Getting Started
What is Cernexa?
Endpoint security for the agentic era — discover, score, and govern everything your endpoints install.
Your EDR sees binaries. Your endpoints run everything else.
Modern developer and AI workstations install a huge amount of software that never passes through traditional endpoint protection: browser extensions, npm and PyPI packages, IDE extensions, MCP servers that hand tools to AI agents, and AI models pulled from public hubs. This is the install surface attackers now target — through typosquats, compromised maintainers, and supply-chain takeovers.
Cernexa makes that surface visible and governable. It discovers every marketplace artifact across your fleet, scores each one with the Crucible engine, and lets you enforce policy — preventively in CI and at install time, and continuously as your agents report.
The three things Cernexa does
- Discovery — A lightweight agent on each endpoint reports the extensions, packages, IDE plugins, MCP servers, and models it finds. Everything lands in one inventory, deduplicated across your fleet. See Discovery & the Crucible score.
- Scoring — The Crucible engine gives every artifact a 0–100 risk score built from named, explainable signals: dangerous permissions, network egress, known CVEs, active exploitation, publisher reputation, supply-chain drift, and agentic-AI risks like auto-approved tool calls. Nothing is a black box — every point traces to a signal.
- Governance — Write preventive policies that auto-approve, block, or flag installs by risk, type, or publisher. Make org-wide allow/block decisions that follow software across versions and endpoints. Gate installs before they ever reach a machine with the Supply Chain Gateway.
What Cernexa covers
- Browser extensions — Chrome, Edge, Brave, and more
- Code packages — npm, PyPI, Homebrew
- IDE extensions — VS Code, Cursor
- MCP servers — the tool access layer for AI agents
- AI models — local and remote
How risk is expressed
Every artifact gets a verdict derived from its Crucible score:
- Safe (0–9)
- Low (10–29)
- Medium (30–54)
- High (55–79)
- Critical (80–100)
You'll see these verdicts everywhere — the dashboard, Discovery, Exposure, and on every artifact's detail page, always backed by the itemized signals that produced the score.