Marquor enforces what autonomous AI agents are authorized to do at the agent-to-tool boundary, and mints an Ed25519-signed, hash-chained receipt for every decision. Enterprise adds entitlement-aware capacity, default-deny egress, and sealed deployment.
Marquor Enterprise is the licensed, capacity-aware edition of Marquor's enforcement and evidence layer for AI agents. Every consequential action an agent takes, allowed and denied alike, becomes an Ed25519-signed, hash-chained receipt that verifies offline, with no call back to Marquor. Because the chain is hashed, a retroactive edit or deletion is detectable. A third party can check your evidence without trusting us.
Accountability you keep
Each receipt records what a given agent was permitted to do, what it did, and on whose delegated authority. That answers the question which arrives long after the action: not whether you have logs, but whose word your records rest on.
Logs are a system's account of itself.
A registry records design-time intent and does not constrain a running agent.
A periodic audit speaks to a control environment over a sample, not to this action on this day.
Marquor produces the per-action record none of those can, and you keep it as your own compliance artifact: producible to a regulator, a customer, an auditor or your insurer at renewal, without Marquor in the loop.
Payload-free by construction
Marquor evaluates declared metadata only. Prompts, files and transaction bodies are never collected: spend bands rather than amounts, digests rather than payees. The decision itself is deterministic, made in real time against verified identity and signed policy, no LLM sits in the decision path, so the same inputs give the same answer, in microseconds on CPU.
Works with the agents you already run
Because enforcement sits at the agent-to-tool boundary, Marquor governs agents whichever model or framework they are built on, and complements your existing identity layer rather than replacing it. You do not have to standardise your agent stack first. One control plane covers every enforcement point you deploy, whether that is an Amazon EKS cluster, EKS Anywhere, or a self-managed Kubernetes cluster in an isolated VPC.
What Enterprise adds beyond the trial edition
Enforcement is something you switch on, not something that happens to you: every policy can run in monitor mode first, so you see the decisions before any of them take effect.
Entitlement-aware capacity. The gateway verifies your AWS Marketplace subscription through a non-consuming license read that can never draw down purchased quantities. Edition and enforcement-point capacity are discovered from the granted license, so a subscription change reaches running gateways on their next check with no redeploy.
Licensing that fails safe. A bounded grace window keeps an already-verified gateway serving straight through a transient AWS outage. Until a subscription has been verified at all, the gateway declines rather than serving unlicensed traffic.
Egress to destinations you approve. Outbound calls go to the destinations on your allowlist; anything else is refused and written to the same evidence ledger as tool-call decisions, as a signed observation. Start in monitor mode to see exactly what your agents already reach, then enforce when the list looks right.
Editions and add-ons. Launch, Platform and Complete cover 25, 75 and 150 governed agents with 3, 6 and 12 enforcement points. Enforcement-point packs, additional isolated tenants, compliance-framework crosswalks with signed evidence bundles, a self-hosted or VPC-isolated sealed engine, and a named technical account manager with a 99.95% availability SLA are available as separate dimensions.
Safe defaults, enforced rather than documented
The ledger is single-writer and the chart refuses to render above one replica. Configuration loaders fail safe: the gateway will not boot on an invalid document, and a caller whose authority it cannot verify is refused rather than admitted on assumption.
Runs on Amazon EKS, EKS Anywhere and self-managed Kubernetes, multi-architecture on x86-64 and AWS Graviton, as a non-root user on a minimal base image. Marquor has passed the AWS Foundational Technical Review and completed an AWS Well-Architected Framework Review.
Highlights
Every agent decision, allow and deny alike, becomes an Ed25519-signed, hash-chained receipt that a third party can verify offline, with no call back to Marquor. Payload-free by construction: declared metadata only, never prompts, files or transaction bodies.
Entitlement-aware and fail-closed. Capacity is discovered from your AWS Marketplace subscription through a non-consuming license read, and reaches running gateways with no redeploy. Until a subscription is verified the gateway answers 402 rather than serving unlicensed traffic.
Enforcement is deterministic and on the hot path; analytics are not. No LLM sits in the decision path, so identical inputs give identical answers in microseconds on CPU. Default-deny egress is recorded as signed observations in the same ledger.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
Pricing starts with three editions that build on each other. Launch Edition covers up to 25 governed agents and 3 enforcement points. Platform Edition raises limits and adds posture and assurance functions. Complete Edition covers 150 agents, 12 enforcement points, and all engines. You then layer add-ons priced independently. Enforcement Point Packs add capacity in sets of 3. Additional Tenants and Sealed Engines extend deployment scope. Compliance Regime adds one framework crosswalk. Adjudication Pack and per-1,000 Automated Decisions apply only to regulated financial services. Premium Support + TAM adds a named account manager and a 99.95% availability SLA.
Top-of-mind questions for buyers
What counts as one governed agent for the edition limits?
A governed agent is an AI agent whose tool calls pass through Marquor. It sits inline at each agent's tool call and verifies identity, checks standing, and allows or denies the action. Each edition caps how many agents you can govern, from 25 up to 150.
What happens if I need more enforcement points than my edition includes?
Each edition includes a set number of enforcement gateway points, from 3 up to 12. You add capacity with the Enforcement Point Pack, which adds 3 gateway points to any edition. Buy multiple packs to scale beyond your edition's included count.
Which add-ons apply only to regulated financial services buyers?
The Adjudication Pack and Automated Decisions apply only to regulated financial services. The Adjudication Pack covers automated adjudication analytics for one venue. Automated Decisions bill per 1,000 adjudication decisions. Both charge on top of your chosen edition. Other buyers do not need these dimensions.
marquor.io
Helpful?
Vendor refund policy
Contract fees are charged in advance for the full term and are non-cancellable and non-refundable, except as stated below or required by law. Unused agent, enforcement point or decision capacity does not carry over and is not refundable. If Marquor cannot be successfully deployed in your environment within 30 days of purchase and we are unable to remedy it, we will refund the unused portion of the term on a pro-rata basis. Refund and billing requests: admin@marquor.io
Request a private offer to receive a custom quote.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
Helm charts are Kubernetes YAML manifests combined into a single package that can be installed on Kubernetes clusters. The containerized application is deployed on a cluster by running a single Helm install command to install the seller-provided Helm chart.
Version release notes
Chart 2.5.0 (gateway image unchanged at 1.4.0). The receipt fields the detection plane runs on are now ON BY DEFAULT: receipts.schemaV2=true sets AGENTSHIELD_SCHEMA_V2, enabling dest_category, shared_target, destination_first_sighting and parent_agent on receipts; set receipts.schemaV2: false to opt out (renders the previous chart's environment). New first-class toolRegistry values create a chart-managed tool-class registry (ConfigMap, read-only mount, env) so outbound/high-impact tools can be classified without hand-built mounts; the class vocabulary is validated at render time. README adds the three configuration steps that remain per-customer: classifying outbound tools, an outcome-neutral first_seen policy rule on destination arguments, and the x-parent-agent header from an orchestrator.
Additional details
Usage instructions
Prerequisites. A Kubernetes cluster (EKS 1.25+ recommended), an OIDC issuer your agents authenticate against, and a StorageClass supporting ReadWriteOnce.
Provide four OAD documents. identity.yaml (issuer/audience/JWKS; PUBLIC keys only), policy.yaml (the global default-deny floor), and per agent a dossier manifest plus a clearance allow-list. Every loader is fail-closed: the gateway refuses to boot on anything invalid, and a verified-but-uncertified caller gets deny-all.
Install. Set upstreamUrl to your MCP server and supply the OAD documents. The chart mounts them read-only from ConfigMaps and the admin token from a Secret. The chart ships with inert placeholder defaults so it renders out of the box: an unconfigured install denies everything and reaches nothing. Replace upstreamUrl and the identity document before expecting it to serve traffic.
Two constraints the chart enforces by refusing to install:
Exactly one replica. The gateway is single-writer: one Ed25519 signing key, one hash-chained traces.jsonl, one ReadWriteOnce volume. Two replicas fork the chain into branches signed by different keys, destroying tamper-evidence silently. The Deployment strategy is Recreate, never RollingUpdate.
Persistent storage is required. /data holds the signing key and the ledger. Losing it restarts the chain under a new key.
Verify. GET /healthz returns {"status":"ok"}. Point your agents at the gateway's /mcp endpoint - no agent code changes are required. Start in monitor mode, review the receipts, then switch to enforce.
Entitlement (Enterprise only). This listing verifies your subscription before it serves traffic.
On Amazon EKS, the gateway's ServiceAccount "marquor-gateway" must carry an IRSA role annotation granting license-manager:ListReceivedLicenses, and the cluster needs outbound access to license-manager.<region>.amazonaws.com. Set the annotation with:
--set serviceAccount.annotations."eks.amazonaws.com/role-arn"=<your-role-arn>
On EKS Anywhere or self-managed clusters, generate the license Secret from the AWS Marketplace console; the licenseSecretName Override Parameter is populated automatically.
Entitlement is a READ (ListReceivedLicenses), never a checkout, so verification can never draw down purchased quantities.
Until a subscription is verified the gateway fails closed: /mcp and the egress proxy answer 402 Payment Required. A verified gateway that later loses contact with AWS keeps serving through a bounded grace window and then closes, so a transient AWS outage is not an immediate outage for you. Service resumes automatically on the next successful check.
What your license controls. Edition (mq_launch, mq_platform, mq_complete) and enforcement-point capacity (mq_gw_pack) are read from the granted license, never configured in the chart. Adding dimensions to your subscription reaches already-deployed gateways on the next check with no redeploy.
Support
Vendor support
Marquor provides technical support for product onboarding, deployment, configuration, integrations, policy setup, runtime enforcement, and troubleshooting.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Arcade.dev is the industry's first MCP runtime enabling AI to take secure, real-world actions. As the MCP runtime, Arcade is uniquely able to deliver secure agent authorization, high-accuracy tools, and centralized governance for multi-user AI agents at scale.
AI Runtime Security (also known as Prisma AIRS) is an adaptive, purpose-built solution that discovers, protects, and defends every component in the AI ecosystem, applications, models, and data from AI-specific and foundational network threats.
It stops evolving and zero-day threats, prevents data leakage from AI models and apps and safeguards models from misuse and attacks. This is done by combining continuous runtime threat analysis of AI apps, models, and data sets with AI-powered security to detect and stop attackers in real time. Security operations are streamlined because they are delivered as part of a unified security platform, eliminating the need for point products for AI.
Runtime security and oversight for AI agents. See every agent, attribute every action, flag hostile inputs, and scrub leaked secrets before they're stored.
This is a repackaged software product wherein additional charges apply for a pre-hardened, SI Core STIG Hardened image and seller support. OpenJDK Java is a robust implementation of the Java Platform, enabling developers to build secure and efficient applications in a cloud environment. With OpenJDK Java, users benefit from enhanced performance, reduced latency, and compatibility with existing Java applications, making it suitable for both enterprise solutions and rapid development cycles. This AMI is designed to simplify deployment without sacrificing security, featuring a hardening process aligned with industry standards. Leverage OpenJDK Java to accelerate application development and ensure a reliable runtime environment in the AWS EC2 cloud.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.