AI agent security · safety · accountability
AI agents are getting real authority.
Make sure they can't cross the line.
Companies are handing AI agents the power to move money, send messages, and change systems — on their own. When an agent makes a mistake or gets hijacked, the damage is real and there's no undo. Scopebond puts enforceable guardrails around every agent: it blocks out-of-policy actions before they happen and proves exactly what each agent did.
Apache-2.0 · works with any agent over HTTP or MCP · self-host free, no account required
Autonomy without accountability is a liability
An AI agent with access to your payments, inbox, or infrastructure is a powerful employee that never sleeps — and can act faster than any human can catch. The same autonomy that makes agents useful is what makes them dangerous when something goes wrong.
- Mistakes at machine speed. A bad instruction or a reasoning error can trigger a costly action instantly — a wrong payment, a mass email, a deleted resource — before anyone notices.
- Prompt injection & hijacking. Attackers hide instructions in the data an agent reads. A compromised agent will happily use its real permissions against you.
- No proof, no recourse. When you can't show exactly what an agent did — or hold anyone to account when a vendor's agent misbehaves — trust breaks down and adoption stalls.
Scopebond is the control layer that makes agent autonomy safe to grant: prevent what you can, prove everything, recover what you can't prevent.
Prevent
A gateway sits between your agent and everything it can touch. Out-of-policy actions are denied in real time — fail closed, with a kill switch. The bad action never happens.
Prove
Every action — allowed or blocked — is countersigned into a tamper-evident receipt. You get an audit trail that writes itself, verifiable by anyone.
Recover
Back a vendor's agent with a refundable deposit against the same policy. On a provable violation, you recover from the deposit. Registry — roadmap
What Scopebond protects
One policy language, enforced everywhere your agents act. Click any area to watch it stopped live in the demo:
Payments & finance
Cap spend per transaction and per day, allowlist payees, and block transfers to unknown accounts — automatically.
Try it live →Security incident response
Keep an incident-response agent from containing a production host it isn't scoped to.
Try it live →Legal & litigation
Prove exactly what an agent did — or blocked — with tamper-evident, court-ready receipts.
Try it live →DevOps & infrastructure
Bound what an agent can deploy, delete, or access, so a bad step can't take down production.
Try it live →Customer support
Stop refunds, discounts, or account changes beyond policy — even from a prompt-injected agent.
Try it live →Data & privacy
Keep an agent from exfiltrating PII to an unapproved endpoint, and contain injection blast radius.
Try it live →Watch it stop a bad transaction — live
An AI agent tries to wire $18,000 past a $10,000 limit. See it get blocked in real time, with a signed receipt as proof — no signup.
Up and running in minutes
Scopebond sits in front of the agents you already run — no rebuild, no platform migration.
npx scopebond-gateway ./policy.json.Pricing
Start free and self-hosted. Move to managed hosting when you want it off your plate.
Open Source
$0/ self-hosted
Run the gateway yourself. Apache-2.0, forever.
- Policy-enforcement gateway (HTTP + MCP)
- Countersigned receipts + kill switch
scopebond-verify+ conformance vectors- Community support
Hosted — Scopebond Cloud
Free/ in beta
A managed control plane, so you don't run infrastructure. Free while in active development.
- Everything in Open Source
- Managed receipt retention & daily Merkle anchoring
- Hosted verification — check any receipt by its key id
- Dashboard: usage, anchors, receipts & attester keys
- Email support
No card required. Paid plans arrive as the hosted product matures.
Enterprise
Custom/ contact
For teams with hosting, security, and recourse needs.
- Everything in Hosted
- The collateral registry & recovery workflow
- Custom SSO, residency, and limits
- Priority support & onboarding
Put guardrails on your agents today
The gateway is open source and runs in minutes — no account required.