AI agent security · safety · accountability

AI agents are getting real authority.
Make sure they can't cross the line.

Companies are handing AI agents the power to move money, send messages, and change systems — on their own. When an agent makes a mistake or gets hijacked, the damage is real and there's no undo. Scopebond puts enforceable guardrails around every agent: it blocks out-of-policy actions before they happen and proves exactly what each agent did.

Apache-2.0 · works with any agent over HTTP or MCP · self-host free, no account required

Autonomy without accountability is a liability

An AI agent with access to your payments, inbox, or infrastructure is a powerful employee that never sleeps — and can act faster than any human can catch. The same autonomy that makes agents useful is what makes them dangerous when something goes wrong.

Scopebond is the control layer that makes agent autonomy safe to grant: prevent what you can, prove everything, recover what you can't prevent.

Prevent

A gateway sits between your agent and everything it can touch. Out-of-policy actions are denied in real time — fail closed, with a kill switch. The bad action never happens.

Prove

Every action — allowed or blocked — is countersigned into a tamper-evident receipt. You get an audit trail that writes itself, verifiable by anyone.

Recover

Back a vendor's agent with a refundable deposit against the same policy. On a provable violation, you recover from the deposit. Registry — roadmap

What Scopebond protects

One policy language, enforced everywhere your agents act. Click any area to watch it stopped live in the demo:

See all 7 areas in the live demo →

Watch it stop a bad transaction — live

An AI agent tries to wire $18,000 past a $10,000 limit. See it get blocked in real time, with a signed receipt as proof — no signup.

Up and running in minutes

Scopebond sits in front of the agents you already run — no rebuild, no platform migration.

1
Write your rules. In plain terms, set what each agent may spend, touch, and do — limits, allowlists, approvals, and which tools it can use. Every rule is either enforced (blocked on the spot) or monitored (allowed, but flagged).
2
Put Scopebond in front of your agent. It sits between the agent and your systems and works with any agent — over HTTP or MCP. One command to start: npx scopebond-gateway ./policy.json.
3
Get prevention and proof, automatically. Out-of-policy actions are stopped in real time, and every action becomes a signed, tamper-evident receipt — an audit trail that writes itself. Deposit-backed recovery for third-party agents is on the roadmap.

Pricing

Start free and self-hosted. Move to managed hosting when you want it off your plate.

Open Source

$0/ self-hosted

Run the gateway yourself. Apache-2.0, forever.

  • Policy-enforcement gateway (HTTP + MCP)
  • Countersigned receipts + kill switch
  • scopebond-verify + conformance vectors
  • Community support
Get started

Enterprise

Custom/ contact

For teams with hosting, security, and recourse needs.

  • Everything in Hosted
  • The collateral registry & recovery workflow
  • Custom SSO, residency, and limits
  • Priority support & onboarding
Contact us

Put guardrails on your agents today

The gateway is open source and runs in minutes — no account required.