One engineering team
Developers running Cursor, Claude Code, or CI agents with MCP tools, and the security owner who reviews what gets refused or held.
One team, the laptops and CI runners they work on, and the MCP servers they use. Two weeks watching, then enforcement. This page lists what is in scope, how setup works, what we measure together, and what the product won't do.
Developers running Cursor, Claude Code, or CI agents with MCP tools, and the security owner who reviews what gets refused or held.
One Go binary on each laptop and CI runner. The policy, the approvals, and the audit log stay on that machine. pyxgrant console gives the security owner one view across them.
The pilot starts in observe mode. PyxGrant decides every routed call exactly as it would, records what it would have refused or held, and lets the call through. Redaction still applies.
pyxgrant policy init pyxgrant selftestpyxgrant agents scan pyxgrant discoverpyxgrant wrap -config .cursor/mcp.json -vault"enforcement": "observe" in the policy. Nothing is refused or held. Each call it would have stopped is recorded as an observe: finding.pyxgrant policy learn pyxgrant replay -candidate new.jsonEvery number below comes from records the pilot produces on your machines, not from our reporting.
How many of the team's agents and MCP servers were found and routed, and which still run outside PyxGrant. pyxgrant processes lists the ones running right now.
Every observe finding is reviewed before enforcement starts. Each one that shouldn't have fired is counted and fixed with a policy change. pyxgrant stats
What the gateway adds on your hardware, at the median and the slow tail. pyxgrant perf
Your auditor verifies the hash chain and a sample of receipts with your public key, without help from us. pyxgrant audit
pyxgrant wrap -undo restores a machine's original config.pyxgrant reconcile names calls that went around it, if you supply the provider's audit export.pyxgrant boundaries, the product's own list of what it doesn't doTell us which agents and MCP servers the team uses. We'll come back with a written scope against this build.