PyxGrant / Company

Agents act for people. Someone should check.

PyxGrant is built by Omantiv. Agents now read code, open files, call tools, and move money, often with auto-run on and nobody watching. We build the binary so those actions get a decision a person can read and a receipt someone else can verify. The way to reach us is a demo or a security review.

What we believe

Four principles the product is built on.

01

The model never decides.

A model can be talked into anything. Enforcement sits outside it, in rules a person can read and a checkpoint the model cannot reach.

02

Unknown means no.

When a check can't complete, the call is refused. A control that waves traffic through when it breaks is a suggestion. When our own audit finds a path that didn't refuse, we fix it and say so in the changelog.

03

Proof you can check without us.

Receipts are signed and chained, and verified with a key you hold. You should not have to trust our binary to trust its record.

04

Say where the line is.

We publish what we don't claim, and this site's tests fail if its copy crosses it.

Where the product is today

  • One Go binary on each machine that runs agents, with a Windows service option
  • Proxies for MCP servers, model APIs, agent-to-agent calls, and AG-UI, a hook for Claude Code and Cursor, and a decision service for your own agents
  • A hash-chained audit log sealed with Ed25519, and an operator console
  • Not yet: a highly available console, a FIPS 140-3 validated module, a shipped kernel hook, or FedRAMP authorization

The full boundary →

What we will not build

  • A replacement for your EDR or your identity provider
  • Productivity scoring or ranking of developers
  • Keystroke logging, screen recording, or emotion inference
  • A silent fail-open mode
  • Models trained on customer data

Running a security review?

Send the questionnaire with your demo request. We'll answer it against this build, including the parts that say "not yet".