AI agent security

AI agent security for small businesses, on a Mac

You don’t need a security team to run agents safely. You need four controls that are on by default: sealed keys, least privilege, a human gate for changes, and a log.

The short answer

Securing an AI agent comes down to four controls: keep credentials where the agent can’t read them, give each agent only the access its job needs, make any change wait for a person, and log every access. MoltenRock puts all four on a Mac: Secure Enclave storage, per-agent grants, Touch ID approval in MoltenRock Connect’s Human Queue, and an Activity log.

The problem

Agents fail in ways normal software doesn’t

  • Prompt injection
    An email, ticket or web page can carry instructions. An agent with broad access may follow them.
  • Credential leaks
    Keys pasted into chats, config files and logs get copied, synced and committed.
  • Too much reach
    One key per platform, shared by every agent, means a mistake in one place is a mistake everywhere.

How MoltenRock handles it

Four controls, on by default

  • Sealed credentials
    Keys live in the Secure Enclave. Agents without a grant can’t read them, and tools on MoltenRock Connect never get them at all.
  • Least privilege
    Grants are per agent and per secret: read, write or resolve. Email agents get their own tokens; rotate one and old access dies.
  • A human gate
    On Stripe, agents propose; you approve with Touch ID. Everywhere else in Connect, agents can only read.
  • An audit trail
    Every grant, unlock and denial is written to the Activity log on your Mac.

How it works

A secure setup in an afternoon

  1. 01
    Inventory the keys
    List every API key your agents use today. Move each into MoltenRock and delete the plain-text copy.
  2. 02
    Grant per agent
    Give each agent the secrets and mailboxes its job needs, nothing more.
  3. 03
    Route changes through the Human Queue
    Connect your business tools to MoltenRock Connect so agents read freely and propose changes you approve.
  4. 04
    Review weekly
    Skim the Activity log. Remove grants nobody used.

Straight answer

What this does and doesn’t cover

Stays on your Mac

  • Credentials, grants and approvals, on your Mac
  • The record of every access
  • Changes on Stripe, until you approve them

Leaves your Mac

  • What your agent sends to a cloud AI model, if it uses one
  • Direct calls to the platforms you connect
  • MoltenRock does not scan your network or replace endpoint security

Questions

What people ask first

Does this stop prompt injection?

It limits what an injected instruction can do. An agent can’t read keys it wasn’t granted, can’t change anything on Stripe without your approval, and can only read on the other Connect platforms. Every attempt is logged.

Do my team members each need it?

MoltenRock runs per Mac. One Pro licence covers up to five Macs. Team Human Queues, where approvals flow up to a manager, are on the roadmap.

Where are keys stored?

In a vault protected by your Mac’s Secure Enclave and encrypted at rest. There is no MoltenRock account or server.

Can I leave later?

Yes. Leaving writes your keys back to where they came from. It is fully reversible.

Security your agents can’t talk their way around.

Free for Mac. Pro from $9.99 a month.