Integration Guides
Step-by-step policy and containment profiles. Learn how to configure workstation security, firewall routing, and credential shielding for your development toolchain.
VS Code
VS Code is one of the most common surfaces for AI-assisted development. Cup’n’String helps govern VS Code itself, agent extensions, local terminals, MCP servers, provider endpoints, and access to local services.
Cursor
Cursor is an AI-native editor with high agentic activity. Cup’n’String applies IDE-aware policy, endpoint governance, secret shielding, and local-service controls.
JetBrains IDEs
JetBrains IDEs are common in enterprise engineering teams. Cup’n’String covers IntelliJ IDEA, PyCharm, WebStorm, GoLand, PhpStorm, Rider, CLion, RubyMine, DataGrip, and Android Studio-family workflows.
Visual Studio
Visual Studio is critical for .NET and Windows enterprise development. Copilot Agent Mode can edit files, run commands, and use build context, so policy attribution and command/network visibility matter.
GitHub Copilot
GitHub Copilot is a broad enterprise AI coding surface across VS Code, Visual Studio, JetBrains IDEs, Xcode, Eclipse, Vim/Neovim, and Azure Data Studio. Cup’n’String provides governance around network egress, policy attribution, and local secret exposure.
Claude Desktop
Claude Desktop commonly connects to local MCP servers. Cup’n’String can govern MCP server registration, tool calls, local file access, command execution paths, and credential exposure.
Claude Code
Claude Code is a terminal-first coding agent that can read files, edit repositories, and execute commands. Cup’n’String treats it as a high-value governance target.
Cline
Cline is a VS Code agent extension that can use tools, read files, run commands, and interact with MCP servers. Cup’n’String governs it as an active agent surface.
Roo Code
Roo Code is a VS Code agent extension that can use tools, read files, run commands, and interact with MCP servers. Cup’n’String governs it as an active agent surface.
Model Context Protocol (MCP)
MCP is a central protocol for connecting AI agents to tools, files, terminals, databases, and services. Cup’n’String provides managed MCP proxying, allowlists, audit logs, and policy controls.
OpenCode
OpenCode is an open-source coding agent available as terminal, desktop, or IDE extension. Cup’n’String governs it through process detection, provider/API proxying, MCP controls, and local-service policy.
Kiro
Kiro is an AWS-backed agentic IDE/CLI built around spec-driven development. Cup’n’String provides process detection, provider/API governance, MCP-aware controls where available, and local workspace protection.
Devin Desktop / Windsurf
Devin Desktop, formerly Windsurf, combines IDE workflows with agent command-center behavior. Cup’n’String supports detection, endpoint governance, local-service policy, and secret shielding.
Zed
Zed is a fast editor with AI edit prediction and provider integrations. Cup’n’String provides detection, provider governance, local-service restrictions, and credential shielding.
Xcode
Xcode is the primary Apple-platform IDE. AI assistance commonly appears through Copilot for Xcode or external agents. Cup’n’String governs provider/API traffic, project secrets, signing materials, and local service access.
Android Studio
Android Studio is JetBrains-based and increasingly uses Gemini assistance for Compose, Gradle, crashes, logs, and Android workflows. Cup’n’String governs provider traffic, project secrets, local services, emulators, and build tooling.
Continue.dev
Continue.dev is a common open-source assistant for VS Code and JetBrains, often used with BYO models and custom endpoints. Cup’n’String governs custom provider URLs, local model connections, MCP/tool activity, and secrets.
Aider
Aider is a terminal coding agent. Cup’n’String governs it through process detection, provider/API proxying, local service controls, and secret shielding.
Local Model Servers
Local model servers such as Ollama, LM Studio, llama.cpp-compatible servers, and OpenAI-compatible local endpoints are common in privacy-sensitive teams. Cup’n’String discovers local ports, attributes access, and governs connections.
OpenAI-compatible API Gateways
OpenAI-compatible API Gateways are governed by routing traffic through a managed proxy to attribute outbound activity, apply policy, and shield API keys.
Anthropic-compatible API Gateways
Anthropic-compatible API Gateways are governed by routing traffic through a managed proxy to attribute activity, apply outbound policy, and shield credentials.
Gemini-compatible API Gateways
Gemini-compatible API Gateways are governed by routing traffic through a managed proxy to attribute activity, apply policy, and shield provider keys.
OpenRouter-compatible Gateways
OpenRouter-compatible aggregator traffic is governed by routing it through a managed proxy to attribute outbound activity across providers and shield keys.
Docker / Docker Desktop
Discovers running Docker Engine containers and local Docker Compose environments via the Docker-compatible socket. Exposes unreachable container ports securely through outbound tunnels.
OrbStack
First-class integration with OrbStack. Automatically scans OrbStack contexts and attributes display domains (*.orb.local) as display metadata.
Apple Container
First-class integration with Apple Container on supported macOS Apple silicon devices. Discovers VM-isolated containers, images, networks, volumes, and container machines via the native Apple container CLI.
Kubernetes (kind / minikube)
Scans local clusters created with kind or minikube. Reads active ingress controllers and cluster service mappings for secure endpoint routing.
macOS Packet Filter (pf)
Orchestrates the host's native kernel firewall (pf) to enforce and roll back outbound network rules.
Windows Filtering Platform (WFP)
Configures native Windows Defender rules and utilizes the Windows Filtering Platform (WFP) API to inject real-time security rules into workstation network interfaces.
Linux nftables & iptables
Coordinates system-level network filters on Linux hosts using nftables and legacy iptables. Provides instant rule rollback on service interruption.
Outbound Reverse Tunneling
Establishes secure, bidirectional gRPC & WebSocket tunnels over TLS 1.3. Bypasses restricted NATs and enterprise firewalls without requiring open inbound ports.
Colima
Supports lightweight Linux VMs running container runtimes on macOS. Discovers running sockets and groups them under the Docker-compatible adapter.
Podman
First-class integration with Podman. Discovers running pods and containers via Libpod local sockets, Podman system connections, containers.conf, and CONTAINER_HOST/CONTAINER_CONNECTION settings.
Rancher Desktop
Detects active Rancher container engines and maps services dynamically for administrative governance.
K3s / K3d
Integrates with lightweight k3s Kubernetes clusters running inside Docker. Discovers local services dynamically without elevated cluster privileges.
MicroK8s
Enables discovery and tunnel mapping for local Canonical MicroK8s developer environments.
Eclipse
Detects Eclipse installations and applies baseline outbound policy and local-service access control to AI plugin traffic.
Neovim / Vim / Emacs
Governs terminal editors and their AI plugins through the compatibility adapter (LSP and local proxy conventions) plus process and network governance.
Gemini Code Assist
Applies a policy profile to Gemini Code Assist across supported IDEs and governs its provider traffic through the compatibility adapter.
Tabnine
Detects Tabnine across IDEs and applies process and network governance, routing cloud provider traffic through the compatibility adapter where configured.
Sourcegraph Cody / Augment
Lower-priority coverage for Sourcegraph Cody and Augment via the compatibility adapter, applying outbound policy and attribution to provider traffic.
Palo Alto Panorama
Orchestrate security rules on Palo Alto Panorama device groups via staged candidate-config commit jobs. Guard owns only its tagged rules and provides verified, idempotent rollback.
FortiManager
Orchestrate policy packages on FortiManager ADOMs using workspace lock and install. Guard manages only its tagged policy block with full staged-commit semantics.
Check Point Management
Orchestrate access rules on Check Point Management via session → publish → install-policy. Guard owns only its tagged rule section in the designated policy package.
Cloudflare Zero Trust
Orchestrate Cloudflare Zero Trust Gateway network policies with immediate, ETag-guarded apply. Guard owns only its tagged policies under a scoped API token.
Tailscale
Orchestrate the Tailscale tailnet ACL grants section managed by Guard. Immediate apply with ETag-based drift detection; Guard manages only its tagged grant block.
Zscaler Internet Access
Orchestrate Zscaler ZIA firewall filtering rules with staged edits and activation. Guard uses a ZIA API role limited to its tagged rules and activates only its own changes.
Microsoft Intune
Push endpoint firewall rule profiles via Microsoft Intune. Enforcement is cooperative and device-resident. Guard tracks compliance posture and associates it with the registered agent.
Jamf Pro
Push macOS firewall configuration profiles via Jamf Pro. Enforcement is cooperative and device-resident. Guard uses a Jamf API role limited to profiles carrying its ownership tag.
AWS Security Groups
Orchestrate AWS VPC security group rules with immediate authorize/revoke semantics. Guard uses an IAM role limited to ec2:Authorize/Revoke on Guard-tagged security groups in one VPC.
Azure Network Security Groups
Orchestrate Azure NSG security rules via ARM declarative apply with ETag-guarded, async operations. Guard uses a service principal with Network Contributor on one resource group.
GCP VPC Firewall
Orchestrate GCP VPC firewall rules via declarative apply with async operations. Guard uses a service account with compute.firewalls admin scoped to one network and owns only its tagged rules.
Kubernetes NetworkPolicy
Orchestrate Kubernetes NetworkPolicy objects via server-side apply (declarative). Guard uses a ServiceAccount with RBAC limited to networkpolicies in one namespace and owns only its labeled policies.
Local OS Firewall (Guard)
Orchestrate the device OS firewall (Windows Defender / nftables / pf) through the Cup'n'String agent. Per-process rules, offline enforcement, and device-bound agent credentials ensure fail-closed operation.
No guides found
Try adjusting your keywords or selecting a different category filter.
Need a specialized environment template?
We offer customized enterprise policy configurations for private model routers, regional networks, and proprietary developer systems.
Contact Enterprise Support