Audience
Developers and security teams building AI agents that call tools
About Vulnify
Vulnify is a runtime authorization service for developers and security teams building AI agents that use tools or APIs. Before a tool runs, the agent sends action metadata—including the agent, action, resource, destination, and record count—and receives an ALLOW, REVIEW, or BLOCK decision with a 0–100 risk score and reasons. Teams can define and test YAML policies through a command-line interface, and add checks using Node.js or Python SDKs, a REST API, or adapters for agent frameworks. Monitor mode records decisions without blocking actions. Fail-closed behavior blocks actions if Vulnify is unavailable unless fail-open is configured. A hash-chained audit log records decisions, and paid plans include human review workflows. Common use cases include governing data exports, external messages, payments, and other agent-initiated actions. Vulnify evaluates action metadata rather than the contents of affected records.