Overview

Prev Next

The Verax Endpoint Agent extends Verax Protect to managed endpoints by automating endpoint configuration and, optionally, providing local traffic interception for AI applications.

The agent is designed for organizations that want a simple, centrally managed deployment without requiring users to manually configure their devices.

Depending on your deployment requirements, the Endpoint Agent can operate in one of two modes:

Mode

Description

Configuration Agent

Configures the endpoint for Verax Protect by installing the Verax CA certificate and applying the required endpoint configuration. Traffic is redirected to the organization's Verax Protect deployment using the configured network path.

Full Agent

Includes all Configuration Agent capabilities and adds local traffic interception and enforcement on the endpoint using a lightweight local proxy.


How it works

When deployed in Full Agent mode, it runs as a lightweight local proxy that intercepts supported AI application traffic on the endpoint and securely forwards it to your organization's Verax Protect deployment for inspection and policy enforcement. The Endpoint Agent is not a kernel driver and does not modify the operating system's networking stack.

When deployed in Configuration Agent mode, it performs endpoint configuration only and does not intercept traffic locally.


Security

The Endpoint Agent is designed with a minimal endpoint footprint.

  • No kernel driver is installed.

  • No deep packet inspection is performed on the endpoint.

  • All policy management remains centralized in Verax Protect.

  • All communication between the Endpoint Agent and the Verax Protect server is encrypted in transit using end-to-end encryption.


Choosing a deployment mode

Choose the deployment mode that best fits your environment.

Configuration Agent

Use this mode when your organization already redirects AI traffic to Verax Protect through existing infrastructure, such as a secure web gateway, proxy, firewall, PAC file, or DNS configuration.

The Configuration Agent prepares the endpoint by:

  • Installing the Verax CA certificate.

  • Applying the required endpoint configuration.

  • Maintaining the endpoint configuration over time.


Full Agent

Use this mode when you want the endpoint itself to transparently intercept supported AI traffic without relying on external network infrastructure.

The Full Agent includes all Configuration Agent capabilities and adds:

  • Local traffic interception using a lightweight proxy.

  • Secure forwarding of AI traffic to Verax Protect.

  • Local policy enforcement support for supported AI applications.


Installer modes

The Endpoint Agent installer supports both deployment modes.

Parameter

Installs

-m, --mode configuration

Configuration Agent

-m, --mode agent

Full Agent

Refer to the platform-specific installation guides for Windows, macOS, and Linux for installation instructions and examples.