Cup'n'String
Join Waitlist

© 2026 Cup'n'String

AI Coding Agent Security

Secure Claude Code with Cup’n’String

Claude Code is a terminal agent that reads files, runs commands, and calls MCP tools. Cup’n’String routes its traffic through a managed proxy to audit tool and MCP calls, apply outbound policy, and shield local API keys.

Support levelActive Proxy & Shielding
CategoryAI Coding Agents
Governance capabilities
AttributeOutbound policyAuditBlockRedactShield secrets

What Cup’n’String controls

Discover the Claude Code CLI and its MCP servers
Apply policy to tool, MCP, and provider access
Detect risky outbound calls
Shield credentials and sensitive files
Route approved access through the control plane
Record audit evidence
Enforce host firewall controls where applicable

Common risks

Terminal agents like Claude Code can execute commands and reach local resources directly.

Command execution against the local system
File-system reads of code and secrets
MCP tool execution
Direct provider API egress
Limited attribution without governance
Lack of centralized audit

How it works

  1. Step 1Install / enroll the Cup’n’String Desktop Agent
  2. Step 2Discover local resources
  3. Step 3Classify environment / resource type
  4. Step 4Apply tenant policy
  5. Step 5Enforce allowed / blocked behavior
  6. Step 6Capture audit evidence
  7. Step 7Expose approved services through controlled access when needed

Recommended policies

Allow only approved AI tools
Block direct access to secrets
Restrict shell and filesystem scope
Log all model endpoint calls
Restrict outbound AI provider access
Apply role-based access
Deny unknown local services by default

Frequently asked questions

Can Cup’n’String detect Claude Code automatically?
Yes. It is detected via the CLI process and MCP servers, and governed through Active Proxy & Shielding.
Can it restrict shell and file access?
Where activity is routed through supported paths, policy can restrict filesystem and shell scope and block disallowed actions.
Does this replace Claude Code?
No. It governs Claude Code’s activity; the agent keeps working.
Can this work self-hosted?
Yes.
Can activity be audited?
Yes. Tool and MCP calls routed through supported paths can be recorded.

Govern Claude Code with Cup’n’String

Discover the environment, apply policy, shield credentials, and capture audit evidence.

Related pages