Loading…
Nobody is on hand to approve here, so the hold timed out and the call was refused. The receipt signs that refusal.
- Tool call
- Why
- Sent as
- Decided
- Receipt
- This record
- Previous
- Signature
A grant can only narrow. Revoking the parent ends every child, and each end is a signed record. Each call is checked against who the agent acts for, what it was granted, and what it could break, then allowed, redacted, held, or refused before it lands.
Every answer below comes from PyxGrant's own decision engine under its hardened policy. Switch to live and the engine itself runs in this tab, compiled to WebAssembly. Edit the request, then check the signed receipt with PyxGrant's own verifier. Nothing is sent to us.
Loading…
Nobody is on hand to approve here, so the hold timed out and the call was refused. The receipt signs that refusal.
In the product, a held call waits up to ten minutes for a signed approval. Controls that need the real machine, such as Linux kernel confinement, aren't part of this demo. The live engine is about 4 MB to download and loads once.
Each plane is tagged shipped, decision-only, or preview. A pilot starts with coding agents and the MCP tools they load. Pick a plane to watch what PyxGrant does there. Each animation replays a check from the walkthrough and tests, or behaviour read from the code.
Start here
Also in the binary
Not fully shipped
Every tool description is pinned when it's approved. A tool that tries to shadow another, or whose description changes after approval, is quarantined and taken out of what the model can see. High-impact calls wait for a person.
Everything an agent reads is scanned before the model sees it. Secrets and personal data are masked, confidential material is withheld, key and credential files are refused, and data from a sensitive source can't leave through a public tool or hide in a URL.
The agent browses in its own profile, never with your signed-in sessions. A first visit to a new site waits for a person, banking, payroll, health and government sites are refused, executable downloads are refused once you turn that on, and a jump to another site after an injected page is refused. Route the agent's traffic through the capture proxy to see every host it reaches, and refuse AI tools you haven't sanctioned.
The agent's own hook asks PyxGrant before each built-in shell or file call. Work inside the workspace goes straight through. A step outside it waits for a person, and network reach your policy doesn't allow is refused. After the tool runs, a PostToolUse hook scans a document that came back: a PDF or Office file with a macro or embedded script is blocked before the model acts on it.
The model proxy masks secrets in a prompt before it leaves, meters tokens and cost per principal, holds requests to models you've listed for a person, and refuses the call once that principal's budget for the window is spent. Each forwarded completion also spends one step on the same agency counter as a tool call. Under the hardened profile, a model with no price is refused.
An instruction planted in an agent's memory is the attack that comes back later. PyxGrant neutralises instructions on the way in, can refuse and fingerprint a poisoned write, and catches the same poison when it's read back in different words.
Authority passes down as grants that can only narrow. A partner can re-delegate your grant without a shared secret but never widen it, sensitive methods can wait for a person, and revoking the parent ends every child.
On the agent's own machine, PyxGrant decides each file write, program launch and outbound connection before it happens: credential files and git hooks are protected, startup items wait for a person, programs run from Downloads are refused, and connections stay on your allowlist.
Text on its way to a person is redacted and checked for instructions aimed at the reader, like "paste this into your terminal". It's tested against a synthetic AG-UI backend, not yet a live deployment.
A payment must match the cart a person approved, come from an untainted session, and stay under the cap. The model can't talk its way past the ceiling. A reverse runs the provider void and only closes when the provider confirms the money is gone; the core binary ships that command, not a live Stripe or Adyen connector.
A held tool call, model request, agent call or browser step waits in one shared queue. The approver is alerted, sees exactly what will run and for whom, and signs the decision with a key the agent can't reach. Nobody approves their own call, and silence means no.
When something goes wrong, stop it in one command without stopping everything else. Freeze just the outbound sends while reads keep working, freeze everything if you need to, resume when it's safe, and revoke an agent for good. contain act adds a dual-control stop: pause and isolate can be undone for 15 minutes; panic and kill_fleet need a second operator.
Coding agents and their MCP tools are the first place agents touch source and secrets. The same binary also decides model calls, agent hops, browsers, and payments.
The four questions every security review asks first, answered before the demo.
One Go binary on each machine that runs agents, with a Windows service option. Agents reach it four ways, and you can mix them.
Decisions run inside the binary, from your policy file. No vendor cloud sits in the path, and the optional data classifier runs locally.
pyxgrant perf measures decision time on your hardware. We don't quote a number from ours.The call is refused, not waved through.
It sits in front of agent actions and leaves the rest of your stack in place.
We don't have public customer results yet. The numbers below are from a full Windows run on 26 September 2026. Reproduce them with the same commands on the binary you have.
checks pass in pyxgrant demo, which starts a hostile MCP server behind the gateway. All 26 sections pass: tool poisoning, rug pulls, poisoned results, confused deputy, blast radius, self-protection, memory poisoning, grant revocation, browsers, payments, and the audit chain among them. No planted secret reached the client or the audit log.
attacks missed, with no false alarms on 22 benign calls. A miss means the attack was allowed. An attack that was only flagged, not blocked, still counts as caught; pyxgrant benchmark prints that count as under_enforced and does not fail the run on it. It is our own corpus and small; the 95% range on the miss rate is 0 to 8%.
Go packages passed go test on that run, and none failed.
Reproduce it: pyxgrant demo · pyxgrant benchmark · More output, condensed →
PyxGrant is built by Omantiv. A pilot covers one team, its laptops and CI runners, and the MCP servers they use. Start in observe mode, read the record, then enforce. Company · Book a demo