Prompts can be ignored.
Policies can't.

Policy Gateway governs the AI your organization already uses. It sees every prompt, completion, attachment, and MCP tool argument on its way out of the device, and reads what they mean rather than only where they are going. That is what lets it block or redact sensitive information going to the AI you trust, not just block the AI you do not.

Free Agent Guard trial
Click to install the latest version

The installer lets you choose Policy Gateway, Agent Enclave, or both.


THE PROBLEM

Blocking untrusted AI is not a policy.

Can you govern the AI you approved?

Your team is not reaching for shady tools. They are pasting contracts into ChatGPT and attaching spreadsheets to Claude, the tools you already approved. Allow-listing the destination does nothing about what gets sent to it.

Can your controls read what is being sent?

Network policy sees a destination and a volume. It cannot tell a routine API call from one carrying credentials in the request body, or a safe tool call from a destructive one, because it never reads what is inside.

Can you stop it before it leaves?

Spreadsheets, ticket trails, and API dumps help you write the incident report afterwards. None of them redact a customer list or block a prompt at the moment it leaves the machine.


TWO WAYS TO DEPLOY IT

Enforce your policies on hosted, SaaS, and shared LLMs.

Policy Gateway runs where it can see the request. On a laptop that means the device itself. For a team, a site, or a whole cluster reaching the same LLM or agent application, it means the shared path they all take. The policy and the audit log are the same either way.

For endpoint devices · macOS and Windows

On the device

Policy Gateway captures AI-bound connections and interactions on the device, enforcing your defined policy on the machine, so inspection happens locally and prompt content never passes through a third-party cloud.

  • Fleet View in Jozu Hub shows every device running Agent Guard, the policy versions applied to it, and whether it is currently connected.
  • Every policy decision writes to a tamper-evident, cryptographically chained audit log that syncs to Hub when the device is online and keeps recording when it is not.
  • Missing data or an evaluation error denies the action rather than allowing it, so a policy that cannot be evaluated is never quietly skipped.
For teams · Shared network

On a shared network

When many people reach the same LLM application, Policy Gateway can sit on that shared path instead of on each device, so one policy governs every request to the application and every decision lands in the same audit log.

  • The same policy definitions you already run on devices, so there is no second policy system to author or maintain.
  • Every request from every person lands in one chained audit log, so a shared application has a single record instead of one per device.
  • Designed to operate at scale, each policy decision is evaluated in micro-seconds, so policy enforcement does not impact time to response.
Policy Gateway governs the AI traffic leaving a device or a network, but it does not contain an agent that is already running on the machine. That is the job Agent Enclave does.

WHAT YOUR POLICY DOES

A policy check on the path, before anything leaves.

Every request headed for an AI service goes through the policy engine first. It reads the prompt text, the attached documents, the completions coming back, and the MCP tool arguments, then applies your rule to what is actually being said rather than to where it is going. You pick what happens next for each rule.

Enforce

Block the action before the agent runs it.

Elicit

Pause and ask a human before continuing.

Audit

Allow the action and log the decision.

  • Policies are short YAML files with CEL assertions, distributed as signed OCI artifacts and verified on the machine that enforces them.
  • Every policy decision is written to a tamper-evident, cryptographically chained audit log that syncs to Jozu Hub when the device is online and keeps recording when it is not.
  • Missing data or an evaluation error denies the action rather than allowing it, so a policy that cannot be evaluated is never quietly skipped.
Terminal showing Agent Guard blocking a push to main because a pull request is required, with the commit hash recorded
A denied action comes back with its reason and an audit entry, not a silent failure.

START

Try it on your machine.

One command installs Agent Guard on your machine. Start from a pre-built policy and you will see your first blocked action in minutes.

Click to install the latest version

The installer lets you choose Policy Gateway, Agent Enclave, or both.


NEXT STEP

Need to contain the agent itself?

Policy Gateway governs the AI traffic leaving a device or a network, but it does not contain an agent that is already running on the machine. That is the job Agent Enclave does, with a dedicated microVM per agent on a laptop or on a node in your Kubernetes cluster.

Put a policy check on the path

Policy Gateway is one of the four places Agent Guard enforces your policy. Same engine, same policy language, same chained audit log as everywhere else it runs.