NEW FalconX Agent Red Team — open-source toolkit for AI Agent & MCP security testing. Explore on GitHub →
AI Cybersecurity · Made in Vietnam · Global by design

The security platform to
secure your AI future.

FalconX discovers, red-teams and protects your AI Agents, LLMs and MCP systems — powered by real attack data and a continuous defense loop. Built for banks, government and enterprises in Vietnam & Southeast Asia.

On-premise · Air-gapped ready · Reproducible evidence
20/20
OWASP LLM & Agentic Top 10 covered
Every probe and control mapped to a standard
<20ms
P95 policy decision latency
Design target for cached deterministic policy
6→1
Six defense layers, one closed loop
Detect → Remediate → Alert → Protect → Verify → Learn
Built on the world's leading AI security standards — mapped to Vietnamese law
OWASP LLM Top 10 OWASP Agentic Top 10 MITRE ATLAS NIST AI RMF ISO/IEC 42001 EU AI Act Vietnam PDP Law 2025
Products

Three products. One AI security platform.

Pick what you need today; every product shares the same policy engine, threat intelligence and evidence vault.

DESIGN PARTNER
FalconX AgentGuard

AI Agent & MCP Security

Runtime control for autonomous agents
  • Zero-Trust Gateway on every tool-call and MCP server
  • Least privilege, JIT access and action limits
  • Tool poisoning, rug-pull and excessive-agency prevention
Explore AgentGuard →
DESIGN PARTNER
FalconX AI Shield + DataGuard

AI Firewall & Data Protection

Real-time protection for LLM apps, RAG and data
  • Prompt injection & jailbreak detection, tuned for Vietnamese
  • PII/secret redaction before data leaves your trust zone
  • ACL-aware RAG retrieval and poisoned-document detection
Explore AI Shield →
OPEN SOURCE · ALPHA
FalconX Red

Continuous AI Red Teaming

Risk-based, reproducible attack testing
  • Direct, indirect and multi-step exploit chains
  • Multi-state findings with structured evidence
  • Regression gates in CI; JSON / HTML / SARIF reports
Get it on GitHub →
Integration & Scale

Deploy where your data lives. Scale without changing how teams build.

API-first and model-agnostic. Works with your IAM, SIEM/SOAR and MCP ecosystem — on cloud, hybrid or fully air-gapped.

API-first architecture

REST/gRPC, OpenTelemetry traces, signed policy bundles.

Cloud · Hybrid · On-prem

Air-gapped profile with offline signed updates.

Enterprise integrations

SIEM/SOAR, IAM/PAM, KMS/HSM, ITSM, CI/CD.

Model-agnostic, MCP-native

OpenAI, Anthropic, Gemini, private models; MCP/A2A adapters.

# 1. Run the red team against your agent / MCP endpoint
pip install falconx-agent-redteam
falconx scan --target mcp:./my-agent --suite owasp-llm,agentic,mcp \
        --safety-mode dry_run --format sarif
 
# 2. Result: findings with status & evidence
✔ 24 probes · 3 exploit chains executed
⚠ vulnerable=3  safe=19  inconclusive=1  n/a=1
→ FX-000412  RC-PROMPT/indirect  severity=critical  evidence=tool_call
 
# 3. Into the defense loop: propose patch → shadow → verify
falconx remediate FX-000412 --playbook PB-PROMPT-INDIRECT --mode shadow
✔ virtual patch VP-01+VP-02+VP-13 proposed · simulation fp=0.0% · awaiting approval
How it works

Continuous AI security powered by real threat data

Every attack we see — from our open-source red team, our research and your production traffic — becomes a detector, a policy and a test. Protection improves without manual updates.

FALCONXThreat IntelligenceAI Security Knowledge Graphattacks · detectors · policies · evidence FalconX Red — real attack data from the open-source red team and community 1 FalconX Red (OSS)Real attack data Research & Threat Intel — OWASP, MITRE ATLAS, published vulnerabilities, Vietnamese corpus 2 Research & IntelOWASP · ATLAS · CVD Adaptive Guardrails — new detectors & rules via corpus tests and shadow mode 3 Adaptive GuardrailsNew detectors & rules Runtime Protection — Gateway, Guardrails, DataGuard protect your AI in real time 4 Runtime ProtectionGateway · Guardrails · DataGuard Production telemetry — blocked attacks, agent behavior anomalies, suspicious tool-calls 5 Production TelemetryBlocked attacks · anomalies Virtual Patch & Verify — patch policy/guardrail/permissions, simulate, shadow, re-verify with Red Team 6 Virtual Patch & VerifyPatch · simulate · verify Detect → Remediate → Alert → Protect → Verify → Learn — every step records signed evidence
Attack data Detectors & patches Production telemetry
1

Real attack data, not synthetic guesses

Our open-source red team runs real payloads — direct, indirect, multi-step — against agents and MCP servers. Every confirmed finding feeds the loop.

2

Research & threat intelligence

OWASP, MITRE ATLAS and our own published vulnerabilities become probes and detectors — including a Vietnamese attack corpus no global vendor has.

3

Protection that adapts without manual updates

New rules are generated from findings, tested on positive/negative corpora, rolled out in shadow mode, then enforced — with reason codes on every block.

4–6

Protect, observe, patch, verify — and learn

Production telemetry reveals new attacks; virtual patches (policy, guardrail, permission, content) are simulated, approved by autonomy level, deployed and re-tested by the red team. The loop closes with signed evidence.

MTTPMean Time To Protect — the metric we optimize
Shadow-firstNo patch enforces before it proves itself on real traffic
Earned autonomyAutomation unlocked only by measured success

Stronger AI security starts with understanding AI

We secure the action layer — where agents call tools, read data and make decisions — not just the text layer.

Stop AI attacks

Prevent prompt injection, tool poisoning, data leakage and excessive agency before they reach your systems.

Adapt in real time

Protection evolves with emerging threats through the continuous loop — without waiting for a vendor release.

Secure fast-moving teams

Enforce at the gateway, not in your code. Ship agents without slowing development.

Earn regulator trust

Reproducible evidence mapped to OWASP, NIST, ISO 42001 and Vietnamese law — ready for any inspection.

Continuously-evolving security

Silent model or prompt changes shift your posture. Event-triggered red teaming re-tests every change and patches what breaks.

Deterministic precision

Final allow/deny is deterministic policy with reason codes; ML detectors are signals, never the sole authority. Measured false-positive rates, not promises.

Ultra-low latency

Cached deterministic policy on the hot path; AI analysis runs async. Design target: P95 under 20 ms.

Central policy control

One policy compiles to every enforcement point — gateway, guardrails, RAG, endpoint — with versioning, simulation and rollback.

Model-agnostic, MCP-native

Any provider or private model. First-class MCP and A2A adapters, tool registry and schema pinning.

Built for sovereignty

Fully on-prem or air-gapped. Vietnamese sensitive-data pack. Evidence stays in your trust zone.

Platform

One platform — six modules across the AI lifecycle

Click a module for details. All modules share one policy engine and one evidence vault.

FOCUS

Agent & MCP Gateway

Zero-Trust enforcement between agent and tools: tool-call control, escalation prevention, MCP audit, least privilege.

Details →

AI Firewall & Guardrails

Real-time blocking of prompt injection, jailbreak, PII leaks and out-of-scope behavior — tuned for Vietnamese.

Details →

Continuous Red Team

Thousands of attack scenarios, continuously — findings with reproducible evidence that feed the defense loop.

Details →

AI SOC & Monitoring

Anomaly detection, correlation and real-time AI attack alerts — with a risk dashboard for leadership.

Details →

RAG & Data Security

Poisoned-document detection, knowledge leakage and unauthorized retrieval in RAG pipelines and vector DBs.

Details →

Compliance & Audit

Reproducible evidence and automated reports mapped to OWASP, NIST AI RMF, ISO/IEC 42001 and local requirements.

Details →
Solutions

Solutions by industry & scenario

Same platform, packaged for each sector's problems and compliance needs. Click to open details.

Banking & Finance

Protect agents handling customer data, prevent leakage and fraud, meet sector standards. On-prem — data never leaves.

Learn more →

Public Sector

Keep AI in public services compliant and sovereign. Full audit trail for inspections.

Learn more →

Internal Copilot & Agents

Protect self-built copilots and agents from prompt injection, tool abuse and internal data leaks.

Learn more →

Data Science & Models

Secure data pipelines, RAG and models: poisoning, model extraction and knowledge leakage.

Learn more →
Design Partner Program

Be among the first to run AI agents under continuous, evidence-based protection

We are onboarding a small number of banks, public agencies and enterprises in 2027. Partners get a free AI security assessment, priority on-prem deployment and a direct line to our research team.

  • Free red-team assessment of one production agent or MCP integration
  • Shadow-mode deployment — observe before you enforce
  • Compliance evidence pack mapped to Vietnamese law
Why we do not show customer logos yet

FalconX is in alpha with its first design partners. We publish vulnerabilities, code and benchmarks — not borrowed trust. Logos will appear when partners agree to be named.

Apply as design partner →
Open-Source-Led

Trusted by developers, not just sold to them

FalconX Red is released as open source under Apache-2.0 — transparent, verifiable, free. The attack data it generates is the fuel of our continuous loop.

Apache-2.0 Made in Vietnam 🇻🇳 · Global by design  v0.1-alpha
# Install
pip install falconx-agent-redteam
 
# Scan an AI Agent / MCP endpoint
falconx scan --target mcp:./my-agent --suite owasp-llm,mcp
 
✔ 24 probes · 6 exploit chains
⚠ 3 critical findings, reproducible evidence
→ falconx-report.html · findings.sarif
Get started

Your business is deploying AI. Is it protected yet?

Book a free AI security assessment with FalconX experts. We will show the real risks in your AI agents — with data and evidence.

Contact

Book a demo & free AI security assessment

Leave your details and a FalconX expert will reach out within one business day.

  • 30-minute demo tailored to your AI stack
  • Free red-team assessment for design partners
  • On-prem deployment, data never leaves

contact@falconx.ai.vn

By submitting, you agree that FalconX may contact you and process your data under applicable law.

Ask FalconX Assistant 👋