Skip to content

Distributed agents

Run your agents where the data lives.

When data can’t or shouldn’t move, send the agent to it. Your validated agents run on partner infrastructure and at your own sites. You control and audit all of them from one place.

UnmanagedManaged · live
  1. Registered
  2. Owned
  3. Permissioned
  4. Observed
  5. Revocable

Example animation. Your validated agents travel from your registry to the sites that hold the data: your headquarters, a partner’s data center, a partner cloud, a plant, a lab, and the edge. Each connects back out on port 443 and registers, gets an owner, and answers only what you grant. Tasks go out to the agents and results come back while the data stays where it is. Then an administrator takes the edge site’s agent offline, and the next task to it is rejected.

The data is too big, too sensitive, or too far away to move.

A global streaming service screens content before it goes live. The content sits with the partners and facilities that hold it. Hauling it to a central system and back costs time and money.

So the service sends its own validated screening agents to where the content lives. The content stays put. Only the task and the result cross the network, and the service controls and audits every one of those agents from one place.

The same shape shows up wherever data can’t or shouldn’t move: patient records in hospitals, trial data at research sites, telemetry on factory floors.

How it works

  1. Your agent goes to the data

    Deploy your validated agent on a partner’s infrastructure or at your own sites: any cloud, data center, or edge device.

  2. It connects out, never in

    The agent opens one outbound connection on port 443. The host opens no inbound ports and needs no public endpoint, static IP, or DNS change.

  3. You control it from one place

    Every agent registers into your private registry under your organization. You decide who can call it, and you can revoke access or take it offline.

  4. You audit it from one place

    Every change to your agents and their access lands in one audit log, whichever site they run at.

Where the data lives

Connects out only →

Scoped access →

Controlled from one place

Where the data lives

  • Partner infrastructureCloudsdata centersfacilities
  • Your own locationsSitesplantslabs
  • Your validated agentsYour codeyour models

Connects out only

Blocks

Your private agent network

Scoped access

Controlled from one place

  • Owners and adminsRegistryrolesrevocation
  • Your apps and agentsCall by permission
  • Your auditorsOne audit log
Where the data lives: Partner infrastructure, Your own locations, Your validated agents. Connects out only to Blocks, your private agent network. Scoped access for Owners and admins, Your apps and agents, Your auditors.

What you get

Work happens next to the data
Run checks and analysis where the data already sits, instead of moving it first.
Less data in motion
Content stays with the partners and sites that hold it. Only tasks and results travel.
One place to govern
Every agent, at every site, in one registry with one set of controls.
An easier ask of your hosts
Partners open no inbound ports, so there is less for their security teams to review.

For your security team

Security overview
Outbound only
Agents connect out over port 443 to a short list of hostnames. Hosts open nothing inbound.
Identity on every request
Organization, participant, role, and scope are verified on every request, with short-lived, isolated credentials.
Scoped access
Each agent answers only the people, teams, and agents you have granted.
Revocation
Revoke a grant and the next call is rejected. Administrators can force any agent offline, wherever it runs.
Audit
Every control-plane change is logged with who made it, what changed, when, and a before-and-after diff.
Encrypted in transit
TLS on every connection between the agent, the network, and its callers.
  • Up to 99.999% SLA
  • SOC 2 Type II
  • SOC 3
  • HIPAA with BAA
  • GDPR
  • CCPA
  • ISO/IEC 27001

For your architects

HOSTOUTBOUND 443config.blocks.aiapi.blocks.ai*.pndsn.comNO INGRESS RULES

You wrap your agent with the Blocks SDK or CLI, in Python or TypeScript, and it runs as an ordinary process on the host. It needs outbound HTTPS on port 443 to config.blocks.ai, api.blocks.ai, and *.pndsn.com, and nothing else: no NAT traversal, no port forwarding, no ingress rules.

Run more than one instance and Blocks routes work across the healthy ones, with retries and failover.

Other solutions

Agent sprawl

YOUR BUSINESSSALESFINANCEOPSYOUR BUSINESSSALESFINANCEOPS

Bring every agent into the light.

Register every shadow agent, give it an owner, and control who can find it. Nothing gets torn down, and teams stop building the same agent twice.

Partner networks

YOUR NETWORKPORTFOLIO APORTFOLIO BPARTNERPORTFOLIO APORTFOLIO BYOUR NETWORKPARTNER

Connect agents you don’t own.

Partners and portfolio companies bring their own agents onto your network, with access they scope and can revoke. Nobody has to standardize on your stack, and companies join and leave cleanly.

Keep the data where it is.

One of our executives will set up time with you.

Talk to Us