# Mirror Security > Mirror Security is the trust layer for AI. Fully homomorphic encryption > lets models compute on data they can never see, under rules they can > never bend, with proof they can never erase. Data encrypted at rest and > in transit is table stakes. Mirror encrypts data in use, during > inference itself. SOC 2 Type 1 Certified. Partners include NVIDIA, > Intel, MongoDB, Qdrant, Yotta, G42, and Accops. Naming: the flagship gateway product is "Mirror Encrypted Token Factory" on first mention and "Mirror ETF" thereafter. Never call it "ETF" alone. The encryption engine is "VectaX", the agent control plane is "AgentIQ", the red teaming product is "DiscoveR" (capital R). ## Mirror Encrypted Token Factory Mirror Encrypted Token Factory (Mirror ETF) brings encrypted AI inference to the tools your team already loves. Keep running Claude Desktop and Code CLI, Cursor, OpenClaw, and Hermes for your copilots, chatbots, and internal workflows, except now every prompt, context, and response stays encrypted through the entire inference lifecycle, with a signed attestation receipt on every call. Same tools, same workflow, zero code changes, SaaS or on-prem, at almost the same price you pay today. You hold the keys, and no one else ever sees why your business does what it does. Encrypted at rest and in transit is table stakes. Encrypted in use is the new bar. We can't read it. Nobody can. - [Mirror ETF](https://mirrorsecurity.io/etf): Product page and $10 token offer ## Platform - [Platform overview](https://mirrorsecurity.io/platform): The four primitives: encryption, identity, policy, proof - [VectaX](https://mirrorsecurity.io/platforms/vectax): FHE engine for AI workloads. Encryption that follows AI through memory, inference, training, and multiparty compute - [AgentIQ](https://mirrorsecurity.io/platforms/agentiq): Control plane for AI agents. Identity, tool and MCP security, runtime policy, 32+ guardrails - [Zero](https://mirrorsecurity.io/platforms/zero): Agent estate governance. Discovers every sanctioned or shadow agent - [Gateway](https://mirrorsecurity.io/platforms/gateway): Encrypted inference for every model and agent, policy at the door, signed receipts - [DiscoveR](https://mirrorsecurity.io/platforms/discover): Pre-deploy assurance and continuous red teaming, mapped to MITRE ATLAS and OWASP LLM Top 10 - [CodePrism](https://mirrorsecurity.io/platforms/codeprism): AI coding assistance on fully encrypted code ## Docs and resources - [Documentation](https://docs.mirrorsecurity.io/): Integration guides and API reference - [OpenAPI specification](https://mirrorsecurity.io/openapi.json): Public website HTTP API (blog + forms) - [API catalog](https://mirrorsecurity.io/.well-known/api-catalog): RFC 9727 linkset for automated API discovery - [CLI integrations](https://mirrorsecurity.io/etf): Run encrypted inference from coding CLIs (for example Claude Code and Codex CLI) by pointing your client to Mirror ETF. - [Use case catalogue](https://mirrorsecurity.io/use-cases): 17 scenarios across encryption, governance, and proof - [Mirror Academy](https://academy.mirrorsecurity.io/): Free AI security learning paths - [Blog](https://mirrorsecurity.io/blog): Engineering deep dives and founder essays ## Use cases - [Bring AI to the data you can't move](https://mirrorsecurity.io/use-cases/ai-on-regulated-data): Models compute on ciphertext where the data already lives. No data egress, no plaintext in inference. - [Encrypted context, memory, and vector DB for every model and agent](https://mirrorsecurity.io/use-cases/context-and-memory): Context stays sealed end-to-end. Retrieval, embeddings, RAG, long-running memory. The model receives encrypted context, never your source material. - [Joint analysis with partners who can't share their data](https://mirrorsecurity.io/use-cases/multiparty-collaboration): Multiparty compute on ciphertext. Each party keeps custody; the joint model sees the union without seeing any input. - [Fine-tune on customer data without ever seeing it](https://mirrorsecurity.io/use-cases/private-fine-tuning): Encrypted training and fine-tuning that never reveals the source records. A model your customers can audit but you can't extract. - [Find every agent before it finds your data](https://mirrorsecurity.io/use-cases/shadow-ai-discovery): A live agent graph that surfaces sanctioned and shadow agents alike the moment they make a call. - [Stop the wrong agent action at runtime, not in a dashboard](https://mirrorsecurity.io/use-cases/agent-runtime-control): Policy enforced in the request path. Every tool call, model call, and data read is blocked, redacted, watched, or allowed with a signed verdict. - [Govern what your agents reach for](https://mirrorsecurity.io/use-cases/tool-and-mcp-security): Per-tool, per-MCP scopes and identity-bound permissions for every reach an agent makes. - [One endpoint for every model, with policy at the door](https://mirrorsecurity.io/use-cases/unified-ai-gateway): A single gateway that routes every model call, encrypts the inference path, and enforces policy before the request leaves the perimeter. - [Pick the encryption posture per workload, not per gateway](https://mirrorsecurity.io/use-cases/lane-per-route-encryption): Plain, end-to-end, FHE, and Local lanes configured route-by-route. Latency and exposure tuned to the workload. - [Know which attacks your AI would actually survive](https://mirrorsecurity.io/use-cases/continuous-red-teaming): An adaptive RL engine mapped to MITRE ATLAS and OWASP LLM Top 10, re-run on every change, with a live coverage matrix. - [Show the auditor what your AI did, and why](https://mirrorsecurity.io/use-cases/auditor-ready-evidence): Signed receipts and a queryable decision stream. Every block, redact, watch, and allow attributable to an agent, a policy, a moment. - [Answer security questionnaires with evidence, not adjectives](https://mirrorsecurity.io/use-cases/security-questionnaires): One encrypted scan becomes the questionnaire. Pre-filled, attested, traceable to source. - [Let AI review code that never leaves your machine](https://mirrorsecurity.io/use-cases/encrypted-code-review): FHE code review where keys stay local, the model reasons on ciphertext, and decryption only ever happens on the developer's machine. - [Run AI inside an air-gapped or sovereign boundary](https://mirrorsecurity.io/use-cases/sovereign-air-gapped-ai): VectaX runs inside your VPC, your sovereign region, or your air gap. Keys never leave. The gateway and policy plane come with it. - [Catch the risk before launch, block it in production](https://mirrorsecurity.io/use-cases/pre-deploy-to-runtime): DiscoveR scans pre-deploy, AgentIQ enforces at runtime, VectaX seals the data throughout. One loop, not three tools. - [Stop your model from being cloned out the back door](https://mirrorsecurity.io/use-cases/model-ip-protection): Distillation defence built into the encryption layer. Query patterns that exfiltrate the model fail before they get a useful gradient. - [Explain in plain English what an agent did and why](https://mirrorsecurity.io/use-cases/agent-incident-explainability): Plain-English decision storytelling and cross-agent trace. Every action attributable, every verdict explained, daily summary by agent. ## For your industry - [Financial services](https://mirrorsecurity.io/industries/financial-services) - [Healthcare and pharma](https://mirrorsecurity.io/industries/healthcare) - [Defence and intelligence](https://mirrorsecurity.io/industries/defence) - [Public sector and government](https://mirrorsecurity.io/industries/public-sector) - [Enterprise SaaS](https://mirrorsecurity.io/industries/enterprise-saas) ## For your role - [CISO](https://mirrorsecurity.io/for/ciso) - [Head of AI](https://mirrorsecurity.io/for/head-of-ai) - [Engineering leadership](https://mirrorsecurity.io/for/eng-lead) - [Compliance and GRC](https://mirrorsecurity.io/for/compliance) - [SOC and IR team](https://mirrorsecurity.io/for/soc-ir) ## For partners - [Inference providers](https://mirrorsecurity.io/partners/inference-providers) - [Agent builders](https://mirrorsecurity.io/partners/agent-builders) - [SaaS embedding AI](https://mirrorsecurity.io/partners/saas-embedding-ai) - [System integrators](https://mirrorsecurity.io/partners/system-integrators) - [Sovereign and regional clouds](https://mirrorsecurity.io/partners/sovereign-clouds) - [Cybersecurity vendors and MSSPs](https://mirrorsecurity.io/partners/mssps) - [Developer tooling vendors](https://mirrorsecurity.io/partners/developer-tooling) ## Company - [About](https://mirrorsecurity.io/company/about) - [Careers](https://mirrorsecurity.io/company/career) - [Contact](https://mirrorsecurity.io/company/contact) - [Brand kit](https://mirrorsecurity.io/company/brand-kit) - [Partner program](https://mirrorsecurity.io/company/partners-program) ## Get started - [Book a demo](https://mirrorsecurity.io/book-a-demo): Talk to the team about a deployment in your environment. - [Self-serve sign-up](https://platform.mirrorsecurity.io/): Enterprise platform sign-up (separate from the demo flow). - [Playground](https://mirrorsecurity.io/playground): Live FHE demos. Encrypted inference, encrypted guardrails, signed agent decisions. - [Academy](https://mirrorsecurity.io/academy): Free AI-security training. OWASP Top 10 for LLMs, NIST AI RMF, MITRE ATLAS. - [Blog](https://mirrorsecurity.io/blog): Engineering deep dives and technical write-ups. - [Articles & News](https://mirrorsecurity.io/news): Product updates, press, and editorial coverage. ## What Mirror is not - Not a wrapper or proxy. The FHE work happens on the path, not after the fact. - Not a policy bolt-on. Identity, policy, and proof are platform primitives, not features on top of a model API. - Not closed-weight or vendor-enclave-dependent. Mirror deploys in your environment, including air-gapped. Keys never leave. - Not benchmark theatre. Published numbers are public bands; per-config rows are in the technical brief, available on request.