Cup'n'String
Join Waitlist

© 2026 Cup'n'String

Integration & System Compatibility

Supported Environments

Cup'n'String coordinates directly with operating systems, native firewall kernel engines, and virtualization frameworks to secure developer workstations without workflow disruption.

Showing 45 of 45 environments
What do the support levels mean?
Native Integration

First-class, product-specific adapter with richer metadata, attribution, policy controls, and lifecycle awareness.

Active Proxy & Shielding

Cup’n’String sits in the path of tool, API, and MCP activity and can audit, block, redact, or shield secrets.

Auto-Discovered

Detected through processes, sockets, config files, contexts, ports, or known installation paths.

Compatibility Adapter

Integrated through a common compatibility layer such as MCP, OpenAI/Anthropic-compatible APIs, Docker sockets, LSP, or local proxy conventions.

Process & Network Governance

Baseline process fingerprinting, outbound policy, local-service access control, and secret shielding without deeper IDE hooks.

Native Policy Profile

A reusable policy profile applied to an agent across every IDE or editor it runs in.

Provider & API Proxy

Provider and API requests are routed through a managed proxy for attribution, auditing, and control.

Developer Preview

Support is intentionally early or experimental.

Support depth varies by environment. See the FAQ for how observe, warn, and enforce modes apply.

LI
Kernel-Level Enforcement

Linux nftables & iptables

Coordinates system-level network filters on Linux hosts using nftables and legacy iptables. Provides instant rule rollback on service interruption.

Controls
Outbound policy Block

Detected via nftables/iptables tables and chains

Firewalls
macOSWindowsLinux
MA
Kernel-Level Enforcement

macOS Packet Filter (pf)

Directly orchestrates the native BSD packet filter (pf) rulesets to block unauthorized outbound LLM tool network calls and enforce local security policy boundaries.

Controls
Outbound policy Block

Detected via pfctl anchors and ruleset state

Firewalls
macOSWindowsLinux
WI
Kernel-Level Enforcement

Windows Filtering Platform (WFP)

Configures native Windows Defender rules and utilizes the Windows Filtering Platform (WFP) API to inject real-time security rules into workstation network interfaces.

Controls
Outbound policy Block

Detected via WFP filter layers and Defender rules

Firewalls
macOSWindowsLinux
OU
Outbound-Only Transport

Outbound Reverse Tunneling

Establishes secure, bidirectional gRPC & WebSocket tunnels over TLS 1.3. Bypasses restricted NATs and enterprise firewalls without requiring open inbound ports.

Controls
Outbound policy

Detected via Agent-initiated outbound TLS session

Firewalls
macOSWindowsLinux
DO
Auto-Discovered

Docker / Docker Desktop

Discovers running Docker Engine containers and local Docker Compose environments via the Docker-compatible socket. Exposes unreachable container ports securely through outbound tunnels.

Controls
Discover Attribute Outbound policy

Detected via docker.sock, DOCKER_HOST, docker context

Container Runtimes
macOSWindowsLinux
CO
Auto-Discovered

Colima

Supports lightweight Linux VMs running container runtimes on macOS. Discovers running sockets and groups them under the Docker-compatible adapter.

Controls
Discover Attribute Outbound policy

Detected via Colima profile sockets

Container Runtimes
macOSWindowsLinux
OR
Native Integration

OrbStack

First-class integration with OrbStack. Automatically scans OrbStack contexts and attributes display domains (*.orb.local) as display metadata.

Controls
Discover Attribute Outbound policy Audit Shield secrets

Detected via OrbStack socket and *.orb.local contexts

Container Runtimes
macOSWindowsLinux
PO
Compatibility Socket

Podman

Scans for rootless or rootful Podman compatibility sockets to discover running pods and local containers without requiring a daemon.

Controls
Discover

Detected via Podman compat socket (rootless/rootful)

Container Runtimes
macOSWindowsLinux
RA
Auto-Discovered

Rancher Desktop

Detects active Rancher container engines and maps services dynamically for administrative governance.

Controls
Discover Attribute Outbound policy

Detected via Rancher Desktop socket and contexts

Container Runtimes
macOSWindowsLinux
KU
Auto-Discovered

Kubernetes (kind / minikube)

Scans local clusters created with kind or minikube. Reads active ingress controllers and cluster service mappings for secure endpoint routing.

Controls
Discover Attribute Outbound policy

Detected via kubeconfig context enumeration

Kubernetes
macOSWindowsLinux
K3
Auto-Discovered

K3s / K3d

Integrates with lightweight k3s Kubernetes clusters running inside Docker. Discovers local services dynamically without elevated cluster privileges.

Controls
Discover Attribute Outbound policy

Detected via k3s/k3d kubeconfig contexts

Kubernetes
macOSWindowsLinux
MI
Auto-Discovered

MicroK8s

Enables discovery and tunnel mapping for local Canonical MicroK8s developer environments.

Controls
Discover Attribute Outbound policy

Detected via MicroK8s kubeconfig context

Kubernetes
macOSWindowsLinux
CU
Native Integration

Cursor

Enforces firewall boundaries and credential protection for Cursor's local AI agent. Routes model and MCP traffic through the managed proxy to audit tool calls and shield secrets.

Active Proxy & Shielding
Controls
Discover Attribute Outbound policy Audit Block Redact Shield secrets

Detected via Process + MCP config + provider endpoints

AI IDEs & Editors
Guide
macOSWindowsLinux
JE
Native Integration

JetBrains IDEs

Native policy coverage across the JetBrains family (IntelliJ IDEA, PyCharm, GoLand, WebStorm, Rider, CLion and more). Attributes outbound AI activity and applies local-service access control.

Controls
Discover Attribute Outbound policy Audit Shield secrets

Detected via JetBrains Toolbox + IDE process fingerprint

AI IDEs & Editors
Guide
macOSWindowsLinux
VS
Native Integration

VS Code

Identifies the Visual Studio Code process and routes its AI extension traffic through the managed proxy. Audits tool calls, applies outbound policy, and shields workspace credentials.

Active Proxy & Shielding
Controls
Discover Attribute Outbound policy Audit Block Redact Shield secrets

Detected via Process + extension host + MCP config

AI IDEs & Editors
Guide
macOSWindowsLinux
AN
Native Integration

Android Studio

Covered by the JetBrains-family native adapter, with Gemini-aware governance applied to outbound assistant activity.

Process & Network Governance
Controls
Discover Attribute Outbound policy Audit Shield secrets

Detected via JetBrains-family process fingerprint

AI IDEs & Editors
Guide
macOSWindowsLinux
DE
Auto-Discovered

Devin Desktop / Windsurf

Detects the Windsurf editor through process and installation signals, with a path toward native integration. Governs model and MCP traffic via the compatibility adapter today.

Compatibility Adapter
Controls
Discover Attribute Outbound policy Audit Shield secrets

Detected via Process + install path + MCP config

AI IDEs & Editors
Guide
macOSWindowsLinux
KI
Auto-Discovered

Kiro

Detects the Kiro agentic IDE and governs its MCP servers and model providers through the compatibility adapter, auditing tool calls and shielding local credentials.

Compatibility Adapter
Controls
Discover Attribute Outbound policy Audit Shield secrets

Detected via Process + MCP config (mcp.json)

AI IDEs & Editors
Guide
macOSWindowsLinux
VI
Native Integration

Visual Studio

Applies a native policy profile to Microsoft Visual Studio, governing Copilot and other AI assistants with outbound policy and credential shielding.

Controls
Discover Attribute Outbound policy Audit Shield secrets

Detected via devenv.exe process fingerprint

AI IDEs & Editors
Guide
macOSWindowsLinux
EC
Auto-Discovered

Eclipse

Detects Eclipse installations and applies baseline outbound policy and local-service access control to AI plugin traffic.

Controls
Discover Attribute Outbound policy

Detected via Process + install path

AI IDEs & Editors
macOSWindowsLinux
NE
Compatibility Adapter

Neovim / Vim / Emacs

Governs terminal editors and their AI plugins through the compatibility adapter (LSP and local proxy conventions) plus process and network governance.

Process & Network Governance
Controls
Discover Attribute Outbound policy Audit Shield secrets

Detected via Process + LSP / local proxy conventions

AI IDEs & Editors
macOSWindowsLinux
XC
Auto-Discovered

Xcode

Detects Xcode and applies process and network governance, with Copilot/MCP-aware policy where those assistants are present.

Process & Network Governance
Controls
Discover Attribute Outbound policy Shield secrets

Detected via Process fingerprint + extension scan

AI IDEs & Editors
Guide
macOSWindowsLinux
ZE
Auto-Discovered

Zed

Detects the Zed editor and applies baseline process fingerprinting and outbound policy to its assistant traffic without deeper editor hooks.

Process & Network Governance
Controls
Discover Attribute Outbound policy Shield secrets

Detected via Process fingerprint

AI IDEs & Editors
Guide
macOSWindowsLinux
CL
Active Proxy & Shielding

Claude Code

Routes Claude Code's terminal agent traffic through the managed proxy. Audits tool and MCP calls, applies outbound policy, and shields local API keys.

Controls
Attribute Outbound policy Audit Block Redact Shield secrets

Detected via CLI process + MCP servers

AI Coding Agents
Guide
macOSWindowsLinux
CL
Active Proxy & Shielding

Claude Desktop

Proxies Claude Desktop's Model Context Protocol (MCP) servers, auditing file reads and terminal executions while safeguarding local API keys.

Controls
Attribute Outbound policy Audit Block Redact Shield secrets

Detected via App process + MCP server config

AI Coding Agents
Guide
macOSWindowsLinux
GI
Native Policy Profile

GitHub Copilot

A reusable policy profile for GitHub Copilot, Copilot Chat, and Agent Mode that travels across supported IDEs. Attributes outbound activity and applies consistent outbound policy.

Controls
Attribute Outbound policy Audit

Detected via Copilot endpoints across host IDEs

AI Coding Agents
Guide
macOSWindowsLinux
CL
Active Proxy & Shielding

Cline

Monitors file-system access and command execution from the Cline VS Code agent via the secure local proxy, auditing tool calls and shielding credentials.

Controls
Attribute Outbound policy Audit Block Redact Shield secrets

Detected via VS Code extension + MCP config

AI Coding Agents
Guide
macOSWindowsLinux
CO
Compatibility Adapter

Continue.dev

Governs the Continue.dev assistant through the compatibility adapter, applying outbound policy and MCP-aware auditing to its configured providers.

Controls
Attribute Outbound policy Audit Shield secrets

Detected via IDE extension + config.json providers

AI Coding Agents
Guide
macOSWindowsLinux
GE
Native Policy Profile

Gemini Code Assist

Applies a policy profile to Gemini Code Assist across supported IDEs and governs its provider traffic through the compatibility adapter.

Compatibility Adapter
Controls
Attribute Outbound policy Audit Shield secrets

Detected via Plugin + Gemini API endpoints

AI Coding Agents
macOSWindowsLinux
OP
Compatibility Adapter

OpenCode

Governs the OpenCode terminal agent through the compatibility adapter, with MCP and provider proxy support to audit tool calls and route model traffic.

Provider & API Proxy
Controls
Attribute Outbound policy Audit Redact Shield secrets

Detected via CLI process + provider/MCP endpoints

AI Coding Agents
Guide
macOSWindowsLinux
RO
Active Proxy & Shielding

Roo Code

Monitors file-system access and command execution from the Roo Code VS Code agent via the secure local proxy, auditing tool calls and shielding credentials.

Controls
Attribute Outbound policy Audit Block Redact Shield secrets

Detected via VS Code extension + MCP config

AI Coding Agents
Guide
macOSWindowsLinux
AI
Process & Network Governance

Aider

Applies baseline process fingerprinting and outbound policy to the Aider terminal agent, with secret shielding for configured provider keys.

Controls
Discover Attribute Outbound policy Shield secrets

Detected via CLI process fingerprint

AI Coding Agents
Guide
macOSWindowsLinux
SO
Compatibility Adapter

Sourcegraph Cody / Augment

Lower-priority coverage for Sourcegraph Cody and Augment via the compatibility adapter, applying outbound policy and attribution to provider traffic.

Controls
Attribute Outbound policy Audit Shield secrets

Detected via Extension + provider endpoints

AI Coding Agents
macOSWindowsLinux
TA
Process & Network Governance

Tabnine

Detects Tabnine across IDEs and applies process and network governance, routing cloud provider traffic through the compatibility adapter where configured.

Compatibility Adapter
Controls
Discover Attribute Outbound policy Audit Shield secrets

Detected via Extension + provider endpoints

AI Coding Agents
macOSWindowsLinux
LO
Auto-Discovered

Local Model Servers

Detects local inference servers (Ollama, LM Studio, llama.cpp-compatible, and other OpenAI-compatible local endpoints) and governs their access through the compatibility adapter.

Compatibility Adapter
Controls
Discover Attribute Outbound policy Audit Shield secrets

Detected via Loopback ports (e.g. 11434) + process

AI Protocols & Gateways
Guide
macOSWindowsLinux
MO
Active Proxy & Shielding

Model Context Protocol (MCP)

Sits in the path of MCP servers and clients to audit tool calls, block disallowed actions, redact sensitive output, and shield local secrets.

Controls
Attribute Outbound policy Audit Block Redact Shield secrets

Detected via MCP stdio/SSE servers + client configs

AI Protocols & Gateways
Guide
macOSWindowsLinux
OP
Compatibility Adapter

OpenAI-compatible API Gateways

Routes OpenAI-compatible API traffic through a managed proxy to attribute outbound activity, apply policy, and shield API keys.

Provider & API Proxy
Controls
Attribute Outbound policy Audit Redact Shield secrets

Detected via /v1/chat/completions style endpoints

AI Protocols & Gateways
Guide
macOSWindowsLinux
AN
Compatibility Adapter

Anthropic-compatible API Gateways

Routes Anthropic-compatible API traffic through a managed proxy to attribute activity, apply outbound policy, and shield credentials.

Provider & API Proxy
Controls
Attribute Outbound policy Audit Redact Shield secrets

Detected via /v1/messages style endpoints

AI Protocols & Gateways
Guide
macOSWindowsLinux
GE
Compatibility Adapter

Gemini-compatible API Gateways

Routes Gemini-compatible API traffic through a managed proxy to attribute activity, apply policy, and shield provider keys.

Provider & API Proxy
Controls
Attribute Outbound policy Audit Redact Shield secrets

Detected via generativelanguage / Vertex endpoints

AI Protocols & Gateways
Guide
macOSWindowsLinux
OP
Compatibility Adapter

OpenRouter-compatible Gateways

Routes OpenRouter-compatible aggregator traffic through a managed proxy to attribute outbound activity across providers and shield keys.

Provider & API Proxy
Controls
Attribute Outbound policy Audit Redact Shield secrets

Detected via openrouter.ai/api endpoints

AI Protocols & Gateways
Guide
macOSWindowsLinux
LI
Native Agent & Daemon

Linux (amd64 / arm64)

Pre-compiled systemd daemons and binary distributions for Debian, Ubuntu, RedHat, and Arch configurations.

Controls
Discover Outbound policy Shield secrets

Detected via systemd daemon (amd64 / arm64)

OS & Architectures
macOSWindowsLinux
MA
Native Agent (Apple / Intel)

macOS

Full Apple Silicon (M1/M2/M3) and Intel 64-bit native application support. Signed PKG/DMG distribution formats.

Controls
Discover Outbound policy Shield secrets

Detected via Signed native app (arm64 / x86_64)

OS & Architectures
macOSWindowsLinux
WI
Native Agent (x64)

Windows

Native agent compiled for Windows 10/11 x64 systems, packaged as an enterprise-grade MSI installer.

Controls
Discover Outbound policy Shield secrets

Detected via Signed MSI service (x64)

OS & Architectures
macOSWindowsLinux
AN
Mobile App (Kotlin/Compose)

Android

Kotlin Multiplatform mobile agent built for background WebSocket service tunneling and enrollment via link or QR code.

Controls
Discover Outbound policy

Detected via KMP app + background service

OS & Architectures
macOSWindowsLinux
HA
Developer Preview

HarmonyOS NEXT

Preview version of the client SDK and agent interface targeting HarmonyOS NEXT devices.

Controls
Discover

Detected via Preview client SDK

OS & Architectures
macOSWindowsLinux

Don't see your specific stack?

Cup'n'String is built on open standards like Docker API, Kubernetes configs, and standard OS system sockets. Custom adaptors can be easily introduced via our Kotlin Multiplatform Agent SDK.

Request Custom Adaptor Support