Provenance — an ImmersiveOne product

Monitor your agents. Alert on what they're talked into. Red‑team them yourself.

Full observability over the agents running in your own environment, against the real tools they call. An AI agent doesn't get exploited the way a web app does — nobody breaks in, someone asks, and the agent uses the access you gave it. Managed in our cloud, or deployed inside your own network.

live capture · support-copilot
User message · untrusted channel
Real spans, real rule output — captured from a running agent.

Observe

Your agents, your environment, your real tools

Every span, every handoff between agents and every argument passed to a tool — captured from the agents you actually run, not a sampled transcript of a staging copy.

Alert

Suspicious behaviour, flagged as it happens

Detections run on the ingest path, so an alert arrives while the conversation is still open — naming the technique, the tool it reached and the trace it belongs to.

Red-team

Attack them before someone else does

Point a red-team run at a live agent endpoint and find out what it complies with. The results land in the same alert list your monitoring writes to.

The gap

One request. Two very different stories.

Your APM saw a healthy request. Inside it, the agent read your customer table and mailed it to an address it had never contacted before — using its own credentials, in under four seconds.

What your stack recorded

POST /v1/chat 200 3.71s user=u_4471

Correct, and useless. The agent's own behaviour is inside the response body, and the damage was done by a tool call your gateway never saw.

What actually happened

0.00suser message arrives — instruction override, exfil address
0.31srouter hands off to orders_agent
1.94stool.run_report_query — SELECT email, phone FROM customers
2.21stool.send_email — to archive@mailbox-sync.co
3.71sagent replies “I've prepared the export you asked for.”

Two findings on the same trace: the attempt, and the tool call that proves it worked.

Detections

Sixteen detections, four different moments.

Not one model grading transcripts. Rules that run where they can actually see something — on the span as it lands, across the whole dataset, over the agent's declared permissions, and against the running agent itself. Pick one.

The console

Built for the person who has to answer for it.

Every screen here is the real product, running on real captured traffic — conversations, alerts, the agent inventory and the trace that explains each one.

Overview dashboard: conversation volume, token usage, estimated spend and findings by severity over the last 30 days.

Overview — volume, tokens, spend and severity mix for the selected project and window. Spend is priced from a model table, so a runaway conversation is visible as money, not just tokens.

Twenty-five seconds, end to end

How it works

A mirror, never a proxy.

your agent app + immersive SDK engine auth · ingest detect phoenix mysql dashboard OTLP · Bearer im_live_… copy

It can't take your agent down

The SDK exports out of band on a background batch processor. If the engine is slow, unreachable or switched off, your app doesn't notice — capture never sits in the request path. That is the difference between an observability tool and a dependency.

One line, any stack

Python and Node SDKs, a browser sensor for ChatGPT sessions, and a tailer that captures Claude Code transcripts. Anything already speaking OpenTelemetry is understood as-is — OTel GenAI, OpenInference and Traceloop conventions all map onto the same five channels.

Isolation is structural

Every project gets its own keys, its own capture buffer and its own trace store, so two teams on one deployment never see each other's traffic. On-prem, that whole store — MySQL and Arize Phoenix — sits inside your network and no span ever leaves it.

# capture starts at import — everything already instrumented is picked up
pip install immersive

import immersive
immersive.configure(
    api_key="im_live_…",
    service_name="Support Copilot",
    endpoint="https://observability.yourco.com",
)

Deployment

Two ways to buy it. Same platform either way.

The product doesn't change with the deployment — the same detections, the same console, the same isolation model. What changes is who operates it and where the traces live.

Cloud

We run it for you

A dedicated tenant on our hosted platform. Point an SDK at your endpoint and traffic starts appearing in minutes — nothing to provision, patch or capacity-plan, and new detections arrive as we ship them.

  • Live within the hour, not the sprint
  • Upgrades, backups and TLS handled
  • Per-tenant isolation of keys, spans and findings
Book a walkthrough

On-premises

It runs inside your network

The whole platform ships as one compose bundle into your own infrastructure. Every span, every prompt and every finding stays on your side of the boundary — useful when the traffic you are capturing is exactly the traffic you can't send anywhere.

  • No telemetry leaves your VPC
  • You hold the database and the keys
  • Air-gap friendly; the offline detections need no model
Talk to us about on-prem

multi-tenant

Tenants own projects; projects own keys, spans and findings. The isolation is structural, not a filter over a shared table.

https by default

TLS is terminated with an automatically renewed certificate, and every internal service binds to loopback — never published.

credentials that can't leak

Sessions are opaque 256-bit tokens stored as SHA-256 in HttpOnly cookies; API keys are hashed and shown once. A database dump yields nothing usable.

extensible

A detection is a subclass and a decorator, so your team can ship rules that encode what only you know about your own agents.

mapped to OWASP

Findings carry their framework tag — LLM01 through LLM10 — so an alert lands in the language your risk register already speaks.

no agent downtime

Capture is out of band in both deployments. If the platform is unreachable, your agents keep serving — they never wait on it.

Provenance

Prove your agents are secure.

The same promise ImmersiveOne makes about your people and your applications, extended to the agents you ship. Bring a week of your own agent traffic and we'll show you what is already in it.