The Verax Endpoint Agent extends Verax Protect to managed endpoints by automating endpoint configuration and, optionally, providing local traffic interception for AI applications.
The agent is designed for organizations that want a simple, centrally managed deployment without requiring users to manually configure their devices.
Depending on your deployment requirements, the Endpoint Agent can operate in one of two modes:
Mode | Description |
|---|---|
Configuration Agent | Configures the endpoint for Verax Protect by installing the Verax CA certificate and applying the required endpoint configuration. Traffic is redirected to the organization's Verax Protect deployment using the configured network path. |
Full Agent | Includes all Configuration Agent capabilities and adds local traffic interception and enforcement on the endpoint using a lightweight local proxy. |
How it works
When deployed in Full Agent mode, it runs as a lightweight local proxy that intercepts supported AI application traffic on the endpoint and securely forwards it to your organization's Verax Protect deployment for inspection and policy enforcement. The Endpoint Agent is not a kernel driver and does not modify the operating system's networking stack.
When deployed in Configuration Agent mode, it performs endpoint configuration only and does not intercept traffic locally.
Security
The Endpoint Agent is designed with a minimal endpoint footprint.
No kernel driver is installed.
No deep packet inspection is performed on the endpoint.
All policy management remains centralized in Verax Protect.
All communication between the Endpoint Agent and the Verax Protect server is encrypted in transit using end-to-end encryption.
Choosing a deployment mode
Choose the deployment mode that best fits your environment.
Configuration Agent
Use this mode when your organization already redirects AI traffic to Verax Protect through existing infrastructure, such as a secure web gateway, proxy, firewall, PAC file, or DNS configuration.
The Configuration Agent prepares the endpoint by:
Installing the Verax CA certificate.
Applying the required endpoint configuration.
Maintaining the endpoint configuration over time.
Full Agent
Use this mode when you want the endpoint itself to transparently intercept supported AI traffic without relying on external network infrastructure.
The Full Agent includes all Configuration Agent capabilities and adds:
Local traffic interception using a lightweight proxy.
Secure forwarding of AI traffic to Verax Protect.
Local policy enforcement support for supported AI applications.
Installer modes
The Endpoint Agent installer supports both deployment modes.
Parameter | Installs |
|---|---|
| Configuration Agent |
| Full Agent |
Refer to the platform-specific installation guides for Windows, macOS, and Linux for installation instructions and examples.