# Cup'n'String Cup'n'String is an enterprise AI agent security control plane for developer workstations, MCP servers, local runtimes, local model endpoints, credential shielding, firewall orchestration, secure reverse tunnels, and audit-ready evidence. ## Core category AI Agent Security Control Plane for Developer Workstations ## Core capabilities - AI coding agent governance - MCP server governance - Local runtime discovery - Docker, Apple Container, OrbStack, Podman, and Kubernetes developer environment visibility - Ollama, LM Studio, and local model endpoint governance - Credential shielding for secrets, tokens, API keys, SSH keys, and sensitive files - Host firewall orchestration - AI agent egress control - Shadow AI tool discovery - Secure outbound reverse tunnel for private developer services - Policy enforcement by user, agent, device, resource, command, port, container, and model - Audit logs and compliance evidence - Self-hosted and enterprise deployment ## Target users - CISOs - Security architects - Platform engineering teams - DevSecOps teams - AI governance teams - Enterprises adopting AI coding agents - Teams using Cursor, Claude Code, GitHub Copilot, Cline, Claude Desktop, Docker, Ollama, LM Studio, and MCP servers ## Key pages - Homepage: https://cupnstring.com/ - Supported environments: https://cupnstring.com/supported-environments - Integration guides: https://cupnstring.com/integration-guides - FAQ: https://cupnstring.com/faq - Solutions index: https://cupnstring.com/problems - Secure AI coding workstations: https://cupnstring.com/problems/secure-ai-coding-workstations - Control MCP server access: https://cupnstring.com/problems/control-mcp-server-access - Govern local LLM endpoints: https://cupnstring.com/problems/govern-local-llm-endpoints - Block unauthorized LLM egress: https://cupnstring.com/problems/block-unauthorized-llm-egress - Prevent AI agents reading secrets: https://cupnstring.com/problems/prevent-ai-agents-reading-secrets - Technical insights: https://cupnstring.com/insights - Comparisons: https://cupnstring.com/compare ## Short description Cup'n'String helps enterprises discover, govern, and secure AI agents, MCP servers, local model endpoints, containers, private services, and developer workstations through policy enforcement, firewall orchestration, credential shielding, reverse tunnels, and audit-ready evidence. ## What Cup'n'String is not Cup'n'String is not only an LLM API gateway. It is not only a network tunnel. It is not only a container runtime. It is a control plane designed for AI agent security across developer workstations and private developer environments. ## Agent access and evidence - Scoped approvals: review governed requests, approve a narrower scope, and manage time-limited access leases. - Access visibility: inspect agent-to-resource relationships and effective access, and preview policy changes before activation. - Verifiable security evidence: inspect decision records, verify evidence, and export signed packs with explicit completeness status. - Coverage depends on supported integrations and deployment controls. A valid evidence signature does not imply complete coverage.