NON-HUMAN IDENTITY SECURITY THE WORLD'S FIRST NHI PLATFORM.

53 modules. 10 security layers. Every credential gated.

▶ Validated against T144 SPECTER CHANGELING — world-first NHI red team tool

144 NHIs PER HUMAN IDENTITY IN ENTERPRISE · 292 DAYS TO DETECT COMPROMISED NHI CREDENTIAL · 97% OF NHIs HAVE EXCESSIVE PRIVILEGES · MIDNIGHT BLIZZARD: OAUTH APP TO SENIOR LEADERSHIP EMAILS · 91% FORMER EMPLOYEE TOKENS STILL ACTIVE · $11.3B NHI SECURITY MARKET BY 2028 · SPECTER CHANGELING: WORLD-FIRST NHI RED TEAM TOOL — 30 PAYLOADS ACROSS 5 WMD CATEGORIES · A2A AGENT CARDS NOW AN ACTIVE NHI ATTACK SURFACE · COPILOT STUDIO: OAUTH TOKENS STOLEN FROM MICROSOFT DOMAIN · M161 NHI INTEGRITY SENTINEL: 18 DETECTORS, ZERO TRUST · 144 NHIs PER HUMAN IDENTITY IN ENTERPRISE · 292 DAYS TO DETECT COMPROMISED NHI CREDENTIAL · 97% OF NHIs HAVE EXCESSIVE PRIVILEGES · MIDNIGHT BLIZZARD: OAUTH APP TO SENIOR LEADERSHIP EMAILS · 91% FORMER EMPLOYEE TOKENS STILL ACTIVE · $11.3B NHI SECURITY MARKET BY 2028 · SPECTER CHANGELING: WORLD-FIRST NHI RED TEAM TOOL — 30 PAYLOADS ACROSS 5 WMD CATEGORIES · A2A AGENT CARDS NOW AN ACTIVE NHI ATTACK SURFACE · COPILOT STUDIO: OAUTH TOKENS STOLEN FROM MICROSOFT DOMAIN · M161 NHI INTEGRITY SENTINEL: 18 DETECTORS, ZERO TRUST ·

Ten Security Layers

The full NHI kill chain — Discovery through Emergency Response. 53 modules enforcing identity integrity at every layer of the AI agent stack, from authentication gating to fleet-wide exploitation detection.

LAYERS 2-3 // RUNTIME & CREDENTIALS
ENFORCING

Identity Runtime & Credential Lifecycle

Module 101 intercepts every agent authentication attempt at the point of execution. Module 20 verifies identity. Module 49 governs credential lifecycle — secret scanning, privilege analysis, Ed25519-attested attestation. Module 161 monitors token anomalies, orphaned NHIs, and OIDC spoofing with 18 real-time detectors.

M101 + M161Runtime & NHI Integrity Anchors
LAYERS 4-5 // DELEGATION & FLEET
MONITORING

Delegation Chains & NHI Fleet Detection

Module 33 enforces cryptographically attested delegation scope with Ed25519-signed tokens and cascading revocation. Module 36 governs the full agent lifecycle from provisioning to decommissioning. The new NHI Fleet layer adds M122 (fleet exploitation detection), M147 (cloud IAM lateral movement), and M149 (orchestration trust chain validation).

Layer 5NHI Fleet & Discovery — NEW
LAYERS 6-10 // DETECTION & RESPONSE
ACTIVE

API Integrity, Compliance & Emergency Response

Module 28 secures the MCP/A2A tool surface with ETDI + OAuth 2.0 attestation. Module 103 provides Ed25519-attested API call verification with rotation and replay prevention. Module 37 automates EU AI Act, NIST, and ISO 42001 compliance. Module 99 provides fleet-wide emergency credential revocation across all agent identities.

Module 99Emergency Credential Revocation
MODULE OVERVIEW
0
Modules Active
0
Specialist Modules
0
Security Layers
Module 101
Agent Identity Runtime Control
AUTH GATING
Intercepts every agent authentication attempt. Policy-based allow, deny, or escalate — at the point of execution
IMPERSONATION
Detects AI agents acting as human users. Session analysis, timing signatures, and interaction pattern matching
SPAWN CONTROL
Controls agent-to-agent creation. Privilege inheritance rules, max spawn depth, mandatory registration of sub-agents

M161 — NHI Integrity Sentinel

18 real-time detectors covering the full NHI threat surface — from token anomalies and OIDC spoofing to shadow NHI creation and cross-tenant correlation. The only module purpose-built for runtime NHI integrity monitoring.

IDENTITY
IDENTITY-DRIFT
Detects gradual divergence from established NHI behavioural baselines. Flags credential use patterns that no longer match the registered identity profile.
SPOOFING
SPOOF-DETECT
Identifies spoofed NHI tokens, forged agent cards, and impersonation attempts at the protocol layer. Validates OIDC claims against registered issuer metadata.
REVOCATION
REVOCATION-CHECK
Continuously validates that revoked credentials are not still accepted downstream. Detects revocation-gap attacks where tokens survive their kill signal.
ANOMALY
TOKEN-ANOMALY
Flags anomalous token usage patterns — unusual call frequency, unexpected scope claims, off-hours access, and volume spikes against established baselines.
LIFECYCLE
LONG-LIVED-TOKEN
Detects tokens exceeding maximum permitted lifetime. Identifies NHI credentials operating beyond their authorised rotation window.
OAUTH
SILENT-REFRESH-ABUSE
Catches OAuth silent refresh chains used to extend NHI credential persistence beyond session boundaries without explicit re-authorisation.
GOVERNANCE
ORPHANED-NHI
Discovers NHIs with no active owner, expired governance record, or decommissioned parent agent. The highest-risk governance blind spot.
PRIVILEGE
ESCALATION-WATCH
Monitors for privilege escalation attempts via NHI credentials — scope expansion, role assumption chains, and IAM policy manipulation.
CRYPTO
KEY-MONITOR
Tracks cryptographic key usage and rotation compliance. Flags keys operating beyond their authorised rotation schedule.
BEHAVIOUR
CALL-PATTERN-DRIFT
Detects unusual API call sequences from NHI endpoints — endpoint enumeration, API abuse, and call patterns inconsistent with the registered role.
TOOLING
TOOL-INVOCATION-ANOMALY
Flags unexpected tool calls from known NHI identities. Detects agents invoking tools outside their authorised capability scope.
CORRELATION
CROSS-AGENT-SPIKE
Identifies correlated NHI activity spikes across multiple agents — coordinated credential abuse campaigns invisible to per-agent monitoring.
COVERAGE
BLIND-SPOT-SCAN
Discovers NHIs invisible to existing monitoring coverage. Identifies identity governance gaps before attackers exploit them.
SHADOW
SHADOW-NHI
Detects unregistered, unauthorised NHI creation — shadow service accounts, rogue API keys, and agent identities outside the governance perimeter.
COMPLIANCE
COMPLIANCE-DRIFT
Tracks NHI governance posture changes against OWASP NHI Top 10, NIST, and EU AI Act requirements. Flags degrading compliance in real time.
VALIDATION
THIRD-PARTY-VALIDATION
Validates external NHI claims from third-party systems and federation providers. Detects trust chain manipulation at integration boundaries.
VENDOR
VENDOR-SCOPE-CREEP
Monitors for expanding vendor NHI permissions over time — the silent privilege accumulation pattern that precedes supply chain compromise.
FORENSICS
TIMELINE-RECONSTRUCTION
Reconstructs complete NHI activity timelines for forensic analysis. Ed25519-signed reports with tamper-evident hash chains and unique NHI incident identifiers.
L5
New Layer // NHI-Specific Detection
NHI Fleet & Discovery

The only platform layer dedicated entirely to NHI fleet-wide attack detection. Covers the full discovery-through-exploitation kill chain — shadow NHI identification, cloud IAM lateral movement, orchestration credential abuse, and fleet-scale exploitation patterns. No competitor covers all four.

M34 Shadow Agent Discovery
M122 NHI Fleet Exploitation Sentinel
M147 Cloud Identity Sentinel
M149 AI Orchestration Guard
DISCOVERY
M34 — Shadow Agent Discovery
Two-layer detection (signature + behavioural fingerprinting) across 34 AI providers. Discovers unsanctioned NHIs operating outside the governance perimeter. 5-tier risk classification with OAuth/SSO monitoring.
FLEET
M122 — NHI Fleet Exploitation Sentinel
Fleet-wide NHI exploitation detection — the primary defensive counterpart to T122 SPECTER GHOST. Detects mass NHI credential harvest, trust graph pivots, and LLMjacking campaigns across the full agent fleet.
CLOUD
M147 — Cloud Identity Sentinel
Cloud IAM lateral movement detection for AI deployments. Covers AWS/GCP/Azure NHI privilege escalation, IMDS credential harvest, and cross-cloud identity pivots — the highest-value NHI attack path in 2026.
ORCHESTRATION
M149 — AI Orchestration Guard
JWT trust chain validation, phantom model credential routing, and delegation cycle detection across n8n/CrewAI/Langflow/AutoGen/Flowise. Validates MCP server integrity against SHA-256 baselines.
L9
New Layer // Emerging NHI Attack Surface
API & Protocol Integrity

The emerging NHI credential exchange surface — MCP tool calls and A2A Agent Card interactions are now active attack vectors. Layer 9 secures the protocol layer where NHI credentials are negotiated, exchanged, and attested. World-first A2A NHI coverage.

M28 MCP/Tool Security Gateway
M47 A2A/Inter-Protocol Security Gateway
M103 Quantum AI Security Engine
MCP
M28 — MCP Tool Security Gateway
ETDI + OAuth 2.0 tool registration, SHA-256 metadata integrity, rug-pull detection, and schema poisoning prevention. Secures the MCP layer where NHI credentials are scoped and delegated to tools.
A2A
M47 — A2A/Inter-Protocol Gateway
A2A spec enforcement including Agent Card validation (/.well-known/agent.json), task.status.update SSE stream integrity, and agents/discover registration security. The only platform covering A2A as an NHI attack surface.
POST-QUANTUM
M103 — Quantum AI Security Engine
PQC-grade NHI credential attestation — ML-DSA-65/87 signing for agent API calls, ML-KEM-768/1024 for credential transport. Ensures every NHI-originated API call is quantum-resistant from issuance through verification. NIST FIPS 204/203 compliant.

The NHI Kill Chain — Covered End to End

No competitor covers the complete NHI attack lifecycle. Specter AI Identity is the only platform with enforcement at every phase.

1
Discovery
M34 / M122
Shadow NHI
Fleet scan
2
Identity Runtime
M101 / M20
M49 / M31
M47 / M19
3
Credential Lifecycle
M23 / M30
M72 / M103
M161
4
Delegation Chains
M33 / M27
M85 / M36
5
Fleet Exploitation
M34 / M122
M147 / M149
6
Compliance
M37 / M25
M44 / M89
M24
7
Emergency Response
M90 / M91
M92 / M99
▲ Red Team Validated
Validated Against T144 SPECTER CHANGELING

SPECTER CHANGELING is Red Specter's world-first NHI red team tool — 30 payloads across 5 WMD categories: agent_identity_mass_spoofing, oauth_token_harvest_and_pivot, service_account_escalation_chain, nhi_governance_blind_spot_exploit, and persistent_agent_identity_backdoor. Every attack surface CHANGELING can exploit is covered by at least one Specter AI Identity module. Our defensive posture is built against real NHI attack payloads, not theoretical frameworks. OWASP NHI Top 10 — 10/10 coverage maintained with all 53 modules active.

"The world's most comprehensive NHI security platform — 53 modules, 10 layers, every attack surface covered."

Astrix, Oasis, and Aembit can see your AI agent credentials. We enforce what those agents do with them — at runtime, at the point of execution, across every delegation chain and fleet endpoint. Specter AI Identity is not another inventory tool. It is the enforcement layer between autonomous AI and your identity infrastructure — validated against real NHI attack payloads from T144 SPECTER CHANGELING, the world's first NHI red team tool.

53
Modules protecting agent identity
54
Docker containers deployed
18
M161 NHI detection subsystems
10/10
OWASP NHI Top 10 coverage
10
Security layers

The Only Platform That Covers the Full NHI Kill Chain

53 modules across 10 security layers. A2A Agent Card security. Runtime NHI integrity monitoring with 18 detectors. Validated against T144 SPECTER CHANGELING — the world's first NHI red team tool. This is what comprehensive NHI security looks like.