Skip to main content
As AI agents move from prototypes to production, the security gap widens. Agents now execute tools, manage budgets, access sensitive data, and make autonomous decisions at scale. Yet most teams still ship without guardrails, audit trails, or policy enforcement — not because they don’t care, but because existing solutions demand infrastructure they can’t justify. TealTiger v1.1.1 changes that equation. It’s a complete AI agent security platform that runs entirely inside your SDK — no sidecars, no proxies, no servers. Just npm install tealtiger or pip install tealtiger, and your agents are secured.

Platform Architecture

TealTiger is built around five core components, each handling a distinct security concern. They compose together through a unified request pipeline, or work independently when you only need one capability.
TealTiger Platform Architecture
Every request flows through the same deterministic pipeline: policy evaluation → content validation → circuit breaker check → provider call → audit logging. Each step is optional, composable, and adds sub-millisecond overhead.

Request Lifecycle

Understanding how a single request traverses the TealTiger stack is key to appreciating the depth of protection.
Request Lifecycle
Every step produces a typed Decision object with a consistent contract — action, reason codes, risk score, and correlation ID. This means your application logic can handle any outcome uniformly, regardless of which component triggered it.

The Five Pillars

1. TealEngine — Deterministic Policy Enforcement

TealEngine evaluates security policies against every request and returns a deterministic Decision object. No probabilistic guessing — the same input always produces the same output. Policy Rollout Modes allow gradual deployment without risk:
Policy Rollout Modes
Start in REPORT_ONLY to measure impact, promote to MONITOR to catch violations without blocking, then move to ENFORCE when confident. Mode resolution follows a strict hierarchy: policy-specific override → environment override → global default. Resolution completes in under 1ms. Decision Contract — every evaluation returns:

2. TealGuard — Client-Side Security Guardrails

TealGuard runs content validation entirely in-process — no network calls, no latency spikes. Guardrails execute in parallel for maximum throughput:
TealGuard Parallel Execution
Detection capabilities:
  • PII: emails, phone numbers, SSNs, credit card numbers, addresses
  • Prompt injection and jailbreak patterns
  • Content moderation (hate speech, violence, sexual content)
  • Custom pattern matching via regex or policy rules

3. TealMonitor — Behavioral Anomaly Detection

TealMonitor establishes behavioral baselines for each agent and detects deviations in real time.
TealMonitor Anomaly Detection
Cost governance is built in. Set budgets at any scope (request, session, agent, tenant) with configurable windows. When budgets are exceeded, TealEngine produces cost-specific decisions with reason codes like COST_BUDGET_EXCEEDED or MODEL_DOWNGRADED.

4. TealCircuit — Cascading Failure Prevention

TealCircuit implements the circuit breaker pattern to prevent one failing provider from taking down your entire system.
TealCircuit State Machine
Combined with multi-provider failover, TealCircuit enables architectures where a primary provider failure automatically routes to a backup — with full policy enforcement maintained across the switch.

5. TealAudit — Compliance-Ready Audit Logging

TealAudit produces versioned, immutable audit events with security-by-default PII redaction.
TealAudit Redaction Levels
The default (HASH) ensures raw prompts and responses never appear in logs. PII detection runs automatically before any redaction. Debug mode (NONE) requires explicit opt-in and emits a warning.

Multi-Provider Coverage

TealTiger wraps 7 LLM providers with consistent security, giving you 95%+ market coverage through a unified interface.
Multi-Provider Coverage
Both TypeScript and Python SDKs have full feature parity across all 7 providers.

End-to-End Traceability

Every request carries an ExecutionContext that propagates through all components automatically.
End-to-End Traceability
Correlation IDs use cryptographically random UUID v4. Context converts to and from HTTP headers for cross-service propagation. OpenTelemetry-compatible trace IDs integrate with existing observability stacks.

OWASP Top 10 for Agentic Applications

TealTiger v1.1.1 covers 7 out of 10 vulnerability categories through its SDK-only architecture:
OWASP Coverage Map
This coverage is achieved without deploying any infrastructure.

Performance Profile


Framework Alignment


Get Started

TypeScript SDK

npm install tealtiger

Python SDK

pip install tealtiger

Quickstart

Get started in 5 minutes

API Reference

Complete API documentation