FAQ
Frequently asked questions
How safe is my data on the Maya fabric?
Maya never decrypts your data or terminates TLS. In simpler terms, we are payload-blind and can only look at the envelope. Maya can read the address on a package but never knows the contents. The Maya fabric never sends any data outside your VPC by default. You can configure OTEL export to your SIEM as needed.
Is Maya yet another agentic identity / AI firewall?
No. Maya's networking stack is keyed on agent identity on the wire. It complements existing agentic identity solutions such as SPIFFE or any other host-side agent lifecycle and identity management tool.
What makes it different?
Traditional firewalls and LLM gateways read your packets and still can't tell you which agent sent them. Maya never reads a payload, and can.
How does Maya scale with my rapidly expanding enterprise agentic fleet?
Maya is a cloud-native firewall, operating at near line rate (insanely fast), built for cloud scale. Each Maya data plane appliance is designed to support up to 65,000 hosts. Our architecture allows for a million agents in a single customer domain spanning regions, provider boundaries, and geos, all managed securely from a single pane of glass.
Does Maya replace my existing firewall / LLM gateway?
We call Maya "not your daddy's firewall." That's because Maya mainly handles east-west traffic, and south-north, while your daddy's firewall protects the north-south edge, keeping bad actors out. So no, Maya doesn't replace your existing firewall. It complements it. Maya typically sits upstream of your LLM gateway and lets you shape traffic on agent boundaries (boundaries the gateway doesn't have) before it hits the gateway for deep packet inspection.
What is Maya not?
Not an identity provider. It issues no credentials, authenticates nothing, brokers no access. Fraud detection exists because authentication succeeded, so Maya starts where identity ends. Not a proxy or gateway. Nothing terminates in front of your agent, so there is no hop to add and no endpoint to repoint. Not an SDK or agent framework. Nothing to import, nothing to wrap, nothing to keep in step with your framework's releases. Not a log pipeline. Attribution is derived on the wire, not reconstructed from what an application chose to report.
Have a question we didn’t answer?
Start a conversation