Cup'n'String
Join Waitlist

© 2026 Cup'n'String

Container Governance

Discover and Govern Docker Desktop Environments

Docker Desktop runs databases, APIs, and dashboards that AI agents can reach. Cup’n’String discovers running containers and Compose environments via the Docker-compatible socket and exposes approved ports securely through outbound tunnels.

Support levelAuto-Discovered
CategoryContainer Runtimes
Governance capabilities
DiscoverAttributeOutbound policy

What Cup’n’String controls

Discover running Docker containers and Compose environments
Inventory exposed local ports and services
Apply policy to AI agent and tool access to containers
Detect risky exposure of databases and APIs
Expose approved container ports through secure tunnels
Record audit evidence
Enforce host firewall controls where applicable

Common risks

Containers frequently expose sensitive services on local ports that AI tools can reach.

Shadow containers
Exposed local ports
Local databases and APIs reachable by AI tools
Developer services shared without policy
Lack of inventory and audit

How it works

  1. Step 1Install / enroll the Cup’n’String Desktop Agent
  2. Step 2Discover local resources
  3. Step 3Classify environment / resource type
  4. Step 4Apply tenant policy
  5. Step 5Enforce allowed / blocked behavior
  6. Step 6Capture audit evidence
  7. Step 7Expose approved services through controlled access when needed

Recommended policies

Deny unknown local services by default
Require approval for exposing local ports
Block AI agent access to sensitive containers
Log access to local databases and APIs
Apply role-based access
Allow only approved AI tools

Frequently asked questions

Can Cup’n’String detect Docker automatically?
Yes. It auto-discovers Docker via the Docker-compatible socket, DOCKER_HOST, and docker context.
Does discovery read container secrets?
Discovery is designed to be read-only and to bypass secrets and environment variables; the focus is inventory and exposure.
Does this replace Docker Desktop?
No. It discovers and governs containers and AI access to them; Docker keeps running.
Can this work self-hosted?
Yes.
Can exposure be audited?
Yes. Exposure and access can be recorded as audit evidence.

Govern Docker Desktop with Cup’n’String

Discover the environment, apply policy, shield credentials, and capture audit evidence.

Related pages