Govern Ollama Local Model Endpoints
Ollama exposes an OpenAI-compatible endpoint (commonly on port 11434) on developer machines. Cup’n’String auto-discovers it, controls which agents may connect, and decides whether it may be exposed beyond the workstation.
Support levelAuto-Discovered
Compatibility Adapter
CategoryAI Protocols & Gateways
Governance capabilities
DiscoverAttributeOutbound policyAuditShield secrets
What Cup’n’String controls
Auto-discover the Ollama endpoint via loopback ports and process signals
Control which agents and identities may connect
Apply outbound policy to provider traffic where routed through the proxy
Decide, by policy, whether the endpoint may be exposed
Detect unintended network exposure
Record audit evidence of access
Enforce host firewall controls where applicable
Common risks
A local OpenAI-compatible endpoint is convenient and easy to reach — including by tools you did not intend.
Unmanaged local model endpoints
OpenAI-compatible endpoints exposed locally
Sensitive prompts leaving controlled flows
Lack of identity, policy, and audit
Unintended exposure to the network
How it works
- Step 1Install / enroll the Cup’n’String Desktop Agent
- Step 2Discover local resources
- Step 3Classify environment / resource type
- Step 4Apply tenant policy
- Step 5Enforce allowed / blocked behavior
- Step 6Capture audit evidence
- Step 7Expose approved services through controlled access when needed
Recommended policies
Allow only approved agents to connect
Deny unknown local services by default
Require approval for exposing the endpoint
Log all model endpoint calls
Apply role-based access
Restrict outbound provider access
Frequently asked questions
Can Cup’n’String detect Ollama automatically?
Yes. Local model servers are auto-discovered via loopback ports (e.g. 11434) and process signals, then governed through the compatibility adapter.
Can it control which agents connect?
Yes. Policy can control which agents and identities may reach the endpoint, and whether it may be exposed remotely.
Does this replace Ollama?
No. It governs access to Ollama; the endpoint keeps running.
Can this work self-hosted?
Yes.
Can access be audited?
Yes.
Govern Ollama with Cup’n’String
Discover the environment, apply policy, shield credentials, and capture audit evidence.