Agent Endpoint Security and the Locality dichotomy
Insane valuations from these pre-launch startups. They all raised a lot of money and sound the same. I have no clue how they work because they (understandably) don’t have any technical docs.
I therefore embarked on a marketing bonanza to see how these products would manifest improduction.
The thing I’m least clear about is whether the claimed intent analysis runs locally or in the cloud,
If it’s local, it’s not really lightweight
If it’s in the cloud, it’s not really endpoint security
Let me walk through:
In the absence of any specifics I will assume these vendors have an LLM-as-Judge. If that’s the case, the judge LLM will surely live in the cloud. If that’s also the case, what’s the point of endpoint security if detection itself lives in the cloud? We already have gateways to do that. If your agent is for collecting data, is it really a new endpoint seucrity category
If they’re not using LLM-as-Judge and are doing some clever cascade/SLM/ML/Encoder-only, does that run on the endpoint? How do you package this inference mechanism to run on a resource constricted endpoint? You would have to run some ONNX or Llama.cpp package plus the model and push that via an UEM or MDM.
Besides all the questions above, I also have some some product-specific questions, which I hope to get some answers to in my associated LinkedIn post.
Bay Security says its Agentless by design and they deploys through your existing EDR or MDM. I can only imagine this is an “EDR top-up”, which isn’t really agentless if you still need the EDR sensor
Bold Security’s DLP with semantic AI classification undergoes the same intent-related questions as above
Operant has clearly been on the market longer, their landing page is way more specific.
Certiv’s sensor sits at the runtime layer of the endpoint below every application, above the OS. I hope Certiv sees how this makes the deployment more confusing than otherwise. It’s either a daemon or an app
Ent collects a new class of endpoint telemetry across every app . Oh man I can’t wait to see what this new endpoint telemetry
Neo’s sensor is 25mb, and they don’t claim intent, so how different is it from ‘legacy’ EDRs?
Harmonic inspects interactions that never touch your network. So processing does happen locally! But how?
Glow is thin enough on details that I cannot even ask the questions but $180m funding my god I expect nothing less than magic.


