Everest Security

One governed edge, optional surrounding controls.

Reference architecture for identity-aware enterprise AI security investigation with optional Aembit, CrowdStrike AIDR, Falcon MCP and live log evidence.

Everest Security reference architecture

Layers

LayerRole
AI client / BrainStormConversation, reasoning, local or hosted model, scheduled agent loop.
Aembit (optional)Human + agent access policy and credential brokerage.
StewardAuthentication, agent attribution, backend exposure, policy, audit and local STDIO runtime.
AIDR (optional)MCP content inspection and allow/block/redaction decisions.
Falcon MCPSecurity-platform context under Falcon API scopes.
Logs MCPLive distributed application/OS evidence, including security evidence records.

Interactive and unattended use

Interactive users can reach supported AD resources under their own authority. SecurityWatch runs under a dedicated automation identity and can be restricted to a separate security-profile backend.

Design principle

Ask at every hop: which identity or credential does the target resource actually authorise?