Block Unauthorized LLM Egress
AI tools can send code and data directly to external providers. Cup’n’String is designed to attribute and control outbound LLM traffic on the workstation, with host firewall orchestration where supported, so unapproved egress can be detected and restricted.
Why this matters
Egress control for AI is harder than for traditional apps. Tools talk to many providers over standard HTTPS, and DNS or cloud gateways alone cannot see everything happening on a developer machine.
Agents can call OpenAI, Anthropic, Gemini, and aggregators directly
DNS and cloud gateways miss local-only and bypass paths
Unknown providers can receive sensitive context
There is often no attribution of which tool made a call
Blocking at the network alone can be blunt and easy to bypass
The Cup’n’String approach
Cup’n’String combines workstation-level attribution and proxying with host firewall orchestration to make AI egress visible and controllable.
Routes provider traffic through a managed proxy for attribution and policy where configured
Detects and surfaces unknown outbound destinations for review
Orchestrates native host firewalls (pf, WFP, nftables) where supported to restrict egress
Applies outbound policy by user, agent, device, and destination
Records egress decisions as audit evidence
How it works
- Step 1AI tool or coding agent
- Step 2Local enforcement / proxy / host policy where supported
- Step 3Cup’n’String gateway
- Step 4Approved provider / model endpoint
- Step 5Audit & policy evidence
Checklist
- Can you attribute outbound AI calls to a tool?
- Can you detect unknown providers?
- Can you restrict egress at the host where supported?
- Can you apply destination policy by role?
- Can you audit egress decisions?
- Can you self-host?
Frequently asked questions
Why are DNS and API gateways not enough?
They are useful but incomplete. Developer workstations need local enforcement and telemetry to attribute activity to a specific tool and to catch local-only or bypass paths. Cup’n’String centralizes that visibility and control.
Can it actually block egress?
Where Cup’n’String orchestrates the host firewall (pf, WFP, nftables) or routes traffic through its proxy, policy can restrict or block destinations. Guarantees are strongest when paired with operating-system, firewall, DNS, proxy, or MDM controls.
Does it break approved AI workflows?
No. Approved providers and tools continue to work. The goal is to allow approved egress while detecting and restricting unapproved destinations.
Can egress be audited?
Yes. Egress decisions and attributions can be recorded as audit evidence.
Control where AI tools can send your data
Attribute outbound AI traffic, detect unknown providers, and restrict unapproved egress.