Runtime security for AI agents

Your AI agent
will do anything.
GUARD IT.

Wrap any agent — Claude Code, Cursor, Codex — in one command. See every API call, file, secret, and tool it touches, then control it: stop prompt-injection attacks, block data exfiltration, hold risky actions for approval, and cap runaway spend.

one command, any agent no SDK, no code changes monitor → enforce
claude-code / guarded session monitor mode · 0 blocked
live agent activity t+00:00
/ the threat model

Everything an agent can do to you, caught.

Agents have your keys, your shell, and no judgment. One poisoned web page or tool result and they'll exfiltrate, overspend, or go off-mission. Straight Chaos catches it at the egress chokepoint, no code change.

01

Prompt injection

A scraped page tells your agent to ship your secrets to an attacker's host. Mirror flags any action driven by untrusted content, caught before it lands.

mirror
02

Data exfiltration

An API key pasted into a prompt, a credential echoed into a tool call. The data firewall scans every outbound request and blocks the leak.

DLP
03

Off-mission drift

You asked it to fix a test; it's reading ~/.ssh and pushing to prod. The intent firewall refuses any action that doesn't serve the mission.

intent
04

Runaway spend

A loop that quietly burns $400 in tokens. Cap the budget per agent and halt before the bill, not after.

budgets
/ how it works

One command. Any agent. No code changes.

Wrap your agent behind chaos guard. It proxies the agent's egress (every HTTP call, model API, tool, and file access) and applies your policy. Start in monitor mode to see the truth, then flip to enforce.

$ chaos guard claude
/ the guard

Built for the agent threat model.

Egress firewall

Allow, deny, or hold for human approval by host, path, SQL, the model it calls, even secrets in its prompts. Least-privilege for everything the agent reaches.

Data firewall

Scan every outbound request for secrets & PII (API keys, tokens, private keys, cards, SSNs) and block, mask, or tokenize them before they leave.

Intent firewall

Goal-aware least-privilege: capture the agent's mission and refuse any action that doesn't serve it. Reading ~/.ssh is fine for an SSH task, off-mission for a PDF summary.

Mirror: catch the injection

Flag a write to a host the agent learned only from untrusted content (the signature of a prompt-injection-driven action) with zero extra model calls.

Receipts

The agent says "all tests pass." Did it run them? Receipts verify the agent's completion claims against the tool calls it actually made.

Spend budgets

Cap tokens and requests per agent over a rolling window, shared fleet-wide. Halt a runaway loop before the bill, not after.

Verifiable conduct

A tamper-evident, hash-chained record of how each agent actually behaved, exportable and mintable into a portable, Ed25519-signed conduct credential a third party can verify offline.

Adversarial GameDays

Red-team your agent's defenses: inject prompt-injection, hijack, and exfil-lure probes and score the result. Resilience as a number that goes up over time.

…and full chaos engineering

The discipline this was built on. Inject real faults (latency, loss, partitions, resource kills, cloud outages) at the kernel layer (eBPF), and degrade the agent's own model API to test how it copes. Advanced →

Pricing

Free to start. Pay when you need to scale.

Solo
Free
For solo devs guarding their agents
  • ✓ 1 agent
  • ✓ Monitor + enforce
  • ✓ All guardrails
  • ✓ Community support
Start free →
RECOMMENDED
Team
$9/mo
For teams running agents in production
  • ✓ Up to 10 agents
  • Unlimited experiments & guard sessions
  • ✓ Templates & schedules
  • ✓ Webhooks (Slack, PagerDuty)
  • ✓ Team invites
  • ✓ Email support
Get Team →
Enterprise
Custom
For platform teams at scale
  • ✓ Unlimited agents
  • ✓ SSO (SAML, Okta)
  • ✓ Audit log
  • ✓ Dedicated support
  • ✓ SLA
Contact sales →

Don't hope your agent behaves.
Prove it.

Wrap your first agent in minutes. Free for solo devs and small teams.