Secure Claude Code with Cup’n’String
Claude Code is a terminal agent that reads files, runs commands, and calls MCP tools. Cup’n’String routes its traffic through a managed proxy to audit tool and MCP calls, apply outbound policy, and shield local API keys.
Support levelActive Proxy & Shielding
CategoryAI Coding Agents
Governance capabilities
AttributeOutbound policyAuditBlockRedactShield secrets
What Cup’n’String controls
Discover the Claude Code CLI and its MCP servers
Apply policy to tool, MCP, and provider access
Detect risky outbound calls
Shield credentials and sensitive files
Route approved access through the control plane
Record audit evidence
Enforce host firewall controls where applicable
Common risks
Terminal agents like Claude Code can execute commands and reach local resources directly.
Command execution against the local system
File-system reads of code and secrets
MCP tool execution
Direct provider API egress
Limited attribution without governance
Lack of centralized audit
How it works
- Step 1Install / enroll the Cup’n’String Desktop Agent
- Step 2Discover local resources
- Step 3Classify environment / resource type
- Step 4Apply tenant policy
- Step 5Enforce allowed / blocked behavior
- Step 6Capture audit evidence
- Step 7Expose approved services through controlled access when needed
Recommended policies
Allow only approved AI tools
Block direct access to secrets
Restrict shell and filesystem scope
Log all model endpoint calls
Restrict outbound AI provider access
Apply role-based access
Deny unknown local services by default
Frequently asked questions
Can Cup’n’String detect Claude Code automatically?
Yes. It is detected via the CLI process and MCP servers, and governed through Active Proxy & Shielding.
Can it restrict shell and file access?
Where activity is routed through supported paths, policy can restrict filesystem and shell scope and block disallowed actions.
Does this replace Claude Code?
No. It governs Claude Code’s activity; the agent keeps working.
Can this work self-hosted?
Yes.
Can activity be audited?
Yes. Tool and MCP calls routed through supported paths can be recorded.
Govern Claude Code with Cup’n’String
Discover the environment, apply policy, shield credentials, and capture audit evidence.