Yamong Security

AI Security for the Real World

AI Agent의 발견부터
실행 검증까지,
안전하게.

조직의 모든 AI Agent를 발견해 Identity·Role·Tool·Data·Resource를 하나의 Security Graph로 연결합니다. Agent가 할 수 있는 것(Authority) 해야 하는 것(Role)
비교하고, 실제 Execution까지 검증합니다.

Discover
Understand
Assess
Protect
Verify

AI는 이제 답변을 넘어,
직접 행동합니다.

Tool을 호출하고, 파일을 읽고, API를 통해 실제 시스템을 변경합니다.

CodeShellFileAPIDatabaseToolMCP

그만큼 생산성도 커지지만, 리스크도 함께 커집니다. Yamong은 AI Agent Security Platform으로 이 행동을 발견하고, 이해하고, 보호하고, 검증합니다.

Discovery + Security Graph

조직의 모든 AI를 발견하고, 무엇과 연결되어 있는지 이해합니다.

Endpoint, Server, Cloud, Kubernetes 전반에서 AI Agent, Model, Tool, MCP는 물론 Shadow AI까지 발견합니다.

EndpointsServersCloudKubernetesAI AgentsModelsToolsMCPShadow AI

Agent → Identity → Role → Tool → Data → Resource

Identity / Role / AgentModelToolData / Resource

AI-SPM

어떤 AI가 어디까지 접근 가능한지, 먼저 보여줍니다.

개별 취약점 목록이 아니라, Agent가 실제로 어디까지 도달할 수 있는지를 관계와 경로로 보여줍니다.

Configuration RiskPermissionsExcessive AccessPublic ExposureCredential RiskSensitive Data AccessAttack Path
78/ 100

Posture Score

Potential Attack Path

Internet
Public exposure
AI Agent
CustomerSupportAgent
IAM Role
support-agent-role
Privileged Role
Excessive permissions
Sensitive Data
customer-data

Agent Role & Authority

Role은 해야 하는 일을, Authority는 할 수 있는 일을
말합니다.

Role은 Agent가 일반적으로 해야 하는 일, Authority는 기술적으로 할 수 있는 일, Purpose는 지금 해야 하는 일, Action은 지금 하려는 일입니다.

FinanceAnalyst

사용자 요청: “이번 달 AWS 비용을 분석해줘

Agent Role무엇을 해야 하는가
Finance Analysis
Actual Authority기술적으로 무엇을 할 수 있는가
iam:CreateAccessKey = allowed
Current Purpose지금 무엇을 해야 하는가
Cost Analysis
Requested Action지금 무엇을 하려 하는가
iam.create_access_key
HIGH RISK

Allowed by IAM, but outside Role and Task Purpose.

Flight Recorder

사용자 요청부터 실제 시스템 영향까지 검증합니다.

User Intent부터 실제 시스템 Effect까지, 하나의 흐름으로 재구성합니다.

User Request
고객 데이터 조회 요청
Task
User Intent
Agent
CustomerSupportAgent
Tool
search_orders
API
api.internal:443
Process
python
File / Network
customers.csv
Resource Effect
orders_db 변경
확장 방향

현재 Runtime Protection은 Prompt, Tool Call, API 요청을 실시간으로 검사합니다. Process·File·Network까지 이어지는 전체 Execution Verification은 Yamong Flight Recorder의 확장 방향입니다.

Flight Recorder · 확장 방향

CustomerSupportAgent를 기준으로 한 Execution Verification 확장 방향 예시입니다.

Event Timeline (5 events)

  1. 11:23:09Tool Call — search_orders
  2. 11:23:12Process — python
  3. 11:23:14File Read — customers.csv
  4. 11:23:18Network — api.internal:443

    Unusual destination for this task

  5. 11:23:21Database Query — SELECT * FROM orders

    Outside declared Role scope

Yamong Console

지금까지 설명한 기능이, Yamong Console에서는 이렇게 보입니다.

실제 Console과 동일한 컴포넌트로 구성했습니다. Discovery, Security Graph, Posture, Runtime을 한 화면에서 확인합니다.

Yamong Console · Overview

Total AI Assets
482+18%
High Risk Agents
29+5
Posture Score
78+3
Runtime Events
1,247+9%
NameTypeEnvironmentStatusRisk
CustomerSupportAgentagentAWS · EKS · ProductionActiveMedium
FinanceAnalystagentAWS · EKS · ProductionActiveHigh
CodeAssistantagentLinux · On-premRunningMedium
MarketingAgentagentGCP · Cloud RunInstalledMedium
DataResearcheragentAzure · AKSRunningLow

Top Risky Agents

  • FinanceAnalystHigh
  • CustomerSupportAgentMedium
  • CodeAssistantMedium
  • MarketingAgentMedium
데모에서 전체 보기 →

Built for Enterprise

실제로 작동하는 기술 위에 세운 Enterprise Security입니다.

지금 가능한 것과 앞으로의 방향을 구분해서, 있는 그대로 보여드립니다.

Model-independent

특정 LLM 벤더에 종속되지 않고 조직이 사용하는 모든 모델을 지원합니다.

Multi-environment Architecture

Endpoint · Server · Cloud · Kubernetes를 하나의 관점으로 다루는 방향으로 설계됩니다.

Endpoint · Cloud · Kubernetes 확장 구조

Kubernetes와 On-prem 환경까지 포함하는 커버리지를 목표로 합니다.

Auditability

모든 판단 근거를 감사 가능한 형태로 기록합니다.

확장 가능한 Integration 구조

IAM, EDR, OTel 등 기존 보안·관측 인프라와 연동할 수 있도록 설계됩니다.

Enterprise Deployment

On-prem과 SaaS 배포를 함께 고려한 아키텍처입니다.

AI Agent가 무엇을 할 수 있는지뿐 아니라,실제로 무엇을 하는지까지 확인하세요.