Defakto
Defakto secures every automated interaction by issuing short-lived, verifiable identities to non-human actors such as services, pipelines, AI agents, and machines, eliminating static credentials, API keys, and standing privileges. Their unified non-human identity and access management solution enables discovery of unmanaged identities across cloud, on-premises, and hybrid environments, issuance of dynamic identities at runtime tied to policy, enforcement of least-privilege access, and full audit-ready logging. The product consists of modules; Ledger for continuous discovery and governance of non-human identities; Mint for automated issuance of purpose-bound, ephemeral identities; Ship for secretless CI/CD workflows where hard-coded credentials are removed; Trim for automatic right-sizing of access and removal of over-privileged service accounts; and Mind for securing AI agents and large-language models with the same identity model used for workloads.
Learn more
AICtrlNet
AICtrlNet enforces AI governance instead of only observing it. Unlike tools that score or monitor AI risk, it runs the work — orchestrating AI agents, humans (as first-class agents, not just approval gates), and enterprise systems under a unified governance model. Model-independent across OpenAI, Claude, Gemini, and local runtimes (Ollama, vLLM). A 6-phase Control Spectrum sets autonomy per workflow and agent. Ships 43 role-configured agent templates and 177+ workflow templates across 41 industry packs. Runs n8n, Zapier, and Make as nodes rather than replacing them. Supports HIPAA, GDPR, SOC2, and EU AI Act via design-time governance and audit-grade accountability. Open-core editions: Community (MIT, free, self-hostable) ships the core platform; Business adds ML-enhanced governance and risk scoring; Enterprise adds multi-tenancy and federation. Access via the HitLai visual no-code interface, REST API, or MCP.
Learn more
Maetra
Maetra is an AI governance and compliance control plane for teams operating tool-using AI agents. Discover inventories agents and capabilities; Comply maps systems to applicable frameworks and keeps reusable evidence current; Govern evaluates consequential actions against versioned policies and routes human approval when required. Secure scans prompts, messages, model outputs, and tool calls for prompt injection, data exposure, unsafe actions, and policy violations. Task Guard detects task drift, scope changes, and mismatched effects. Interaction Guard protects supported browser-AI prompts and files, while Audit preserves linked decision, approval, runtime, and change evidence. Teams can adopt modules separately or together through the web app, REST APIs, SDKs, and MCP. A 14-day no-card trial is available, with paid plans from $20/month.
Learn more
Preloop
Preloop is the open source AI agent control plane for agents that take real actions. It combines an MCP firewall for tool access, an AI model gateway for cost, safety, and attribution, policy-as-code with human approvals, runtime session observability, and audit trails in a single self-hostable platform. AI agents can deploy code, change infrastructure, move money, touch production data, and burn model spend in seconds, so Preloop helps teams control what agents can do, how much they spend, and which actions require human approval. It works with OpenClaw, Hermes, Claude Code, Codex CLI, Cursor, Gemini CLI, Windsurf, Cline, OpenCode, and any MCP-compatible agent or managed runtime. Access rules can inspect arguments and context, not just tool names, with CEL expressions for fine-grained conditions. Teams can start with observability, then layer in approvals and deny rules without SDKs or invasive app changes.
Learn more