Secure every AI agent action.
Every developer keeps running locally, on every plan. Paid plans add coordination — shared rules, human approval workflows, and organization-wide visibility — not execution.
Every plan — including Free — runs the identical security gate. Paid plans buy coordination. Never safety.
Free protects yourself. Starter protects your team. Growth governs your organization.
Protect yourself locally — every unsafe command still gets blocked before it runs.
- ✓Blocks destructive commands before they run
- ✓Deterministic rules decide pass, block, or hold — no AI guesswork
- ✓Understands what a command actually does, not just its text
- ✓Watches first — nothing blocks until you turn it on
- ✓Remembers every action, no time limit
- ✓See every action an agent took, in order
- ✓Community support
Protect your team — coordinate approvals and build safer workflows from your own team's experience.
- ✓Everything in Free
- ✓Organization Memory — every approval is stored with its rationale and surfaced when a similar action occurs, so a human can promote it into versioned policy
- ✓One shared org: pooled seats, pooled usage, one bill for the whole team
- ✓Cloud account dashboard for usage, seats, and billing
- ✓Risky actions wait for a human's one-click approval in Slack
- ✓Unanswered approvals escalate — secondary on-call at 5 minutes, PagerDuty page at 10
- ✓Ephemeral, task-scoped AWS/GCP/Azure credentials — no long-lived secrets in agent config
- ✓Advisory AI code-review comments on pull requests before they merge
- ✓CI gate flags risky pull requests before merge via GitHub Actions — one repository included
- ✓Export your audit trail as CSV
- ✓Daily & weekly summaries of what your agents tried to do
- ✓5 included seats
- ✓Community + email support
Sign in required · No card for trial · Cancel anytime
Govern AI agent usage across the organization — one set of rules, proof for every stakeholder who asks.
- ✓Everything in Starter
- ✓20 included seats
- ✓Control who can approve what, by role — Slack approvals are signature-verified and mapped to the clicker's identity
- ✓Quorum approvals: require N distinct sign-offs for terraform-destroy-class actions
- ✓CI gate flags risky pull requests before merge via GitHub Actions — unlimited repositories included
- ✓Fleet-wide visibility: see every teammate's blocked actions and gate decisions in one place
- ✓SOC 2 / ISO 27001 control mapping in the compliance report
- ✓Stream blocked actions and the agent ledger to your SIEM (Splunk HEC or webhook)
- ✓Weekly digest of gate decisions and approver analytics, org-wide
- ✓Support: same-day response + private Slack channel
Sign in required · No card for trial · Cancel anytime
Included limits (seats, protected tool calls, CI repositories) are metered, never enforced against safety: exceeding a limit adds an upgrade notice (and, if usage-billing is enabled on your account, an overage line), while every call and every build keeps getting the identical evaluation, blocking, and audit trail. The security decision is plan-agnostic by architectural invariant — paid plans change delivery channels, collaboration, and visibility, never the verdict.
Common questions
Everything you need to know before starting a trial.