CyberArk Agent Guard
Purchase this listing from Webvar in AWS Marketplace using your AWS account. In AWS Marketplace, you can quickly launch pre-configured software with just a few clicks. AWS handles billing and payments, and charges on your AWS bill.About
Agent Guard delivers secure secret retrieval and observability for AI agent communications by reducing the risks of unmonitored access and hardcoded secrets. Designed for environments using STDIO communication, it helps keep secrets ephemeral, centrally managed, and out of code.
By auditing all interactions and integrating with AWS Secrets Manager or CyberArk Secrets Manager (previously CyberArk Conjur), Agent Guard provides dynamic, just-in-time secret injection, empowering organizations to meet high standards of compliance, traceability, and operational security without compromising performance or flexibility.
Usage instructions:
github.com/cyberark/agent-guard/blob/main/docs/agent-guard-containerized.md
Key capabilities and differentiators:
Auditing and monitoring: Interactions between the AI agent and MCP servers are logged, providing complete traceability and compliance with enterprise security standards.
STDIO-based deployment support: Ideal for local or containerized environments, the proxy supports STDIO communication while isolating the MCP server from direct access to sensitive data on the host.
Dynamic secret injection: Secrets are ephemeral, so they are not stored in code or local files. Instead, they are dynamically retrieved from your secrets manager (AWS Secrets Manager or CyberArk Secrets Manager), injected into the MCP server session, and disposed of after use.
Lightweight and flexible: Easy to deploy and integrate into existing AI workflows without introducing significant overhead.
Integration with AWS:
Agent Guard is configurable with the Amazon Q Developer agent to trace and audit interactions with MCP servers using Agent Guard MCP proxy capability. It can be used for securely retrieving secrets required by the AWS Q Developer agent and its tools. Those secrets can be retrieved from AWS Secrets Manager or CyberArk Secrets Manager.
Optional integration with AWS CloudWatch: Centralized logging and monitoring for enhanced observability.
IAM Role support: Allows only authorized agents to access specific secrets or perform actions.
Please note: this offering is offered free-of-charge and is therefore subject to section 1.4 of the CyberArk SaaS Terms of Use.
Related Products
show moreHow it works?
Search
Search 25000+ products and services vetted by AWS.
Request private offer
Our team will send you an offer link to view.
Purchase
Accept the offer in your AWS account, and start using the software.
Manage
All your transactions will be consolidated into one bill in AWS.
Create Your Marketplace with Webvar!
Launch your marketplace effortlessly with our solutions. Optimize sales processes and expand your reach with our platform.