Token Security
Token Security accelerates secure enterprise adoption of Agentic AI by discovering, managing, and governing every AI agent and non-human identity across the organization. From continuous visibility to least-privilege enforcement and lifecycle management, Token Security provides complete control over AI and machine identities, eliminating blind spots, reducing risk, and ensuring compliance at scale.
Learn more
Golf
GolfMCP is an open source framework designed to streamline the creation and deployment of production-ready Model Context Protocol (MCP) servers, enabling organizations to build secure, scalable AI-agent infrastructure without worrying about boilerplate. It allows developers to define tools, prompts, and resources as simple Python files, after which Golf handles routing, authentication, telemetry, and observability, so you focus on logic, not plumbing. The platform supports enterprise authentication (JWT, OAuth Server, API key), automatic telemetry, and a file-based structure that eliminates decorators or manual schema wiring. With built-in utilities for LLM interactions, error logging, OpenTelemetry integration, and deployment tools (such as a CLI with golf init, golf build dev, golf run), Golf provides a full stack for agent-native services. Included also is the Golf Firewall, an enterprise-grade security layer for MCP servers that enforces token validation.
Learn more
Preloop
Preloop is the open source AI agent control plane for agents that take real actions. It combines an MCP firewall for tool access, an AI model gateway for cost, safety, and attribution, policy-as-code with human approvals, runtime session observability, and audit trails in a single self-hostable platform. AI agents can deploy code, change infrastructure, move money, touch production data, and burn model spend in seconds, so Preloop helps teams control what agents can do, how much they spend, and which actions require human approval. It works with OpenClaw, Hermes, Claude Code, Codex CLI, Cursor, Gemini CLI, Windsurf, Cline, OpenCode, and any MCP-compatible agent or managed runtime. Access rules can inspect arguments and context, not just tool names, with CEL expressions for fine-grained conditions. Teams can start with observability, then layer in approvals and deny rules without SDKs or invasive app changes.
Learn more
KYDE
KYDE is the behavioral firewall for AI agents. KYDE makes AI agents trustworthy enough to hand them real responsibility. It prevents what an agent must not do, proves what it did, and keeps your knowledge yours.
Not on the machine. Not in the agent. KYDE sits outside, in the request path between your agents and every LLM provider — every action intercepted, scoped, and signed before it executes. Outside the agent. Cannot be overridden.
Zero code changes. One environment variable. Provider-agnostic, MCP-ready, <100 ms target latency.
Three functions. One layer.
PROVE — After the action. An audit trail that is architecturally independent of every LLM provider: Ed25519-signed, hash-chained, captured at the boundary, undeletable by any agent. The suspect can't write the police report.
RATE — Across the network. The KYDE Trust Score™: agent behavior rated across every provider in the same currency. Vendors grade their own homework. We grade behavior.
Learn more