Canyon Road
Canyon Road builds runtime security software for AI agents and AI workloads, enforcing least-privilege policy at the operating-system syscall layer. Its three-product platform — open-source AgentSH, paid Beacon endpoint security, and Watchtower enterprise control plane — serves security teams, DevOps/platform engineers, and compliance organizations deploying supervised and unsupervised AI.
- Company typePrivate
- Founded2026
- Headquarters—
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
What Canyon Road does
Canyon Road Technologies Inc. is a privately held, early-stage US software company founded in 2026 that builds runtime security software for AI agents and AI workloads. The company has 1–10 employees and operates from canyonroad.ai, distributing its core runtime, AgentSH, as a free open-source single binary on GitHub.
The company's product platform is organized around what it terms "Execution-Layer Security" — enforcement at the operating-system syscall layer (using eBPF/LSM on Linux, ESF/FUSE-T on macOS, and minifilter on Windows) rather than at the prompt or proxy layer. The platform comprises three products: AgentSH, an open-source runtime that intercepts file, network, and process operations of headless AI agents in CI/CD, containers, and dev environments; Beacon, a paid endpoint agent that monitors and controls supervised desktop AI tools (Claude, Cursor, ChatGPT, Claude Code) on employee macOS and Windows machines with human-in-the-loop approvals; and Watchtower, an enterprise control plane providing centralized policy distribution, approval routing to Slack/email/SMS, SIEM export to Splunk/Sentinel/QRadar, OpenTelemetry forwarding, SSO/RBAC, and a fleet-wide emergency kill switch. Policies are defined as code (YAML/JSON), versioned in git, and tested in CI. Adjacent capabilities include MCP (Model Context Protocol) security with version/hash pinning and cross-server attack-pattern detection, a Secrets Manager with third-party vault integration, and @agentsh/secure-sandbox — a TypeScript SDK with adapters for Vercel AI SDK, E2B, Daytona, Cloudflare Workers, and Blaxel.
The business model is a freemium-to-enterprise flywheel: AgentSH is free and open-source (no direct revenue); Beacon offers a Free tier for individuals, a Team tier for up to 5 endpoints, and an Organization tier with SIEM integration; Watchtower offers Team and Enterprise tiers with multi-policy groups, configurable retention, SSO/RBAC, and dedicated support. GTM combines product-led growth through GitHub and npm with enterprise field sales for Watchtower and higher Beacon tiers, supplemented by content marketing (founder-authored blog, agentsh.org documentation) and category-education efforts around "Execution-Layer Security." SOC 2 Type 2 and ISO 27001 compliance alignment is self-attested but certification status is not confirmed. No funding rounds, named customers, revenue figures, or geographic operating footprint are disclosed.
Canyon Road firmographics
Firmographics- Name
- Canyon Road
- Legal name
- Canyon Road Technologies Inc.
- Website
- https://canyonroad.ai
- Company type
- Private
- Founded year
- 2026
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- Canyon Road builds runtime security software for AI agents and AI workloads, enforcing least-privilege policy at the operating-system syscall layer. Its three-product platform — open-source AgentSH, paid Beacon endpoint security, and Watchtower enterprise control plane — serves security teams, DevOps/platform engineers, and compliance organizations deploying supervised and unsupervised AI.
- Ownership category
- akta.pro rank
Canyon Road industry classification
Industry- Product category
- AI Runtime Security Software
- NAICS
- Security Systems Services (except Locksmiths) (561621), Security Systems Services (56162)
- SIC
- Services-Computer Programming Services (7371)
- akta.pro primary industry
- Model Monitoring, Drift & Behavioral Anomaly Detection (HDAAAKAF)
- akta.pro secondary industries
- Responsible AI, Security & Privacy Platforms (Safety, Guardrails, PII) (HDAEANAG), Responsible AI, AI Governance & Compliance Services (BPAEAHAJ)
Keywords
Canyon Road business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Marketing or Sales, Operations
Revenue model
- AgentSH Open Source: Free, open-source runtime security for AI agents. Available as a single binary on GitHub. No direct revenue; drives awareness and adoption that converts to paid enterprise products.
- Beacon Endpoint Security (Paid Tiers): Beacon offers Free tier (1 endpoint), Team tier (up to 5 endpoints), and Organization tier (unlimited endpoints with advanced features). Revenue from endpoint security subscriptions.
- Watchtower Enterprise Control Plane: Enterprise subscription with Team and Enterprise tiers. Enterprise includes multi-policy groups, 30/90/365-day retention, SIEM integration, SSO/RBAC, and dedicated support. Revenue from fleet-wide security management.
- Enterprise Onboarding Services: Enterprise onboarding and deployment support mentioned as a service offering for Beacon for endpoints and Watchtower fleet management. Professional services revenue stream.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Others | Free tier for individuals with 1 endpoint, full monitoring and control, local policy management, prompt-based approvals, and 24-hour local history. |
| Subscription | Monthly | Team tier for small teams with up to 5 endpoints, shared cloud policy, 7-day event history, and team dashboard with fleet-wide visibility. |
| Subscription | Annual | Organization tier with unlimited endpoints, multiple policies, endpoint groups, and SIEM integration (Splunk, Sentinel). |
| Subscription | Monthly | Team tier for small teams with centralized policy management, approvals routing, fleet dashboard, 7-day event retention, and community support. |
| Subscription | Annual | Enterprise tier with everything in Team plus multi-policy groups, 30/90/365-day retention, SIEM integration, SSO/RBAC, fleet-wide kill switch, and dedicated support. |
Go-to-market motion2 records
Distribution channels5 records
Marketing channels5 records
Canyon Road product offering
Product offeringCore offering
Canyon Road provides Execution-Layer Security for AI workloads through a three-product platform. AgentSH is an open-source runtime that intercepts system calls (files, network, processes, secrets) at the kernel level to enforce policy on AI agents and copilots before actions execute. Beacon monitors and controls supervised AI tools (Claude, Cursor, ChatGPT) on employee endpoints (macOS/Windows) with per-app visibility and human-in-the-loop approvals. Watchtower is the enterprise control plane providing centralized policy management, approval routing, SIEM export, and a fleet-wide kill switch for both Beacon and AgentSH deployments.
Product overview
Canyon Road offers Execution-Layer Security for AI workloads through a three-product platform. The core portfolio consists of: (1) AgentSH — an open-source runtime that secures unsupervised headless AI agents in CI, containers, and dev environments by intercepting system calls and enforcing least-privilege policy at execution time; (2) Beacon — an endpoint agent that monitors and controls supervised AI tools (Claude, Cursor, ChatGPT, Claude Code) on employee macOS and Windows machines with per-app visibility, runtime policy, and human-in-the-loop approvals; and (3) Watchtower — the enterprise control plane that governs both Beacon and AgentSH from one place, distributing policies, routing approvals, exporting to SIEM, and providing a fleet-wide emergency kill switch. The three products share a unified policy engine and single audit trail, with policies defined as code (YAML/JSON) and enforcement happening locally at execution time while governance flows from the central Watchtower plane.
Differentiator
Problem solved
Functional benefit
Products and services
- AgentSH
- Beacon
- Watchtower
- @agentsh/secure-sandbox
Quantifiable outcome
- Fleet halted in 1.2 seconds across 847 agents
- +2 more outcomes
Companies that use Canyon Road
Customer profileSegments4 records
Ideal customer profiles4 records
Canyon Road technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration7 records
AI capability5 records
Feature9 records
Canyon Road partnerships and signals
Strategic signalScale indicators3 records
Recent moves5 records
Expansion highlights5 records
Canyon Road competitors and assessment
Company assessmentDirect peers
- Astrix Security: Astrix Security focuses on securing AI agents and non-human identities, providing runtime controls for third-party AI integrations and API-connected automations. Direct competitor in AI agent runtime security.
- Lakera: Lakera provides AI security for LLM-powered applications, including prompt injection defense and runtime guardrails for agentic systems. Comparable as a runtime AI security platform for enterprises deploying LLM/agent workloads.
- HiddenLayer: HiddenLayer offers an AI security platform covering model protection, runtime monitoring, and adversarial defense for ML and AI systems. Comparable scope in AI/ML security and behavioral monitoring.
- Noma Security: Noma Security delivers AI security and lifecycle management for enterprise AI applications, including agent governance and runtime policy enforcement. Direct competitor targeting enterprise AI governance buyers.
- PromptArmor: PromptArmor provides runtime AI security specifically designed for AI agents and LLM applications, including prompt injection prevention and tool-call monitoring. Highly comparable niche focus on agent runtime defense.
Emerging players
- Pillar Security: Pillar Security provides AI security posture management and runtime controls for enterprise AI applications and agents. Emerging player with overlapping scope in AI runtime protection.
Broad incumbents
- Cloudflare: Cloudflare is a major cloud security and edge platform with emerging AI workload controls, including bot management and Workers AI safeguards. Broad incumbent that could bundle AI agent security into its existing platform.
- CrowdStrike: CrowdStrike is the EDR/XDR market leader with an extensive endpoint footprint and is actively adding AI workload protection capabilities. Broad incumbent that could subsume AI agent endpoint security into Falcon.
- Microsoft Defender for Cloud / Security Copilot: Microsoft Defender and Security Copilot provide cloud workload protection and AI security features bundled with Azure and the Microsoft enterprise stack. Broad incumbent with deep enterprise distribution.
- SentinelOne: SentinelOne is an endpoint and cloud security platform expanding into AI workload monitoring and agentic security. Broad incumbent with overlapping endpoint AI visibility use cases to Beacon.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
Canyon Road social profiles
Digital presenceCanyon Road compliance and trust
Trust signalCompliance2 records
Canyon Road financial estimates
Financial estimateRevenue estimate
Valuation estimate
Canyon Road leadership team
Management profileNumber of profiles
Canyon Road funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Canyon Road M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Canyon Road
What does Canyon Road do?
Canyon Road provides Execution-Layer Security for AI workloads through a three-product platform. AgentSH is an open-source runtime that intercepts system calls (files, network, processes, secrets) at the kernel level to enforce policy on AI agents and copilots before actions execute. Beacon monitors and controls supervised AI tools (Claude, Cursor, ChatGPT) on employee endpoints (macOS/Windows) with per-app visibility and human-in-the-loop approvals. Watchtower is the enterprise control plane providing centralized policy management, approval routing, SIEM export, and a fleet-wide kill switch for both Beacon and AgentSH deployments.
Is Canyon Road a public or private company?
Canyon Road is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Canyon Road founded?
Canyon Road was founded in 2026. It employs 1 to 10 people.
How does Canyon Road make money?
Four revenue lines are on record. AgentSH Open Source is the primary driver. The others are beacon Endpoint Security (Paid Tiers), watchtower Enterprise Control Plane and enterprise Onboarding Services.
Who are Canyon Road's main competitors?
Direct peers on record are Astrix Security, Lakera, HiddenLayer, Noma Security and PromptArmor. Pillar Security is listed as an emerging player. Broad incumbents are Cloudflare, CrowdStrike, Microsoft Defender for Cloud / Security Copilot and SentinelOne.
Does Canyon Road have an API?
No public API is recorded for Canyon Road.
What industry is Canyon Road in?
Canyon Road's product category is AI Runtime Security Software. Its primary akta.pro industry code is HDAAAKAF, Model Monitoring, Drift & Behavioral Anomaly Detection, with a secondary code of HDAEANAG, Responsible AI, Security & Privacy Platforms (Safety, Guardrails, PII). Its NAICS code is 561621 and its SIC code is 7371.