Cloud only · internet required. Use browser speech-to-text, AI, and text-to-speech with no model installation.
Checking browser speech services…Add source media to begin.
Create images or videos, or add source media to edit them.
Nessco Vision
Use a live camera or upload PNG, JPEG, and WebP images. Local OpenCV analysis needs no account. Vision Pro sends a frame to the configured GPU service when you press Analyze with Vision Pro. Camera access starts only when you ask, and stops when this panel closes or the page is hidden.
Local analysis stays in this browser. Vision Pro uploads only on request. Capture & attach adds an attachment sent with your message.
Reference object
Upload an image cropped to a flat, textured object, then save it as the reference. Upload another scene or start the camera to find it.
Camera calibration
Optional JSON: width, height, fx, fy, cx, cy, distortion [k1,k2,p1,p2,k3]. Use the same camera, resolution and crop as the calibration.
Starting microphone…
Voice settings
Prefers natural and enhanced voices available on your device.
TASKS
No steps yet. Add one, or ask for a plan and its checklist lands here.
- Connected to a computer
- Analyzing agent workflow
- Explored 0 files, 0 directories, 0 searches
- Working for 0 seconds
Chief's screen
Routines are recurring tasks this Bot runs on a schedule. Ask it in chat to set one up.
Harness OS
GitHub Files
Sign in to browse repositories.
Command palette click a command to run it
Four ways an agent gets away from you.
Four places we hold the line.
Autonomy fails at the boundary — where an agent decides, where it reaches for data, where it was taught what "good" looks like, and what it is shown. Nessco covers all four.
Agentic firewalls
A policy boundary that sits between an agent and everything it can touch. Every intent is classified, scored and either allowed, held for a human, or killed — before the tool call leaves the process.
- Intent classification on every tool call
- Prompt-injection and jailbreak interception
- Human-in-the-loop holds for high-blast-radius actions
- Hard kill-switch and blast-radius caps per agent
Cyber attack & data leak prevention
Agents are a new attack surface and a new exfiltration path at the same time. We watch both directions: what gets into the context window, and what leaves it.
- Outbound checks for secrets, PII and source code
- Poisoned-tool and untrusted-content quarantine
- Lateral-movement detection across agent fleets
- Immutable, replayable audit trail for every decision
Training edge-AI agents & LLMs
Small models that run on your hardware, trained on your data, aligned to your policy — so the safe behaviour is baked in before the firewall ever has to catch it.
- Domain fine-tuning and distillation to edge-size models
- Quantisation and compilation for constrained devices
- Policy-aligned reward models and refusal training
- Red-team evaluation harness with regression gates
Vision-language models & real-time classifiers
An agent that can see is an agent that can be shown something. We inspect what a model looks at — screens, camera feeds, scanned documents — and run the classifiers that have to answer in milliseconds, on the device, without a round trip.
- Prompt injection hidden inside images, screenshots and PDFs
- Millisecond-budget classifiers running on the device
- Frame-level redaction of faces, badges and open screens
- Drift monitoring against a held-out labelled reference set
What the model sees is an input too.
Text inputs get inspected as a matter of course. The moment an agent takes a screenshot, opens a scanned invoice or reads a camera frame, the same untrusted content arrives through a channel most guardrails never look at.
Injection hides in pixels
Instructions rendered into an image are invisible to a text filter and perfectly legible to a vision-language model. We read what the model reads — rendered text, QR codes, overlays — and apply the same policy to it as to any other untrusted source.
Fast enough to sit inline
A classifier on the hot path has a millisecond budget, not a second one. These run quantised on the device, so a camera feed is judged where it is captured rather than shipped somewhere to be judged.
Redact before it is stored
Faces, badges, whiteboards and open screens are masked at the frame, before anything reaches a log, a prompt or a training set. What was never captured cannot leak later.
Watched for drift
Vision models decay quietly as lighting, hardware and scenes change. A held-out labelled set runs on a schedule, and a classifier that loses ground is flagged rather than trusted.
Visual attack surface
inspected per frame- HIGHText rendered into an image"Ignore prior instructions" printed on a slide the agent screenshots.
- HIGHMalicious QR or barcodeScanned document encodes a destination the agent then fetches.
- MEDIncidental captureA colleague's screen or badge caught in frame and written to a log.
- MEDAdversarial perturbationCrafted noise flipping a classifier's label without a visible change.
- LOWSilent accuracy driftNew camera firmware shifts colour balance; confidence stays high, labels do not.
Four checkpoints between intent and impact.
The harness wraps the agent loop itself. Nothing reaches a tool, a dataset or the network without clearing all four.
-
01
Intercept
The runtime shim sits inside the agent loop. Every planned tool call, retrieval and network request is captured as a structured intent instead of executing straight away.
-
02
Reason
A small, fast classifier scores the intent against policy: who is asking, what it touches, how reversible it is, and whether the context that produced it can be trusted.
-
03
Enforce
Allow, redact, hold for a human, or block and terminate. Enforcement happens inline, so a rogue action never reaches the system it was aimed at.
-
04
Learn
Every decision is signed, stored and replayable. Blocked patterns become training data for your edge models and new rules for the fleet.
Stop a rogue agent at the intent, not at the incident report.
Traditional security assumes a human on the keyboard. An agent has credentials, a plan, and no hesitation — it will chain forty tool calls before anyone opens a dashboard. The agentic firewall makes that loop reviewable at machine speed.
Intent-level policy
Rules are written against what the agent is trying to do — "no writes to production billing", "no outbound POST with customer records" — not against brittle string matches.
Injection interception
Retrieved documents, web pages and tool output are treated as untrusted input. Instructions smuggled into content never gain the caller's privileges.
Blast-radius caps
Per-agent budgets on spend, rows touched, files written and external calls. Breach the cap and the harness freezes the agent with its state intact for review.
agent: support-copilot
boundary:
allow:
- tool: crm.read
scope: "tenant:self"
- tool: ticket.write
limit: 50/hour
hold:
- tool: refund.issue
when: amount > 250
approver: finance-oncall
block:
- sendsTo: "*"
carrying: [secret, pii, source_code]
- origin: untrusted_content
escalates_to: [shell, iam, deploy]
on_violation: freeze + snapshot + page
Two directions of failure. One inspection point.
An agent connected to your stack is both a target and a courier. Nessco inspects the inbound context that shapes its behaviour and the outbound payload that carries your data.
Inbound: the attack path
Poisoned documents, hostile MCP servers, compromised tool responses and supply-chain prompts are quarantined before they reach the model's context.
Outbound: the leak path
Everything the agent sends out is classified for secrets, credentials, regulated data and proprietary code, then redacted or blocked according to the destination's trust tier.
Fleet-wide correlation
One agent probing is noise. Nine agents probing the same boundary in an hour is an incident — correlation runs across the whole fleet, not per session.
Threat surface
continuously monitored- HIGHPrompt injection via retrievalUntrusted page instructs agent to email an export.
- HIGHCredential harvestingAgent asked to "debug" by printing environment secrets.
- MEDSilent data exfiltrationRecords dripped out through an allow-listed webhook.
- MEDTool-chain escalationRead-only agent reaching shell through a helper tool.
- LOWModel drift into over-collectionRetrieval scope widening beyond the task over time.
Small models, your hardware, your rules.
Enforcement is the floor, not the ceiling. We train the models that run inside the harness — compact enough for a factory gateway or a handset, aligned tightly enough that the firewall rarely has to intervene.
Distil, don't just prompt
Frontier-model behaviour distilled into task-specific models you own, so latency, cost and data residency stop being negotiable trade-offs.
Aligned to the same policy
The policy that drives your firewall becomes the reward signal in training. Guardrail and model agree instead of fighting each other at runtime.
Evaluated like software
Red-team suites, refusal benchmarks and behavioural regression gates run in CI. A model that loses ground on safety does not ship.
Training pipeline
- 01CurateYour domain data, cleaned, de-identified, provenance tracked.
- 02DistilTeacher-student compression to supported models up to 3B parameters.
- 03AlignPolicy-derived preference training and refusal tuning.
- 04CompressQuantise, prune and compile for the target silicon.
- 05ProveRed-team and regression gates before any promotion.
- 06ShipSigned artefacts, staged rollout, one-command rollback.
One harness. Four control planes.
Deploy as an SDK inside the agent, a sidecar next to it, or a gateway in front of the fleet. Same policy, same audit trail, wherever it runs.
Network plane
Outbound control, destination trust tiers, DNS and payload inspection for everything the agent tries to reach.
Data plane
Classification, redaction and residency rules applied to every record entering or leaving the context window.
Tool plane
Capability scoping per agent and per session: which tools exist, with what arguments, under what budget.
Intent plane
The model's plan itself — classified, risk-scored and checked against policy before a single call is made.
SDK
Drop-in wrapper for Python and TypeScript agent frameworks.
Sidecar
Process-local proxy for containerised fleets and Kubernetes.
Gateway
Central chokepoint for model, tool and MCP traffic.
Edge
Air-gapped build for on-prem, industrial and offline devices.
Built for the places where a rogue action is expensive.
Financial services
Agents with ledger access, held to approval thresholds and full replayable audit.
Healthcare
Clinical copilots that cannot leak a record, running on-prem where residency demands it.
Critical infrastructure
Edge models on isolated networks, with hard caps on anything that touches control systems.
Defence & public sector
Air-gapped deployment, signed artefacts, no data leaving the perimeter. Ever.
Software & platforms
Coding agents kept out of production secrets, credentials and customer databases.
Manufacturing
Gateway-class models on the factory floor, trained on your process data offline.
Straight answers.
What exactly is an "agentic harness"?
A control boundary that wraps an autonomous agent's execution loop. The agent still reasons and plans freely; the harness decides what is allowed to actually happen. Think of it as the difference between trusting a driver and fitting the car with brakes, limiters and a black box.
How is this different from a WAF or a DLP product?
Those inspect traffic. We inspect intent. A WAF sees a well-formed API call and lets it through; the harness sees that a support agent — which has never issued a refund above $250 — is about to move $40,000 after reading an untrusted email, and holds it.
Will it slow our agents down?
Enforcement runs inline on small, local classifiers rather than a round trip to a frontier model. Low-risk intents clear on the fast path; only genuinely ambiguous ones take the deeper review, and only high-blast-radius ones wait on a human.
Do you need access to our data or models?
No. The harness is designed to run entirely inside your perimeter, including fully air-gapped. Training engagements happen on your infrastructure or an isolated environment you control, and the resulting model weights are yours.
Which agent frameworks do you support?
Anything that speaks tool calls. The SDK wraps common Python and TypeScript frameworks directly, the gateway sits in front of model and MCP traffic for everything else, and custom loops integrate through the intercept API.
What happens when the harness blocks something it shouldn't?
Every decision is logged with the full intent, the matching rule and the context that produced it. You can replay the moment, adjust the policy, and — where it makes sense — feed the correction back into the next training round.
Put a harness on it.
Tell us what your agents can reach today. We will map the blast radius, show you where the boundary should sit, and book you a free consultation with one of our experts — no payment details, no obligation.
- A short questionnaire about your agents and your exposure
- An instant, non-binding pricing estimate for your company's size
- A free 30-minute consultation, booked straight into an expert's calendar
Prefer email? hello@nessco.ai
Two ways in
A short questionnaire about your agents, then straight to booking a free consultation with an expert.
Start the questionnaireGet an instant estimate from your company size and revenue, then book when you're ready.
Open the pricing estimator