Model Context Protocol &
Tool Governance
Manage the tools and MCP servers available to local agents. Apply policy and approval checks to supported actions routed through Cup'n'String, and record the resulting decisions.
(IDE/CLI)
Intercept
(Inspect Tool)
Illustrative governed flow. Enforcement depends on the supported runtime and deployment controls.
Sovereign Firewall
Orchestration & Verification
Programs policies into native firewall rulesets rather than forcing complex custom overlays. Cup'n'String translates policy intents into platform-native pf, nftables, or SASE routes and continuously scans for config drift.
Device Operating Mode: MANAGED_AGENT
Local Container &
Shadow IT Discovery
Inspect local workstation environments read-only. Detect running Docker, Apple Container, and other container runtimes, Compose setups, and Kubernetes services. Identify shadow AI engines (Ollama, LM Studio) and expose them securely using outbound reverse tunnels (gRPC/WebSockets).
Zero-Trust API
Credential Shielding
Keep provider API keys out of AI clients on supported, gateway-routed connections. Cup'n'String brokers provider requests using tenant-managed credentials and records governed access.
Full Security Features Catalog
Discover, govern, and audit AI activity across your developer environment.
MCP & Tool Governance
Manage and audit what tools and servers AI agents can access on developer workstations.
Firewall Orchestration
Program and verify host-level OS firewalls and corporate Zero Trust networks.
Shadow AI Discovery
Discover unmanaged local AI engines and rogue developer tools.
Enterprise Identity
Federate authentication and automate user access control.
Sovereign Deployment
Run a secure, fully self-hosted, on-premises control plane.
Credential Shielding
Keep provider keys out of AI clients on supported, gateway-routed connections.
Smart Agent Groups
Group registered agents dynamically and enforce restrictive, fail-closed policies.
Power & Bandwidth Limits
Scale connection parameters and enforce session byte budgets based on device signals.
Hardened Desktop Agent
Native agent security with SPKI pinning, Ed25519 checks, and OS keystore storage.
Scoped Approvals & Access
Review requests, approve a narrower scope, and manage time-limited access leases for governed actions.
Access Visibility & Policy Preview
Inspect agent-to-resource relationships, review effective access, and preview policy changes before activation.
Verifiable Security Evidence
Inspect decision records, verify evidence, and export signed evidence packs with explicit completeness status.
Discover, govern, and secure AI on the workstation
Discover, govern, and secure AI agents, MCP servers, local model endpoints, containers, private services, and developer workstation activity with policy enforcement, credential shielding, firewall orchestration, and audit-ready evidence.
Join the Waitlist
Be the first to secure your developer machines and govern AI agent runtimes.
You're on the list!
Thank you for your interest. We'll reach out to your work email shortly.