FAQ
Questions, answered.
What security, platform, and engineering teams ask us most about running agentic AI safely.
Overview
What is Dash?
Dash is an agentic AI security platform: a single control and intelligence layer to see, govern, and control every AI agent and interaction, everywhere agents run. Dash discovers your entire agentic estate, sanctioned and shadow, governs the agentic supply chain, monitors every session end to end, and enforces in runtime.
What problem does Dash solve?
AI agents interpret instructions, build their own execution plans, and adapt at runtime. The same action can be safe in one session and a breach in the next. Traditional security tools were built for deterministic decisions, so they can see what ran but not why. Dash is session and intent aware: it understands what the user intended, what the agent reasoned, what it actually did, and where those diverged, and acts on that understanding in real time.
Is Dash a replacement for my EDR, SIEM, or DLP?
No. Dash works alongside your existing stack and makes it stronger. Your EDR sees the command; Dash adds the session and intent behind it. Detections flow to your SIEM, identity context comes from your IDP, and actions reach your team through Slack, Jira, Teams, email, and webhooks.
Who is Dash for?
Three teams get direct value: security teams (discover, govern, and control agentic activity), AI transformation leaders (understand adoption, workflows, cost, and effectiveness), and builders (full observability of every tool, action, access, and token spent).
Is Dash an AIDR solution?
Dash delivers AI detection and response, built on session and intent awareness rather than isolated events. But AIDR is where Dash starts, not where it ends: the same platform covers discovery, agentic supply chain governance, policy, and AI cost operations.
Coverage & platforms
Where does Dash work?
Wherever agents operate: coding agents in CLIs and IDEs, AI assistants in browsers and on desktops, SaaS agents, and custom agents running autonomously in cloud environments, VMs, and containers.
Which agent platforms does Dash support?
Dash provides runtime protection for +20 coding agents and +60 unique platforms including Cursor, Claude Code, Devin, Cline, GitHub Copilot, Antigravity, Codex, Open Code, Kiro, Cortex Code, VS Code Agent, Augment code, CodeBuddy, Command Code, Qoder, Qwen Code, Factory Droid, Mistral Vibe, Amp Code and Kilo Code.
Does Dash cover shadow AI?
Yes. Dash continuously discovers unsanctioned tools, sanctioned tools accessed through personal or untrusted accounts, and dormant installs, across the entire organization.
Does Dash cover MCP servers and skills?
Yes. Dash discovers every MCP server, skill, and plugin in your environment, continuously scans and scores their risk based on capability, autonomy, and safety, and lets you govern them down to the individual tool: sanction, ticket, or block.
Which operating systems does the Dash client support?
The Dash client supports all major operating systems.
Does Dash cover custom-built and autonomous agents, not just commercial tools?
Yes. Dash covers custom agents running autonomously in cloud environments, VMs, and containers, with the same discovery, session monitoring, and enforcement as workstation agents.
Does Dash cover enterprise AI platforms and SaaS agents, or only workstation agents?
Both. Dash covers coding agents in CLIs and IDEs, AI assistants in browsers and desktops, enterprise AI platforms and SaaS agents, and custom agents running autonomously in cloud environments.
Does Dash cover multi-agent systems and agent-to-agent interactions?
Yes.
How it works
What does "session and intent aware" mean?
Dash reconstructs every agentic session end to end: the user's prompt and intent, the agent's reasoning, every tool call, shell command, file access, and MCP invocation, and the outcome. That full chain is what lets Dash tell a legitimate action from a risky one, and detect when an agent drifts from what the user actually asked for.
What is intent drift?
Intent drift is when an agent's actions diverge from the user's request: a simple cleanup task that reaches for production credentials, a UI fix that balloons into auth changes. Dash detects drift in real time by comparing user intent against agent behavior at every step, and can alert or block the session.
Can Dash block risky behavior, or only alert?
Both, and the response is risk proportionate. Depending on your policy, Dash can alert, open a ticket, notify the user in session, require a human in the loop, block a specific tool, model, or skill, or block the session entirely, inline, in runtime.
What is the Dash MCP server?
The Dash MCP server turns every agent, action, and detection into a question you can ask. Query your entire AI estate in natural language, from "who is running agents I haven't approved" to "what drove our token spend this week," or build automations and SOC workflows on top of it.
How does Dash avoid false positives and unnecessary blocks?
Because Dash evaluates actions against full session context, user intent, prior actions, and data accessed, rather than isolated events, its detections carry the story behind them. Responses are risk proportionate: most findings alert or ticket, and blocking is reserved for high risk, high confidence cases you define.
Does Dash protect against prompt injection?
Yes. Indirect prompt injection, a poisoned README, a manipulated tool response, a malicious MCP server steering the agent's reasoning, is exactly the class of attack session and intent awareness catches. Dash detects when an agent's behavior diverges from the user's intent, whatever caused the divergence, and blocks it in runtime.
Does Dash support human-in-the-loop approvals?
Yes. Policies can require human approval for specific actions, and only when required, so oversight lands where risk is high without slowing everything else down.
Does Dash secure agents during development, or only at runtime?
Dash secures the full operational lifecycle: vetting the agentic supply chain before agents touch it, hardening posture and permissions, and enforcing in runtime.
Deployment & performance
How long does deployment take?
Under 5 minutes to full deployment. Dash deploys via your existing MDM with a single line of code and starts surfacing your inventory within minutes.
Do I need to roll out a new agent to my fleet?
Dash's client has various models covering different use cases. The deployment is flexible and built to match the needs of the customer.
Does Dash work with my EDR?
Yes. Dash integrates with leading EDRs, including CrowdStrike Falcon, enriching endpoint detections with the full agentic session context behind them.
Will Dash slow down my endpoints or disrupt my developers?
The Dash client is lightweight and designed to be invisible to users. No kernel module, no reboot, no workflow changes. Developers keep working exactly as before; Dash only steps in when policy requires it.
Does inline enforcement slow down agent sessions?
Dash's detection and enforcement run inline with negligible latency, invisible to the user until policy requires action.
Data, privacy & compliance
Does Dash capture full prompt or response content?
Dash never stores any prompt or response, it does store related metadata and summarized content. Customers can grant consent to collect raw data.
Is Dash compliant with SOC 2 / ISO 27001 / GDPR?
Dash is built to enterprise security standards. Contact us for our security documentation.
Can Dash help with compliance and regulatory requirements?
Dash makes every agent action auditable and attributable, with a full session trail, supporting AI governance frameworks and regulatory requirements.
Comparisons
Can Dash help with AI cost and ROI?
Yes. Dash attributes every token spent to the user, agent, team, and project behind it, identifies which activities drive high costs, and gives you the data to make adoption and efficiency decisions.
How is Dash different from endpoint AI security tools?
Endpoint AI security decides what software is allowed to run. Dash governs what agents do while running. A fully sanctioned agent on a healthy endpoint can still be steered by a poisoned input, drift from user intent, and cause impact in code, SaaS, and cloud. Dash sees inside the session, the only place that story is visible, and feeds that context back into your endpoint stack.
I already have (or am evaluating) an EDR vendor's AI detection module. Do I still need Dash?
Yes, and they work together. An AI module on an endpoint platform extends endpoint telemetry into AI. Dash is native to the agentic session: it reconstructs the full chain from prompt to reasoning to action to impact, catches intent drift no isolated event reveals, and feeds that context back into your EDR and SIEM. Your endpoint tool gets stronger with Dash, not redundant.