Cup'n'String
Join Waitlist

© 2026 Cup'n'String

Security Configuration Manuals

Integration Guides

Step-by-step policy and containment profiles. Learn how to configure workstation security, firewall routing, and credential shielding for your development toolchain.

VS
Native Integration

VS Code

VS Code is one of the most common surfaces for AI-assisted development. Cup’n’String helps govern VS Code itself, agent extensions, local terminals, MCP servers, provider endpoints, and access to local services.

NetworkMCPSecretsLocal ServicesAudit
Complexity: LowView Guide
CU
Native Integration

Cursor

Cursor is an AI-native editor with high agentic activity. Cup’n’String applies IDE-aware policy, endpoint governance, secret shielding, and local-service controls.

NetworkSecretsAudit
Complexity: LowView Guide
JE
Native Integration

JetBrains IDEs

JetBrains IDEs are common in enterprise engineering teams. Cup’n’String covers IntelliJ IDEA, PyCharm, WebStorm, GoLand, PhpStorm, Rider, CLion, RubyMine, DataGrip, and Android Studio-family workflows.

NetworkSecretsAudit
Complexity: MediumView Guide
VI
Native Integration

Visual Studio

Visual Studio is critical for .NET and Windows enterprise development. Copilot Agent Mode can edit files, run commands, and use build context, so policy attribution and command/network visibility matter.

NetworkSecretsAudit
Complexity: MediumView Guide
GI
Native Policy Profile

GitHub Copilot

GitHub Copilot is a broad enterprise AI coding surface across VS Code, Visual Studio, JetBrains IDEs, Xcode, Eclipse, Vim/Neovim, and Azure Data Studio. Cup’n’String provides governance around network egress, policy attribution, and local secret exposure.

NetworkSecretsAudit
Complexity: LowView Guide
CL
Active Proxy & Shielding

Claude Desktop

Claude Desktop commonly connects to local MCP servers. Cup’n’String can govern MCP server registration, tool calls, local file access, command execution paths, and credential exposure.

NetworkMCPSecretsAudit
Complexity: MediumView Guide
CL
Active Proxy & Shielding

Claude Code

Claude Code is a terminal-first coding agent that can read files, edit repositories, and execute commands. Cup’n’String treats it as a high-value governance target.

NetworkSecretsAudit
Complexity: MediumView Guide
CL
Active Proxy & Shielding

Cline

Cline is a VS Code agent extension that can use tools, read files, run commands, and interact with MCP servers. Cup’n’String governs it as an active agent surface.

NetworkMCPSecretsAudit
Complexity: LowView Guide
RO
Active Proxy & Shielding

Roo Code

Roo Code is a VS Code agent extension that can use tools, read files, run commands, and interact with MCP servers. Cup’n’String governs it as an active agent surface.

NetworkMCPSecretsAudit
Complexity: LowView Guide
MO
Active Proxy & Shielding

Model Context Protocol (MCP)

MCP is a central protocol for connecting AI agents to tools, files, terminals, databases, and services. Cup’n’String provides managed MCP proxying, allowlists, audit logs, and policy controls.

NetworkMCPSecretsAudit
Complexity: MediumView Guide
OP
Compatibility Adapter

OpenCode

OpenCode is an open-source coding agent available as terminal, desktop, or IDE extension. Cup’n’String governs it through process detection, provider/API proxying, MCP controls, and local-service policy.

NetworkMCPSecretsAudit
Complexity: MediumView Guide
KI
Auto-Discovered

Kiro

Kiro is an AWS-backed agentic IDE/CLI built around spec-driven development. Cup’n’String provides process detection, provider/API governance, MCP-aware controls where available, and local workspace protection.

NetworkSecretsAudit
Complexity: MediumView Guide
DE
Auto-Discovered

Devin Desktop / Windsurf

Devin Desktop, formerly Windsurf, combines IDE workflows with agent command-center behavior. Cup’n’String supports detection, endpoint governance, local-service policy, and secret shielding.

NetworkSecretsAudit
Complexity: MediumView Guide
ZE
Auto-Discovered

Zed

Zed is a fast editor with AI edit prediction and provider integrations. Cup’n’String provides detection, provider governance, local-service restrictions, and credential shielding.

NetworkSecretsAudit
Complexity: LowView Guide
XC
Auto-Discovered

Xcode

Xcode is the primary Apple-platform IDE. AI assistance commonly appears through Copilot for Xcode or external agents. Cup’n’String governs provider/API traffic, project secrets, signing materials, and local service access.

NetworkSecretsAudit
Complexity: AdvancedView Guide
AN
Native Integration

Android Studio

Android Studio is JetBrains-based and increasingly uses Gemini assistance for Compose, Gradle, crashes, logs, and Android workflows. Cup’n’String governs provider traffic, project secrets, local services, emulators, and build tooling.

NetworkSecretsAudit
Complexity: MediumView Guide
CO
Compatibility Adapter

Continue.dev

Continue.dev is a common open-source assistant for VS Code and JetBrains, often used with BYO models and custom endpoints. Cup’n’String governs custom provider URLs, local model connections, MCP/tool activity, and secrets.

NetworkMCPSecretsAudit
Complexity: LowView Guide
AI
Process & Network Governance

Aider

Aider is a terminal coding agent. Cup’n’String governs it through process detection, provider/API proxying, local service controls, and secret shielding.

NetworkSecretsAudit
Complexity: LowView Guide
LO
Auto-Discovered

Local Model Servers

Local model servers such as Ollama, LM Studio, llama.cpp-compatible servers, and OpenAI-compatible local endpoints are common in privacy-sensitive teams. Cup’n’String discovers local ports, attributes access, and governs connections.

NetworkSecretsAudit
Complexity: LowView Guide
OP
Compatibility Adapter

OpenAI-compatible API Gateways

OpenAI-compatible API Gateways are governed by routing traffic through a managed proxy to attribute outbound activity, apply policy, and shield API keys.

NetworkSecretsAudit
Complexity: LowView Guide
AN
Compatibility Adapter

Anthropic-compatible API Gateways

Anthropic-compatible API Gateways are governed by routing traffic through a managed proxy to attribute activity, apply outbound policy, and shield credentials.

NetworkSecretsAudit
Complexity: LowView Guide
GE
Compatibility Adapter

Gemini-compatible API Gateways

Gemini-compatible API Gateways are governed by routing traffic through a managed proxy to attribute activity, apply policy, and shield provider keys.

NetworkSecretsAudit
Complexity: LowView Guide
OP
Compatibility Adapter

OpenRouter-compatible Gateways

OpenRouter-compatible aggregator traffic is governed by routing it through a managed proxy to attribute outbound activity across providers and shield keys.

NetworkSecretsAudit
Complexity: LowView Guide
DO
Auto-Discovered

Docker / Docker Desktop

Discovers running Docker Engine containers and local Docker Compose environments via the Docker-compatible socket. Exposes unreachable container ports securely through outbound tunnels.

NetworkAudit
Complexity: LowView Guide
OR
Native Integration

OrbStack

First-class integration with OrbStack. Automatically scans OrbStack contexts and attributes display domains (*.orb.local) as display metadata.

NetworkAudit
Complexity: LowView Guide
AP
Native Integration

Apple Container

First-class integration with Apple Container on supported macOS Apple silicon devices. Discovers VM-isolated containers, images, networks, volumes, and container machines via the native Apple container CLI.

NetworkAudit
Complexity: LowView Guide
KU
Auto-Discovered

Kubernetes (kind / minikube)

Scans local clusters created with kind or minikube. Reads active ingress controllers and cluster service mappings for secure endpoint routing.

NetworkAudit
Complexity: MediumView Guide
MA
Kernel-Level Enforcement

macOS Packet Filter (pf)

Orchestrates the host's native kernel firewall (pf) to enforce and roll back outbound network rules.

Network
Complexity: MediumView Guide
WI
Kernel-Level Enforcement

Windows Filtering Platform (WFP)

Configures native Windows Defender rules and utilizes the Windows Filtering Platform (WFP) API to inject real-time security rules into workstation network interfaces.

Network
Complexity: MediumView Guide
LI
Kernel-Level Enforcement

Linux nftables & iptables

Coordinates system-level network filters on Linux hosts using nftables and legacy iptables. Provides instant rule rollback on service interruption.

Network
Complexity: MediumView Guide
OU
Outbound-Only Transport

Outbound Reverse Tunneling

Establishes secure, bidirectional gRPC & WebSocket tunnels over TLS 1.3. Bypasses restricted NATs and enterprise firewalls without requiring open inbound ports.

Network
Complexity: LowView Guide
CO
Auto-Discovered

Colima

Supports lightweight Linux VMs running container runtimes on macOS. Discovers running sockets and groups them under the Docker-compatible adapter.

Network
Complexity: LowView Guide
PO
Native Integration

Podman

First-class integration with Podman. Discovers running pods and containers via Libpod local sockets, Podman system connections, containers.conf, and CONTAINER_HOST/CONTAINER_CONNECTION settings.

Network
Complexity: LowView Guide
RA
Auto-Discovered

Rancher Desktop

Detects active Rancher container engines and maps services dynamically for administrative governance.

Network
Complexity: LowView Guide
K3
Auto-Discovered

K3s / K3d

Integrates with lightweight k3s Kubernetes clusters running inside Docker. Discovers local services dynamically without elevated cluster privileges.

Network
Complexity: MediumView Guide
MI
Auto-Discovered

MicroK8s

Enables discovery and tunnel mapping for local Canonical MicroK8s developer environments.

Network
Complexity: MediumView Guide
EC
Auto-Discovered

Eclipse

Detects Eclipse installations and applies baseline outbound policy and local-service access control to AI plugin traffic.

Network
Complexity: LowView Guide
NE
Compatibility Adapter

Neovim / Vim / Emacs

Governs terminal editors and their AI plugins through the compatibility adapter (LSP and local proxy conventions) plus process and network governance.

NetworkSecrets
Complexity: LowView Guide
GE
Native Policy Profile

Gemini Code Assist

Applies a policy profile to Gemini Code Assist across supported IDEs and governs its provider traffic through the compatibility adapter.

NetworkSecretsAudit
Complexity: LowView Guide
TA
Process & Network Governance

Tabnine

Detects Tabnine across IDEs and applies process and network governance, routing cloud provider traffic through the compatibility adapter where configured.

NetworkSecrets
Complexity: LowView Guide
SO
Compatibility Adapter

Sourcegraph Cody / Augment

Lower-priority coverage for Sourcegraph Cody and Augment via the compatibility adapter, applying outbound policy and attribution to provider traffic.

NetworkSecrets
Complexity: LowView Guide
PA
Guard Firewall Orchestration

Palo Alto Panorama

Orchestrate security rules on Palo Alto Panorama device groups via staged candidate-config commit jobs. Guard owns only its tagged rules and provides verified, idempotent rollback.

Network
Complexity: AdvancedView Guide
FO
Guard Firewall Orchestration

FortiManager

Orchestrate policy packages on FortiManager ADOMs using workspace lock and install. Guard manages only its tagged policy block with full staged-commit semantics.

Network
Complexity: AdvancedView Guide
CH
Guard Firewall Orchestration

Check Point Management

Orchestrate access rules on Check Point Management via session → publish → install-policy. Guard owns only its tagged rule section in the designated policy package.

Network
Complexity: AdvancedView Guide
CL
ZTNA Orchestration

Cloudflare Zero Trust

Orchestrate Cloudflare Zero Trust Gateway network policies with immediate, ETag-guarded apply. Guard owns only its tagged policies under a scoped API token.

Network
Complexity: MediumView Guide
TA
ZTNA Orchestration

Tailscale

Orchestrate the Tailscale tailnet ACL grants section managed by Guard. Immediate apply with ETag-based drift detection; Guard manages only its tagged grant block.

Network
Complexity: LowView Guide
ZS
ZTNA Orchestration

Zscaler Internet Access

Orchestrate Zscaler ZIA firewall filtering rules with staged edits and activation. Guard uses a ZIA API role limited to its tagged rules and activates only its own changes.

Network
Complexity: AdvancedView Guide
MI
Cooperative Endpoint Control

Microsoft Intune

Push endpoint firewall rule profiles via Microsoft Intune. Enforcement is cooperative and device-resident. Guard tracks compliance posture and associates it with the registered agent.

Endpoint
Complexity: AdvancedView Guide
JA
Cooperative Endpoint Control

Jamf Pro

Push macOS firewall configuration profiles via Jamf Pro. Enforcement is cooperative and device-resident. Guard uses a Jamf API role limited to profiles carrying its ownership tag.

Endpoint
Complexity: MediumView Guide
AW
Cloud-Native Rules

AWS Security Groups

Orchestrate AWS VPC security group rules with immediate authorize/revoke semantics. Guard uses an IAM role limited to ec2:Authorize/Revoke on Guard-tagged security groups in one VPC.

Network
Complexity: MediumView Guide
AZ
Cloud-Native Rules

Azure Network Security Groups

Orchestrate Azure NSG security rules via ARM declarative apply with ETag-guarded, async operations. Guard uses a service principal with Network Contributor on one resource group.

Network
Complexity: MediumView Guide
GC
Cloud-Native Rules

GCP VPC Firewall

Orchestrate GCP VPC firewall rules via declarative apply with async operations. Guard uses a service account with compute.firewalls admin scoped to one network and owns only its tagged rules.

Network
Complexity: MediumView Guide
KU
Cloud-Native Rules

Kubernetes NetworkPolicy

Orchestrate Kubernetes NetworkPolicy objects via server-side apply (declarative). Guard uses a ServiceAccount with RBAC limited to networkpolicies in one namespace and owns only its labeled policies.

Network
Complexity: MediumView Guide
LO
Kernel-Level Enforcement

Local OS Firewall (Guard)

Orchestrate the device OS firewall (Windows Defender / nftables / pf) through the Cup'n'String agent. Per-process rules, offline enforcement, and device-bound agent credentials ensure fail-closed operation.

Network
Complexity: LowView Guide

Need a specialized environment template?

We offer customized enterprise policy configurations for private model routers, regional networks, and proprietary developer systems.

Contact Enterprise Support