Turbot GuardianPreview

Guardrails for
Vibe Coding

Your developers and shadow IT are using AI coding agents every day. Guardian gives your security team visibility and control over every credential those agents hold, plus the resources and environments they can reach, across every machine in your fleet.

You locked down your CI/CD pipeline. You hardened your cloud IAM. But your developers' AI agents have the keys to everything, and nobody's watching.

Talk to us β†’
Guardian Fleet Overview Dashboard
40+
Credential formats discovered
42
Session threat paths detected
<1s
Policy evaluation time
6
Enforcement modes
Guardian Dashboard showing live sessions and recent blocks

AI agents don't ask permission.

AI coding agents run with full developer permissions. They can read AWS keys, database passwords, and API tokens. A single unmonitored session can exfiltrate secrets, make unauthorized API calls, or expose production credentials. And there's no audit trail.

βœ“See every credential on every developer machine
βœ“Know which AI agents are installed and active
βœ“Watch what agents do with credentials in real time
βœ“Block credential exfiltration before it happens

Works with the agents your team already uses

Claude CodeClaude Code
CursorCursor
GitHub CopilotGitHub Copilot
Aider
Gemini CodeGemini Code
CodexCodex

Full visibility and control over your AI agents

What agents are running?

Guardian auto-discovers every AI coding agent across your fleet, including Claude Code, Cursor, Aider, Gemini, and Codex. It maps the devices they run on and the MCP servers and plugins they connect to.

What can they reach?

See the blast radius of every agent. Guardian inventories the credentials each one can use, then maps them to the projects, resources, and environments those credentials unlock.

What are they doing?

Watch agents work in real time. Guardian records every session, the resources they touch, and how each credential gets used, so nothing happens without a trail.

How do you control it?

Set the rules and enforce them. Guardian runs as native hooks in each agent's config, with no proxy and no code changes. Block risky actions, warn on others, and allow the rest.

One dashboard for it all

Your security team sees the whole picture in one place: credential posture, device and agent inventory, live activity, and policy drift across the fleet.

What is AI costing you?

Break down agent spend by project, device, and model. When your team juggles several projects at once, you can finally see where the AI budget actually goes.

Inside the agent,
across the fleet.

Guardian works inside the AI agent workflow through native hooks while giving you fleet-wide visibility. It's not a network proxy, a sandbox, or a secrets scanner. It's credential governance built specifically for AI agents.

βœ“Native hooks. No code changes, no proxy
βœ“Six enforcement modes: Block, Redact, Warn, Audit, Log, Allow
βœ“Background daemon with offline resilience
βœ“SSO/OIDC/SAML integration
Guardian fleet architecture: a Guardian server with fleet console, policy, and audit log, connected to managed devices over device-initiated outbound HTTPS.Guardian on a single device: AI agents fire hooks that write records to a spool, the guardian-daemon ingests them and runs credential detection, policy engine, and session watching, then syncs to the server.
Live audit trail
policy Β· decision Β· provenance
14:32:07
Claude Code β€” Pasted Anthropic API key into promptBlock
β–Έ credential-in-prompt Β· sk-ant-β€’β€’β€’
14:32:05
Cursor β€” Read browser-stored GitHub tokenRedact
β–Έ redact-on-read Β· ghp_β€’β€’β€’β€’a4x9
14:32:03
Aider β€” Read ~/.aws/credentialsWarn
β–Έ credential-file-access Β· AKIAβ€’β€’β€’β€’MPLE
14:32:01
Claude Code β€” Committed .env to gitBlock
β–Έ secret-detected Β· DATABASE_URL
14:31:58
GitHub Copilot β€” MCP tool: github.repo.deleteBlock
β–Έ attack-path: prompt_injection Β· @org/payments

Built for teams that
answer to auditors.

Every time Guardian blocks, warns, or allows an action, it records exactly which policy rules were in effect. Your audit trail is complete and provable. Auditors love that.

βœ“SOC 2 Type II compliant
βœ“Complete audit trail for every agent action
βœ“Policy versioning with per-decision provenance
βœ“Alert rules with PagerDuty, Slack, and SIEM integration
βœ“SSO/OIDC/SAML for enterprise identity
βœ“Three-layer credential redaction: write-time, read-time, and server-ingress

Get early access to Guardian

Guardian is in early preview. We're working with security teams who want to get ahead of AI agent risk. If that's you, let's talk.