GrubX checks every agent action, whether it's an MCP tool call, an API request, or a SaaS operation, against your policy before it executes. Allow it, block it, or send it for human approval. Every decision is recorded as evidence.
No SDK · No agent code changes · Change one URL
Agents issue refunds, change records, open pull requests, send email, and call internal APIs. The tools you already have each miss the moment that matters.
They route prompts and tokens. They don't decide whether a $10K refund or a DELETE should go through.
Traces tell you after the fact. By then the customer was deleted or the data left the building.
A key that can refund $10 can refund $10,000. Nothing checks the parameters, the context, or the session.
Start by watching, not blocking. Turn protection on once you've seen what your agents actually do, and keep the evidence for every decision.
Every tool call and API request is classified: destructive operations, large transactions, secrets or PII leaving in outbound calls, unknown APIs. Nothing is blocked yet.
Allow, block, or require human approval, with limits on amounts, targets, and spend. Kill any agent instantly.
Every decision records the agent, the user it acted for, the policy version, and the reason, in a tamper-evident audit trail you can export for review.
Get an endpoint and a token. Run an existing agent through it. Within minutes you get an Audit & Evidence Report: every action it took, the ones you'd want stopped, and a record your CISO can sign off on.
A free, read-only Agent Audit. Point your agents at a GrubX URL in Audit Mode. Nothing is blocked and nothing changes for your users. You get a risk report showing what would have gone through unchecked.
Every API and MCP tool your agents actually call, including the ones nobody approved or documented.
Credentials, tokens, and personal data leaving in tool parameters, flagged and redacted before anything is stored.
DELETEs, DROPs, and refunds over $1,000 that went through with nothing checking them.
Read-only and zero-risk. No SDK, no code changes, and it's live in about 5 minutes.
An exportable evidence report of shadow APIs, sensitive data egress, and destructive actions, ready for your security team.
Hit "Activate protection" to allow, block, or require approval with the same URL. Still no code changes.
Three decisions on every action. Approvals are async and bound to the exact action, so they can't be replayed.
Rules on amounts, targets, and scopes, not just endpoints. Written as code, versioned, and testable.
Per-transaction and cumulative caps per agent, session, or day. Stop runaway agents before the bill arrives.
Catch credentials and personal data in outbound calls. Redacted before anything is stored.
An agent that just read customer PII can't email it outside. Context carries across the session.
Stop one agent or all of them instantly, whatever the policy mode.
Agents never hold upstream keys. GrubX injects them at runtime, so agents can't go around the control.
Tamper-evident, hash-chained decision records. Export an evidence pack for your security review.
That's the bar we build to: fast, fail-safe, and careful with your data.
We've spent more than a decade as SREs and platform engineers running production Kubernetes and cloud infrastructure. We watched the cloud grow up, and one rule never changed: nothing touches production without admission control, scoped permissions, approvals for risky changes, and an audit trail.
AI agents are now among the fastest-growing sources of change in production systems. They issue refunds, edit records, call internal APIs, and act for real users, usually with nothing more than an API key and a prompt. So security says no, and the agents stay stuck in pilot.
GrubX is admission control for agent actions. It's the layer we wanted every time someone asked whether an automated system could be trusted with write access: fast enough to sit in the request path, safe when it fails, and clear about what it did and why.
Run the 5-minute test and protect your first agents.
For teams putting agents with write access into production.
No. There's no SDK. You change the MCP server URL or API base URL your agent already uses. It works with any agent framework.
They work at different layers and fit together. OpenShell sandboxes the agent: which files, processes, network destinations, MCP tools, and credentials it can use. GrubX governs the actions themselves. It reads the arguments of each tool call or API request, including amounts, targets, and data in the parameters, and decides whether this specific action, for this user and session, should run, needs human approval, or should be blocked, with a tamper-evident record for your security review. GrubX works wherever your agents already run, including inside an OpenShell sandbox. OpenShell decides where your agent can connect; GrubX decides what it's allowed to do there.
Policy is evaluated in-process inside the gateway, with no extra network call per decision. Our target is under 2 ms at p99 for the decision and under 10 ms end to end.
Gateways keep enforcing the last known policy if the control plane is unreachable. You choose the failure mode per action: fail-closed for payments, writes, and deletes; fail-open only for read-only actions if you allow it.
Secrets are never stored or logged. Parameters are redacted or hashed field by field before anything is written, and raw PII is not retained. With brokered credentials, keys stay in your secrets manager and are referenced, not copied.
Only if it holds its own keys. With credential brokering, agents authenticate to GrubX and never see the upstream credentials, so there is no way around the control.
MCP tools and common SaaS APIs are recognized out of the box. For internal services, upload an OpenAPI spec and GrubX maps each operation to a named action with typed parameters.
Tell us what your agents do and what they should never be allowed to do. We'll set up your endpoint and walk through the results with you.
GrubX is designed to support the record-keeping and human-oversight expectations of the EU AI Act and of US frameworks such as the NIST AI Risk Management Framework, as well as emerging US state AI laws. It provides runtime controls, human approval, and tamper-evident decision records. Using GrubX does not by itself make a system compliant, and nothing on this site is legal advice.