RelayShield's Consumption Security API Bundles deliver metered access to focused sets of threat intelligence and identity risk detection capabilities, billed entirely through AWS Marketplace. Each bundle is licensed independently, with no dependency on any other bundle. Bundle D, Agentic Attack Surface, covers MCP registry risk, prompt-injection breach correlation, agent-framework CVE targeting, bulk per-agent identity risk scoring, and LLM Credential Exposure Detection.
Bundle D: Agentic Attack Surface is built for the emerging risk of AI-agent-driven attacks. It includes MCP registry risk scoring (detecting typosquatted or newly-registered AI agent tool servers), prompt-injection breach correlation (surfacing exposed sessions tied to prompt-injection attacks via infostealer log analysis), agent-framework CVE targeting risk (CVE exposure scoped to your declared agent stack, LangChain, AutoGPT, CrewAI, and similar), bulk per-agent identity risk scoring across up to 10 domains and 5 agents each, purpose-built for AI governance programs and MSP client sweeps, and LLM credential exposure detection to detect exposed LLM/AI provider API keys (OpenAI, Anthropic, Google, Groq, xAI, Replicate) in criminal stealer logs.
All endpoints are backed by RelayShield's live threat intelligence corpus: 5.0M+ indicators of compromise, 3,750+ malware families, and 85+ monitored criminal Telegram marketplaces. Billing note: the monthly minimum commitment applies whether or not you call a given security function that month, and per-Unit charges apply only to the functions you actually call above the included baseline. Your API key is issued automatically by email when your AWS Marketplace subscription activates, with full usage instructions included. All access is provisioned and billed through AWS Marketplace.
Highlights
Each bundle is licensed independently through AWS Marketplace, with no dependency on any other bundle or platform-wide subscription.
Contract-with-consumption pricing: a minimum monthly commitment covers included usage, with transparent per-call pricing for anything above that baseline.
Backed by RelayShield's live threat intel corpus: 5.0M+ IOCs, 3,750+ malware families, 85+ monitored criminal Telegram marketplaces.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor, and additional usage. You pay upfront or in installments according to your contract terms with the vendor. This entitles you to a specified quantity of use for the contract duration. Usage-based pricing is in effect for overages or additional usage not covered in the contract. These charges are applied on top of the contract price. If you choose not to renew or replace your contract before the contract end date, access to your entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
This bundle prices Agentic Attack Surface API access. You buy usage in Units across five independent security functions: agent identity risk scoring, agent framework exploit monitoring, MCP registry risk, prompt injection breach detection, and LLM credential exposure detection. Each function is billed per Unit, so cost scales with how many calls you make to that function. A sixth dimension sets a monthly minimum commitment for overall API access, covering all five functions. You mix and match the individual functions as needed while meeting that monthly access baseline.
Top-of-mind questions for buyers
What counts as one Unit for these Agentic Attack Surface functions?
One Unit equals one API call to that function's endpoint. For example, one agent framework exploit check, one MCP registry lookup, or one prompt injection breach scan each consume a Unit. Cost accrues per call, so your usage tracks the number of checks you run.
How do the five function charges combine with the monthly access commitment on my bill?
The Agentic Attack Surface Monthly Access dimension sets a monthly minimum for API access. Each of the five functions then bills independently per Unit as you call it. Whichever function you use most drives the largest share. All charges appear together while your usage meets the monthly access baseline.
Am I charged if I make no calls to a given security function in a month?
You are charged only for calls you make to each function. A function you do not call adds no per-Unit cost that month. However, the Agentic Attack Surface Monthly Access commitment sets a minimum spend for overall API access, which applies regardless.
api.relayshield.net
Helpful?
Vendor refund policy
The monthly minimum commitment and metered usage charges are billed in arrears and are generally non-refundable once incurred. RelayShield will issue a full or partial refund for verified billing errors, duplicate charges, or a service outage attributable to RelayShield. To request a refund, contact us at support.relayshield.net within 30 days of the disputed charge.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
API-Based Agents and Tools integrate through standard web protocols. Your applications can make API calls to access agent capabilities and receive responses.
No account-level secret is required to connect. Each tool call takes your RelayShield API key as a parameter, so you're only billed for the calls you make.
Tools
check_mcp_server_risk Checks an MCP server URL for typosquat risk, presence in RelayShield's criminal IOC corpus, and domain-registration age. Returns CRITICAL/HIGH/MEDIUM/LOW with findings. Params: server_url, api_key
check_prompt_injection_breach Checks an email for credential exposure sourced specifically from prompt-injection attacks against AI agents, distinct from ordinary phishing/malware breaches. Params: email, api_key
check_tech_stack_cve Checks a declared AI agent framework / tech stack for CISA KEV or high-EPSS CVEs currently being exploited. Params: tech_stack (comma-separated, e.g. "langchain, nacos, minio"), api_key
check_bulk_identity_risk Hierarchical org + AI-agent-identity risk scoring for a domain and up to 5 agent/service-account identities. A critically-exposed agent elevates the org's overall rating. Params: domain, agent_emails (comma-separated, up to 5), api_key
check_llm_credential_exposure Checks a domain for exposed LLM/AI provider API keys (OpenAI, Anthropic, Google, Groq, xAI, Replicate) in criminal stealer logs from LLMjacking, where a leaked key becomes a live, uncapped billing liability. Params: domain, api_key
Getting an API key
Your API key is generated automatically and emailed to you when your AWS Marketplace subscription activates. No separate signup step is required.
Support
Vendor support
Email support: support@relayshield.net. Full API documentation, authentication steps, endpoint URLs, and sample requests are included in this product's Usage Instructions. Response within 1 business day for standard issues.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
RelayShield delivers threat intelligence and identity security via REST API - 4.5M+ IOC corpus, breach detection, SIM swap monitoring, infostealer exposure, ransomware victim tracking, and session hijack detection. Built for MSPs, MSSPs, and security-forward development teams.
RelayShield Core Identity Exposure delivers metered access to six identity threat detection APIs, billed entirely through AWS Marketplace. It covers breach exposure, SIM swap detection, infostealer log checks, domain lookalike detection, OAuth token exposure, and crypto threat intelligence. The bundle is licensed independently, with no dependency on any other RelayShield product or bundle.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.