When an agent
goes rogue,
you see it first.
Autonomous AI agents now run inside every enterprise. Elendil detects the ones that go rogue — exfiltrating data, probing or attacking systems, acting beyond their mandate — from behaviour and content, every alert explained, the engine air-gapped. The same platform that catches financial-crime rings, turned on the newest adversary: AI itself.
Sovereign by design
Core infrastructure, keys, and data residency stay in Europe — outside US cloud jurisdiction.
Explainable, not opaque
Every flag is auditable, with evidence a human and a regulator can follow.
Lawful & proportionate
Scoped to GDPR, the AI Act, AMLR, and sectoral law, with data-minimisation built in.
Domains of intelligence
Three adversaries. One graph.
We focus on the intersection of adversarial AI and deep financial networks — exposing behaviour that stays hidden in siloed, row-based systems.
AI agents gone rogue
Detect autonomous agents that go off-mission — exfiltrating data, probing or attacking systems, acting beyond their mandate. Caught from behaviour and content, not from what they were told to do.
- Exfiltration & unauthorised egress
- Intrusion & attack-tooling in agent traffic
- Off-envelope, off-mandate behaviour
Financial crime & fraud
The same engine, proven on money: expose fraud rings, mules, and synthetic identities exploiting instant payments and cross-border rails before losses crystallise.
- Mule & money-laundering networks
- Synthetic identity clusters
- Scam-as-a-service infrastructure
Coordinated agent fleets
Sniff out fleets of agents driven by one hand — coordinated manipulation, platform abuse, and influence operations run at machine scale across open information spaces.
- Coordinated inauthentic agent rings
- Fleet attribution from behaviour
- Narrative & amplification mapping
The pipeline
From raw signal to lawful action.
A single chain of custody — from ingestion to enforcement — so institutions can act quickly without acting blindly.
Ingest & normalise
Unify fragmented public, on-chain, and regulated financial signals into one analysable substrate — under contract and law.
Resolve entities
Link people, accounts, devices, businesses, and wallets into a graph that exposes rings invisible to row-based systems.
Detect & explain
Rules, graph analytics, and ML surface illicit behaviour — every alert carries human-readable evidence, not a black-box score.
Route action
Push findings into case management, KYC/KYB, and transaction controls: step-up checks, payout holds, account review.
Our products
One explainable core. Two products.
The operator console where institutions investigate, and ARNOR — the on-premises engine for autonomous-AI governance and cyber defence that surfaces inside the very same console.
The social contract
We monitor behaviour to protect the public — and submit that monitoring to European law.
We are explicit about what we do. We analyse publicly available information and financial data — including personal data — to identify fraud, illicit AI activity, and manipulation against clearly defined risk and illegality criteria.
We do it with European infrastructure, under European legal control, with auditable safeguards and defined routes to contest. No privacy-washing, no opaque surveillance.
Read the full manifestoBuilt by the public, for the public.
Europe should not have to choose between security and sovereignty. We are building the trust layer that refuses the trade-off.