. Enforce the policy. Prove every decision — and pay for the platform with what it recovers.