Cup'n'String
Join Waitlist

© 2026 Cup'n'String

The Enterprise Security Brain for AI Agents

AI agents are powerful.
Give them boundaries.

A standalone security control plane that automatically discovers local runtimes, orchestrates host firewalls, secures model endpoints, and compiles compliance evidence for your developer workstations.

Join the waitlistExplore Capabilities

Model Context Protocol &
Tool Governance

Manage the tools and MCP servers available to local agents. Apply policy and approval checks to supported actions routed through Cup'n'String, and record the resulting decisions.

Enforce strict tool schema and parameter boundary limits.
Dynamic prompt/response risk classification and PII redaction.
Governed MCP server registry with custom administrative approval workflows.
AI Tool Gating Flow
Real-Time
AI Client
(IDE/CLI)
Gateway127.0.0.1
Local Gateway
Intercept
Policy Engine
Rule Matcher
(Inspect Tool)
INTERCEPT LOGactive
✔tool: fs_read_file("/src/index.ts") → APPROVED
✘tool: shell_run("rm -rf /") → BLOCKED

Illustrative governed flow. Enforcement depends on the supported runtime and deployment controls.

Sovereign Firewall
Orchestration & Verification

Programs policies into native firewall rulesets rather than forcing complex custom overlays. Cup'n'String translates policy intents into platform-native pf, nftables, or SASE routes and continuously scans for config drift.

Generates clean change sets before applying security rules.
Continuous policy verification scanning for real-time host config drift.
Tamper-evident audit records with HMAC-based integrity checks.
Firewall Orchestration
Orchestrated
macOS pf / Windows DefenderActive

Device Operating Mode: MANAGED_AGENT

CHANGE SET PREVIEW1 Proposed
@@ -23,8 +23,9 @@
- pass out proto tcp to any port 8080
+ block out proto tcp to any port 8080
+ pass out proto tcp to 127.0.0.1 port 8080
Evidence Hash Generated
HMAC Verified

Local Container &
Shadow IT Discovery

Inspect local workstation environments read-only. Detect running Docker, Apple Container, and other container runtimes, Compose setups, and Kubernetes services. Identify shadow AI engines (Ollama, LM Studio) and expose them securely using outbound reverse tunnels (gRPC/WebSockets).

Bypasses secrets, env vars, and code configs for strict read-only privacy.
Converts shadow containers to formal tenant-governed endpoints.
Outbound reverse tunnels (gRPC/WebSockets) securely bridge local runtimes.
Local Service Scanner
Read-Only
Docker / Podman / Compose
5 services found
Kubernetes Cluster
Kubeconfig Active
🔐 Privacy Guardrails Active:Zero collection of environment secrets, Kubernetes config secrets, database passwords, or raw inspector payloads. Scanner strictly lists container labels and exposed ports.

Zero-Trust API
Credential Shielding

Keep provider API keys out of AI clients on supported, gateway-routed connections. Cup'n'String brokers provider requests using tenant-managed credentials and records governed access.

Zero-trust local proxies map key references without local plaintext keys.
Stores keys in tenant-isolated encrypted keystores.
Tracks cost quotas and token limits per developer.
Credential Shielding
Zero-Trust
1. Workstation requestNo LLM Key
2. Provider GatewayInjects Key Reference
3. Outbound LLM CallKeys Injected
"Tenant-managed keys are used for supported provider requests routed through the gateway."

Full Security Features Catalog

Discover, govern, and audit AI activity across your developer environment.

Bo

MCP & Tool Governance

Manage and audit what tools and servers AI agents can access on developer workstations.

Sh

Firewall Orchestration

Program and verify host-level OS firewalls and corporate Zero Trust networks.

Se

Shadow AI Discovery

Discover unmanaged local AI engines and rogue developer tools.

Us

Enterprise Identity

Federate authentication and automate user access control.

Se

Sovereign Deployment

Run a secure, fully self-hosted, on-premises control plane.

Sh

Credential Shielding

Keep provider keys out of AI clients on supported, gateway-routed connections.

Us

Smart Agent Groups

Group registered agents dynamically and enforce restrictive, fail-closed policies.

Ac

Power & Bandwidth Limits

Scale connection parameters and enforce session byte budgets based on device signals.

Sh

Hardened Desktop Agent

Native agent security with SPKI pinning, Ed25519 checks, and OS keystore storage.

Sh

Scoped Approvals & Access

Review requests, approve a narrower scope, and manage time-limited access leases for governed actions.

Se

Access Visibility & Policy Preview

Inspect agent-to-resource relationships, review effective access, and preview policy changes before activation.

Sh

Verifiable Security Evidence

Inspect decision records, verify evidence, and export signed evidence packs with explicit completeness status.

AI Agent Security Control Plane for Developer Workstations

Discover, govern, and secure AI on the workstation

Discover, govern, and secure AI agents, MCP servers, local model endpoints, containers, private services, and developer workstation activity with policy enforcement, credential shielding, firewall orchestration, and audit-ready evidence.

Join the Waitlist

Be the first to secure your developer machines and govern AI agent runtimes.