Ultra is aligned with and an early contributor to AARM and the Agentic Trust Control Framework.

Products/Anomaly detection
Anomaly detection

Catch what rules miss.

An LLM-as-judge scores every tool call across seven threat categories with a 0 to 1 risk score, a confidence level, and a one-line explanation, using the full per-session history rather than a single call in isolation.


01 · How it works

Background scans that learn what normal looks like.

Analysis runs asynchronously, so it never slows a request. Findings roll up on a schedule you set, from 15 minutes to 24 hours, and alert to Slack on high or critical risk. Run it passively for visibility, or in blocking mode above a risk threshold you choose.

Coverage

Seven threat categories

Every call is judged for injection, exfiltration, privilege escalation, reconnaissance, unusual patterns, data-volume abuse, and rug pulls, with the full per-session history in view.

Scoring

Five risk levels, scored 0 to 1

Findings land in none, low, medium, high, or critical, with a numeric score and a confidence level so you can tune exactly where to pay attention.

Narratives

Full attack narratives

Related events are assembled into a single narrative with an explanation and a recommended action, instead of a stream of disconnected alerts.

Operations

Passive or blocking, on your schedule

Run async for zero added latency, choose a scan frequency from 15 minutes to 24 hours, optionally block above a threshold, and alert to Slack on high or critical.


02 · The judge

A judgment on every call.

An LLM-as-judge evaluates each tool call against the session so far and returns a risk level, a score, the categories it matched, a confidence, and a one-line explanation, then recommends allow, alert, or block.



Catch the compromise rules can't see.

Join the waitlist to get early access to Ultra's AI-native security and governance.