product
Runtime Guardrails
Deterministic rules that decide what your agent may do.

customers
ubicloudevry healthdotenvxfirecrawlcapchasenangomastrapaperclip
why
your agent runs as you. it can read .env and send it out. it can delete a home directory.
another model will not stop that in time. a rule on the machine can.
rules
built-in detections
secrets, exfil, destructive commands, persistence, privilege, and the rest of the catalog. four catastrophic defaults already enforce.
custom rules
yaml and cel on a single event, or a sequence. evaluated on the machine, not in our cloud.
monitor or enforce
alert first. block when you are ready and the agent hook can deny the action.
groups and api
assign rules to client groups. manage clients and rules from the dashboard or the api.
how it works
three steps
01 keep using your agent. cursor, claude code, codex, or another agent you already use.
02 risky actions get caught. on the machine, while you work.
03 you see what matched. a finding in superagent. set a rule to enforce and the agent can block the action.
get started
free for open source.
the whole suite, on any public repo. private repos are paid — contact us and we'll set you up.