Orchestrate macOS pf for AI Agent Policy
Cup’n’String directly orchestrates the native BSD packet filter (pf) to enforce outbound network policy for AI tools on macOS — generating clean change sets, owning only its tagged rules, and scanning for drift.
Support levelKernel-Level Enforcement
CategoryFirewalls
Governance capabilities
Outbound policyBlock
What Cup’n’String controls
Orchestrate native pf anchors and rulesets
Translate policy intent into pf rules
Block unauthorized outbound AI tool calls (kernel-level enforcement)
Generate change sets before applying rules
Continuously scan for configuration drift
Record tamper-evident audit evidence
Common risks
Hand-managed host firewall rules drift and are hard to verify, especially as AI tools change.
Outbound AI calls that bypass centralized controls
Firewall rule drift over time
No clean change sets or rollback
Limited audit of rule changes
Inconsistent enforcement across machines
How it works
- Step 1Install / enroll the Cup’n’String Desktop Agent
- Step 2Define tenant network policy intent
- Step 3Generate a clean pf change set
- Step 4Apply Guard-owned pf rules (kernel-level enforcement)
- Step 5Continuously verify for drift
- Step 6Capture audit evidence and support rollback
Recommended policies
Restrict outbound AI provider access
Block risky ports unless explicitly allowed
Deny unknown destinations by default
Apply role-based egress policy
Log and audit all rule changes
Frequently asked questions
Does Cup’n’String use native pf?
Yes. It orchestrates the native BSD packet filter (pf) via pfctl anchors and ruleset state for kernel-level enforcement on macOS.
Will it overwrite my existing pf rules?
No. Guard owns only the rule sections carrying its ownership tag and performs verified, idempotent changes with rollback.
Is enforcement unbypassable?
No tool should claim that on a general-purpose workstation. Enforcement is strongest when combined with MDM and network controls.
Are changes audited?
Yes, with a tamper-evident audit trail.
Can this work self-hosted?
Yes.
Govern macOS Packet Filter (pf) with Cup’n’String
Discover the environment, apply policy, shield credentials, and capture audit evidence.