# Security Agent: Your Ai1 Server Checked Every Night

> The Security Agent is AI security monitoring for your server in the Ai1 platform by MyZone AI: every night it probes your Ai1 server for weak spots, checks it for unexpected changes, sorts each finding by who should act and sends urgent security decisions to you, and it never touches platform files.

Canonical page: https://myzone.ai/pages/agents/ai-security-agent
Part of Ai1, by MyZone AI. Book a Security Agent walkthrough: https://calendly.com/d/ct6h-tcy-8qf/ai1-demo?a1=Security%20Agent&utm_source=myzone.ai&utm_medium=agent-page&utm_content=ai-security-agent-final
Last updated: 2026-10-05. Reviewed by the MyZone AI team.

Your Ai1 server checked every night, with only real decisions sent to you.

## At a glance

- **When it runs:** A full sweep every night, with the report ready when your day starts
- **What it looks for:** Exposed credentials, excess access, suspicious new tools and changes since the last known-good state
- **Where findings go:** Platform issues to MyZone platform support, urgent decisions to you, the rest logged
- **Scope:** Your Ai1 server only, and a clean report is not a guarantee
- **On request:** A probe or drift check at any time, read-only
- **What it never does:** Touch platform files

## What the Security Agent does

- **Runs a full sweep each night:** Every night it probes your Ai1 server for weak spots and checks it for unexpected changes, then writes up what it found.
- **Looks for leaks and excess access:** The probe searches for exposed credentials, unexpected access to connected services, areas with more permission than they need and suspicious new tools on the server.
- **Spots configuration drift:** The drift check compares the server today with its last known-good state and flags anything that has shifted since the last approved release.
- **Sorts and routes each finding:** Every result lands in one of three groups: a platform issue for MyZone platform support, an item that needs your attention, or a low-priority note that is logged.
- **Keeps its reference point current:** After a release has been verified, it updates the known-good snapshot it compares against, so planned changes do not show up as false alarms.
- **Checks on request:** Ask for a probe or a drift check at any time and it runs one straight away, read-only, outside the nightly schedule.

## How the Security Agent differs from a one-off security audit

A one-off audit checks your server once and is out of date by the next release. The Security Agent sweeps your Ai1 server every night, probing for leaks and excess access and comparing it with a known-good snapshot it refreshes after each verified release. Each finding is sorted: platform issues go to the platform support agent with redacted evidence, and only real decisions reach you. It watches and reports, and never touches platform files.

## How it works

1. **Sweep** (Every night, and on request): It runs two passes over your Ai1 server: one hunting for weaknesses and one looking for anything that changed unexpectedly.
2. **Classify** (As each finding comes in): Each finding is labelled as a platform issue, something for your attention, or information only.
3. **Route or log** (you approve) (Straight after sorting): Platform issues go to MyZone platform support with redacted evidence. Urgent security decisions come to you right away. The rest is logged.
4. **Report** (Before your day starts): A written report summarises what ran, what passed and what still needs follow-up, ready when your day starts.
5. **Queue the next run** (Once the report is out): The following night's sweep is scheduled automatically, so coverage does not lapse.

## When to use it

- **You want to know your Ai1 server was checked overnight:** The nightly sweep runs on its own and a sorted report is waiting for you in the morning.
- **Something feels off and you want a check now:** Ask for on-demand server security checks and it looks for leaks, excess access and suspicious additions straight away.
- **You are not sure what changed on the server:** A drift check compares the current state with the last known-good snapshot and lists the differences.
- **A release has just been verified:** It refreshes its reference point, so the next drift check measures against the new normal instead of raising noise.

## What you get

- A nightly security scan report covering what was checked, what passed and what needs follow-up
- Findings sorted into platform issues, items for you and information only
- Redacted evidence packs for platform issues sent to your support team
- On-demand probe and drift check results
- A refreshed known-good snapshot after each verified release

## Example: nightly security sweep

Example with a fictional company. Names, people and figures are invented to show the agent's output. Any resemblance to a real company or person is unintended.

What it was asked: Show me a concise nightly security sweep of our Ai1 server, including what was checked, what needs attention, and who handles each next step.

The Security Agent formatted invented access, configuration, scan, API, audit-log and installed-tool snapshots into a sample nightly sweep using its current triage and routing pattern. It did not connect to or scan a live company system, test exploitability, inspect unlisted locations, change platform settings, or certify the server. A person on the team makes every platform change; the agent only reports, routes and later refreshes a baseline after a verified release or correction. Run date: 30 September 2026.

### What it found

- One retired service role still has release access; the platform support agent should verify ownership and remove that access.
- The monitoring configuration differs from the last verified baseline, so baseline refresh should wait until the change is explained.
- No exposed credentials were found in the selected scan inputs; that result does not cover unscanned systems or prove there are no secrets elsewhere.

## Guardrails

- It watches and reports. It never changes platform files itself.
- It covers your Ai1 server only. It does not check your other systems, and a clean report is not a guarantee that nothing is wrong.
- Spending and permanent actions are your decision. It brings them to you instead of acting.
- Evidence sent to your support team is redacted, so secrets are not passed around in the process.

## Frequently asked questions

### What does a nightly security scan of a server look for?

Leaked credentials, unexpected access, permissions wider than needed, suspicious new tools and changes from the last known-good state. The Security Agent in Ai1 by MyZone AI runs that scan on your Ai1 server in the early hours, so the report is ready when your working day begins. It covers your Ai1 server only, not your other systems, and it reports rather than guarantees: a clean report is not a guarantee.

### How can a small business get fewer, better security alerts?

Sort findings before they reach you. The Security Agent labels each one as a platform issue, something for your attention or information only. Platform issues go to MyZone platform support with redacted evidence, urgent decisions come to you and the rest is logged, so you hear about what genuinely needs you.

### Should a server security checks agent fix what it finds?

Not on the platform itself. The Security Agent never touches platform files: it reports, routes each finding to the right owner and redacts evidence so secrets are not passed around. Platform issues go to MyZone platform support. Spending and permanent actions are your decision, and it brings them to you instead of acting.

### How is a security probe different from a drift check?

A probe actively hunts for weaknesses such as leaked secrets or excess access. A drift check compares the server with a saved known-good snapshot and flags anything that differs. Updating the snapshot after a verified release keeps the drift check accurate, so planned changes are not reported as problems. You can ask for either whenever you like. It runs read-only and reports back, and the nightly sweep still runs as usual.

## More on this topic

- [Locking Down AI Agents: The 10-Point Security Checklist Every CTO Needs](https://myzone.ai/pages/blog/ai-agent-security): AI agents are powerful,and vulnerable. Learn the 10 critical security steps to lock down your AI agents before they become your biggest liability.

## About Ai1

Ai1 is the AI operations platform by MyZone AI, where each client runs on its own private server. The Security Agent is included on every Ai1 level, including Developer Core, with no per-agent charge. It works alongside the other Ai1 agents on your account.

Pricing: https://myzone.ai/pages/services/ai1-pricing. Security: https://myzone.ai/pages/security.
