Discover, decide, approve, contain, prove.
PyxGrant is one Go binary that sits in front of the calls your agents make: tools, models, other agents, browsers, and payments. It decides each call before it runs, holds the risky ones for a person, and writes a signed, hash-chained record of every decision.
- Discover
- Decide
- Approve
- Contain
- Prove
Agents on the left, systems on the right, one decision in the middle.
Callers
PyxGrant
Systems
Find the agents nobody registered.
Read-only scans of each machine list the coding agents, the MCP servers they load, and plaintext secrets in their configs. Exports from your proxy, IdP, and SaaS tenants fill in the rest.
agents scan finds Claude Code, Codex, Gemini, Copilot, Cursor, and Windsurf. discover flags MCP servers not routed through PyxGrant, and local model ports (Ollama, LM Studio, vLLM-style) with no gateway in front.processes lists agent and MCP processes and whether each is behind a gateway, including ones started outside any config.shadow ingest classifies proxy, DNS, extension, process, and OAuth signals: sanctioned, shadow, personal tenant, or imitation.sanctioned enterprise ChatGPT personal-tenant chatgpt.com shadow meeting notetaker (Fireflies) imitation lookalike host shadow browser extension (Grammarly) found local model (Ollama), by process 4 signal families seen · 6 of 6 checks pass
One decision per call, made before it runs.
Each call is checked against your policy file: who is asking, which tool, what the arguments would do, and what the session has already read. The answer is allow, allow with redactions, hold for a person, or refuse. If the engine can't decide, it refuses.
tool hostile/db_query score critical, 85 (limit 70) because DELETE/UPDATE with no WHERE clause targets a high-sensitivity resource identity read high-sensitivity data this session decision BLOCK before execution (-32018)
Risky calls wait for a person, and silence means no.
A held tool call, model request, agent message, or browser step waits in one queue. An approver signs the decision with their own Ed25519 key. If nobody answers in ten minutes, the call is refused.
HOLD hostile/delete_record awaiting approval 8612106e1424 $ pyxgrant approvals $ pyxgrant approve 8612106e1424 approved, then run undo restore record rec-9 from snapshot
Freeze, resume, revoke, or contain with two people.
Freeze pauses calls in flight and holds new ones until you resume. It can cover every session, one session, a workflow run, a grant, or a whole class of action such as payments or sending, while read-only work carries on.
contain act records pause and isolate with a 15-minute undo. Panic and kill_fleet need a second, different operator on -confirm, and they kill the target grant on the store, the revocation file, and the signed death stream.$ pyxgrant freeze every session $ pyxgrant freeze -class pay payments only $ pyxgrant contain act -verb pause -actor ops $ pyxgrant contain act -verb panic -actor ops -confirm sec -target g_9ec3… $ pyxgrant grant revoke g_9ec3… 2 grants killed · GrantDead receipt signed
A record that holds up without trusting us.
Each decision is written to a hash-chained log, and the chain head is sealed with Ed25519. No plaintext secret is written to it. Anyone with the public key can verify the chain and individual receipts offline.
ediscovery searches by person, session, tool, or decision, and places legal holds.disclosures lists every record where PHI, PII, or a secret was found, and whether it was sent, redacted, or refused.prove -anchor must live in a tree that does not overlap the pack.PASS hash-chained audit log verifies 39 records, head aec71ae40f85fb02 PASS Ed25519 seal over the chain head verifies PASS no plaintext secret written to the log $ pyxgrant audit verify
What the security owner sees.
These are screenshots of pyxgrant console, taken on a test machine while an agent's calls were waiting. Three calls are held for a person, each bound to the exact payload it will run with. Every row carries a signed receipt.
Mapped to OWASP, including the gaps.
This is the product's own map, printed by pyxgrant compliance. It marks what a runtime gateway covers, what it covers in part, and what sits outside it.
LLM Top 10 · 5 covered
resultsredactsanitiseholdbudgetLLM Top 10 · partial or none
partialpartialnonenonenoneAgentic Top 10 · 8 covered
coveredcoveredcoveredcoveredcoveredcoveredcoveredcoveredAgentic Top 10 · 2 partial
partialpartialRun it on your own machines.
One Go binary, your policy file, and no vendor cloud in the decision path.