Cup'n'String
Join Waitlist

© 2026 Cup'n'String

Firewall Orchestration

Orchestrate Linux nftables for AI Agent Policy

Cup’n’String coordinates system-level network filters on Linux hosts using nftables and legacy iptables, providing instant rule rollback on service interruption and owning only its tagged rules.

Support levelKernel-Level Enforcement
CategoryFirewalls
Governance capabilities
Outbound policyBlock

What Cup’n’String controls

Orchestrate nftables/iptables tables and chains
Translate policy intent into host firewall rules
Block unauthorized outbound AI tool calls (kernel-level enforcement)
Generate change sets before applying rules
Provide instant rollback on service interruption
Record tamper-evident audit evidence

Common risks

Linux developer hosts and CI runners need consistent, auditable AI egress policy with safe rollback.

Outbound AI calls that bypass centralized controls
Firewall rule drift over time
Risk of lockout without safe rollback
Limited audit of rule changes
Inconsistent enforcement across machines

How it works

  1. Step 1Install / enroll the Cup’n’String Desktop Agent
  2. Step 2Define tenant network policy intent
  3. Step 3Generate a clean nftables change set
  4. Step 4Apply Guard-owned nftables/iptables rules (kernel-level enforcement)
  5. Step 5Continuously verify for drift, with instant rollback
  6. Step 6Capture audit evidence

Recommended policies

Restrict outbound AI provider access
Block risky ports unless explicitly allowed
Deny unknown destinations by default
Apply role-based egress policy
Log and audit all rule changes

Frequently asked questions

Does Cup’n’String use native nftables?
Yes. It coordinates nftables and legacy iptables tables and chains for kernel-level enforcement on Linux.
What happens if a change breaks connectivity?
Cup’n’String provides instant rule rollback on service interruption, and Guard owns only its tagged rules.
Is enforcement unbypassable?
No tool should claim that on a general-purpose host. Enforcement is strongest when combined with system and network controls.
Are changes audited?
Yes, with a tamper-evident audit trail.
Can this work self-hosted?
Yes.

Govern Linux nftables & iptables with Cup’n’String

Discover the environment, apply policy, shield credentials, and capture audit evidence.

Related pages