Five verbs. Nine shipped surfaces.

Prove. Kill. Contain. Answer. Discover.

Five things every buyer needs Guard to do. Pick your verb; jump to the shipped surface that does it. Every one is live in production today.

Governance is not a brake. It is the scaffolding that lets you expand agent autonomy safely.

Prove2 shipped

Prove every agent action to a regulator, a board, or an auditor.

Hash-chained evidence per call. Attested agent identity. Same receipt shape whether you're answering a SOC2 assessor or a CISO in Monday review.

Kill2 shipped

Kill any misbehaving agent by flipping one column.

Sub-second revocation at the auth path. The next LLM call, MCP call, or tool call the agent makes gets 401 — regardless of token TTL. Stops in-flight damage without a deploy.

Contain4 shipped

Contain shadow AI, sprawl, and blast radius.

One policy across every AI tool your team runs — IDE, MCP, LLM proxy. Spend caps, PII/injection filters, per-tool allowlists. The most-used verb because containment is what Guard does every day.

Answer1 shipped

Answer the board question: every AI call this week, who approved it.

Not a screenshot, not a Notion doc — a signed, hash-chained record you can export the day the question lands. Same evidence base as Prove, different consumer.

Discover1 shipped

Discover every agent already running before you govern them.

Passive scan of dev environments, CI logs, and MCP servers to find agents you didn't sanction. First step before policy — you can't govern what you can't see.

Nine surfaces below · each shipped, each auditable

01Security engineers, platform leads, CISO teams standardizing developer AI.

AI in the IDE, governed

One policy across every AI tool your engineers actually use.

The situation

Your engineers use Claude Code, Cursor, Copilot, Windsurf, Codex, ChatGPT desktop, and Claude desktop. Each one speaks to a different model, over a different API, using a different tool surface. Your policy is a wiki page. Most of the time, nobody has read it.

What Guard does

  • ›Two integration paths. A hook inside the tool where the tool supports it (Claude Code hooks, Copilot CLI, Cursor). A transparent proxy on the model endpoint where it does not. Same policy engine on both.
  • ›Every call returns allow, warn, or block before it proceeds. Fail closed. Hash-chained audit for every decision.
  • ›Rules live as declarative YAML. Security ships a rule change without a deploy.

A concrete run

A developer pastes a customer email into Cursor to draft a reply endpoint. The email contains a raw credit card number. Guard sees the prompt, matches the PAN pattern, blocks the call, and shows the rule that fired. The developer strips the number and retries. Nothing left the machine.

Metrics that move

Policy violations blocked per day. Unique models in use. Per-tool cost. Coverage: what fraction of your AI calls actually go through Guard.

Where it plugs in

Anthropic, OpenAI, Azure OpenAI, Google, Perplexity, OpenRouter, Vercel AI Gateway. Any provider your engineers route through.

02AI platform teams shipping or consuming MCP servers.

MCP that behaves like a permitted action, not a shell

Every MCP call becomes a governed call.

The situation

MCP made every tool a callable. That was the point. It also made every tool an unguarded shell if the model on the other end decides to call it. Most teams have no throttle, no per-tool allowlist, and no audit of which agent invoked which tool at which time.

What Guard does

  • ›Guard proxies MCP calls. Per-tool rate caps. Per-server allowlists. Per-agent scope. All decisions land in the same hash-chained audit as your model calls.
  • ›Tools that write, delete, or send can require review. Tools that read stay fast.
  • ›A single /guard/mcp endpoint per workspace. One place to point every client.

A concrete run

An analytics agent has access to an MCP tool that runs SQL on the warehouse. A user asks it to export a customer table to CSV. Guard sees the row estimate, the destination, and the PII columns in the projection. It blocks with a specific rule cited. The analyst sees the block reason without needing to open the warehouse logs.

Metrics that move

MCP calls per tool. Blocked calls by rule. Median latency Guard adds to a tool call. Per-agent tool usage.

Where it plugs in

Any MCP server, self-hosted or third-party. Vercel MCP, Cloudflare MCP, custom servers.

03Compliance officers, GRC leads, auditors in regulated environments.

Compliance evidence from what the AI actually did

One hash-chained table, mapped to every framework you care about.

The situation

Auditors have started asking about AI usage. Most companies answer with screenshots, a vendor letter, or the SOC 2 report the model provider gave them. That is evidence the vendor has controls. It is not evidence that you do.

What Guard does

  • ›Every allow, warn, block, finding, fix, and approval is a signed row.
  • ›Compliance packs map that table to specific controls. SOC 2 CC7.3 and PCI DSS 12.3.1 point at the same rows. ISO 27001 A.14.2.1 and the EU AI Act share the map.
  • ›When an auditor asks how you enforce your AI usage policy, the answer is a query, not a slide.

A concrete run

SOC 2 Type II auditor asks how you prevent hardcoded secrets from being generated by AI tools. You show the Guard rule that fires on secret patterns, the audit chain of the last 90 days of allow and block decisions on that rule, and the tickets opened for engineers whose calls were blocked. The auditor moves on.

Metrics that move

Framework control coverage. Evidence rows per control. Days until audit ready.

Where it plugs in

SOC 2, PCI DSS, HIPAA, ISO 27001, EU AI Act, NIST AI RMF. Custom pack for internal frameworks.

04FinOps, engineering leadership, anyone who has been surprised by an AI invoice.

Cost guardrails that stop the call

Limits enforced at the proxy, not discovered on the invoice.

The situation

One agent misconfigured on a Friday can burn a month of your model budget over a weekend. Provider dashboards show the damage after the fact. Finance hears about it on Monday. The engineer who wrote the loop hears about it on Tuesday.

What Guard does

  • ›Per-user daily caps. Per-project monthly caps. Per-agent lifetime caps. All enforced at the proxy, at the moment of the call.
  • ›Warn thresholds page the owner before the block threshold hits.
  • ›When a cap is reached, the call fails cleanly with a rule that names the limit and the owner.

A concrete run

A nightly PR reviewer agent hits a retry loop after a schema change. Its cost climbs at 200x the normal rate. At the per-agent daily warn threshold, Slack pings the owning team. At the block threshold, Guard stops the calls. The morning after, the agent report shows the cap enforced, not the runaway.

Metrics that move

Cost under policy. Warn events. Block events. Utilization by owner.

Where it plugs in

Anthropic, OpenAI, Azure OpenAI, Bedrock, any provider Guard proxies.

05Security, IT, CISO teams doing an AI inventory before writing rules.

Shadow AI, found

Discovery first. Then policy. Then evidence.

The situation

You cannot govern what you did not know was running. Engineers connect Cursor to a personal Anthropic account. Someone installs an MCP server from a GitHub gist. A support agent pastes a customer sample into a chat window. Your policy is silent on tools it has not heard of.

What Guard does

  • ›A lightweight watch daemon reports which AI CLIs and desktop apps are running on developer machines.
  • ›Self-registration lets any tool that connects to the Guard proxy declare itself.
  • ›MCP servers announce their tool surface at registration.

A concrete run

A security lead runs discovery for the first time. The report shows 47 developers on Cursor, 12 on Windsurf that were not on any approved list, three running local Ollama servers, and one MCP server pointed at a production Postgres from a home lab. The policy conversation starts from a list, not a guess.

Metrics that move

Unique tools discovered. Unique models discovered. MCP servers registered. Users with unmanaged AI usage.

Where it plugs in

Claude Code, Cursor, Copilot, Windsurf, ChatGPT desktop, Claude desktop, Codex, custom CLIs.

06Platform engineering teams standing up agent fleets.

Know Your Agent (KYA). Every agent gets an attested identity, not a shared API key.

Every run is a bounded session. Every credential expires with the run.

The situation

An agent is not a user. It is not a service account either. Most orgs give the agent a static API key, tape it into a secrets manager, and hope it does not leak. When the agent misbehaves, revocation is manual, credential rotation is a ticket, and there is no clean way to prove which specific run made which specific call.

What Guard does

  • ›The executor mints two tokens at run start. cond_run for proxy authorization. cond_cred for credential brokerage.
  • ›Both are scoped to the run, expire when the run ends, and revoke instantly on policy violation.
  • ›The executor is the only minter. No fallback path. No user-token reuse. No trigger-time shortcut.
  • ›Agent role permits describe what any run in that role can do. Rotation is a config change.

A concrete run

A code-review agent starts. Guard issues a cond_run scoped to the model calls the playbook needs, and a cond_cred scoped to the GitHub PR API for that repo only. The run finishes. Both tokens die. If the run had tried to call the payroll API instead, cond_cred would have refused before GitHub was ever contacted.

Metrics that move

Active identities. Median session length. Revocations per week. Unused credential scopes.

Where it plugs in

Okta, Azure AD, Google Workspace as identity source. Guard is the runtime authority.

07Security teams handling untrusted documents, customer content, or web-scraped input.

Prompt injection and PII, caught at the wire

Inspect content before the model sees it.

The situation

Prompt injection is not a bug you patch in a model version. A model that reads instructions from content will follow instructions from content. Redacting PII after the model has read it is also too late. Both have to be handled before the model gets the payload.

What Guard does

  • ›Guard inspects prompt content at the proxy. Injection patterns trigger a rule that either blocks or strips the offending region.
  • ›PII patterns trigger redaction. The model sees a placeholder instead of the raw value.
  • ›Custom rules handle domain-specific terms. YAML, not code. Ship without a deploy.

A concrete run

A support agent summarizes a customer email. The email contains injected text asking the model to forward the entire thread to an external address. Guard’s injection rule fires, strips the region, and marks the call warn. The summary runs on the sanitized content. A note lands in the run’s audit trail. The support engineer sees a clean summary and a small sanitized banner.

Metrics that move

Injections blocked. PII redactions. False-positive rate on custom rules.

Where it plugs in

Any prompt, any model, any tool that routes through the Guard proxy.

The rule library covers common patterns. Domain-specific rules are shipping on a rolling basis.

08Heads of CX, ops leaders, and CISOs deploying customer-facing or ops-facing AI agents.

Business agents that take real actions

What your agent does. Not just what it can.

The situation

An agent that answers questions is a search box with a hallucination risk. An agent that issues refunds, cancels subscriptions, updates accounts, or commits pricing is a financial actor with the same risk. Air Canada honored the bereavement fare its chatbot invented. Klarna reversed thousands of automated CX actions when a rules change misfired. The failure is not that the agent could talk. The failure is that the agent could act without a policy in front of the action.

What Guard does

  • ›Guard sits between the agent and the action tool. Every action call is checked against the current policy: is this refund inside the allowed amount, is this cancellation inside the allowed reason list, does this commitment need a supervisor.
  • ›Warn triggers a human handoff. Block returns a clean refusal the agent can explain in language.
  • ›Every action becomes one hash-chained line with the customer, the amount, the reason, and the reviewer.

A concrete run

A support agent offers a $400 credit to a customer whose bill was $180. Guard sees the tool call before the credit hits billing, checks the per-transaction cap for the agent’s role, and returns block with the rule cited: credit cannot exceed twice the disputed amount. The agent tells the customer it needs a supervisor. The supervisor approves. The credit posts. Finance sees the audit line, not the mistake.

Metrics that move

Actions above threshold. Human handoffs per week. Out-of-policy attempts. Median handoff time.

Where it plugs in

Any agent framework (Sierra, LangChain, custom). Any action API (Stripe, Zendesk, Salesforce, internal tools).

Not sure which one is you?

Most teams land in three at once. Pick the one that hurts the most today. The other two will be on the same Guard install.

What buyers do with Conduct — prove, kill, contain, answer, discover | Conduct | ConductAI