GRUBX
// runtime action firewall for AI agents

Let your AI agents act. Decide what they're allowed to do.

GrubX checks every agent action, whether it's an MCP tool call, an API request, or a SaaS operation, against your policy before it executes. Allow it, block it, or send it for human approval. Every decision is recorded as evidence.

No SDK · No agent code changes · Change one URL

support-agent · decisions example
ALLOW
stripe.customer.retrieve
read-only · within scope
ALLOW
stripe.refund.create amount=$40
policy refund-limits v7 · under $100
APPROVAL
stripe.refund.create amount=$400
above $100 · routed to security reviewer
BLOCK
mcp: crm.delete_customer
destructiveHint=true · destructive-actions v3
BLOCK
mcp: email.send to=external
session read PII · pii-egress v2
audit chain ✓ verified p99 decision < 2 ms (target)
// built for agents that act through
// the gap

Agents now take real actions. Your controls weren't built for them.

Agents issue refunds, change records, open pull requests, send email, and call internal APIs. The tools you already have each miss the moment that matters.

AI gateways

Control model traffic

They route prompts and tokens. They don't decide whether a $10K refund or a DELETE should go through.

Observability

Record what already happened

Traces tell you after the fact. By then the customer was deleted or the data left the building.

API keys & IAM

All-or-nothing access

A key that can refund $10 can refund $10,000. Nothing checks the parameters, the context, or the session.

GrubX sits in the path of every action and makes the decision at runtime, using the parameters, the agent, the user it acts for, and what happened earlier in the session.
// how it works

Observe. Enforce. Prove.

Start by watching, not blocking. Turn protection on once you've seen what your agents actually do, and keep the evidence for every decision.

AUDIT MODE

See every action and its risk

Every tool call and API request is classified: destructive operations, large transactions, secrets or PII leaving in outbound calls, unknown APIs. Nothing is blocked yet.

ACTIVE MODE

Enforce in milliseconds

Allow, block, or require human approval, with limits on amounts, targets, and spend. Kill any agent instantly.

EVIDENCE

Show security exactly what happened

Every decision records the agent, the user it acted for, the policy version, and the reason, in a tamper-evident audit trail you can export for review.

// the 5-minute agent security test

See what your agents would have done before it costs you.

Get an endpoint and a token. Run an existing agent through it. Within minutes you get an Audit & Evidence Report: every action it took, the ones you'd want stopped, and a record your CISO can sign off on.

# 1. your endpoint GRUBX_ENDPOINT=https://acme.grubx.io GRUBX_TOKEN=gx_•••••••••••• # 2. swap one URL (MCP or API) MCP_SERVER_URL=$GRUBX_ENDPOINT/mcp/crm STRIPE_API_BASE=$GRUBX_ENDPOINT/u/stripe # 3. run your agent as usual
  • Works immediately for MCP tools and common SaaS APIs
  • Internal APIs: upload an OpenAPI spec
  • Audit mode by default, so nothing is blocked until you choose
  • Export the report for your security review or CISO sign-off
audit & evidence report example
agent support-agent · 142 actions mode AUDIT · nothing blocked
131
would allow
7
would block
4
need approval
TOP RISKS
Destructive call (DELETE / DROP)3
Secret / PII in outbound payload2
Refund > $1,000, unchecked1
Shadow / unmapped API call1
✓ hash-chained evidence · export ready for CISO / security sign-off
Activate protection
// free agent risk assessment

Discover what your AI agents are doing in production before your CISO does.

A free, read-only Agent Audit. Point your agents at a GrubX URL in Audit Mode. Nothing is blocked and nothing changes for your users. You get a risk report showing what would have gone through unchecked.

Shadow API calls

Every API and MCP tool your agents actually call, including the ones nobody approved or documented.

Secrets & PII in outbound payloads

Credentials, tokens, and personal data leaving in tool parameters, flagged and redacted before anything is stored.

Destructive calls that would have executed

DELETEs, DROPs, and refunds over $1,000 that went through with nothing checking them.

  1. AUDIT MODE

    Drop in one URL

    Read-only and zero-risk. No SDK, no code changes, and it's live in about 5 minutes.

  2. RISK REPORT

    Get your Agent Audit Report

    An exportable evidence report of shadow APIs, sensitive data egress, and destructive actions, ready for your security team.

  3. ACTIVE PROTECTION

    Flip to enforcement when you're ready

    Hit "Activate protection" to allow, block, or require approval with the same URL. Still no code changes.

Get Your Free Agent Audit Report Free · read-only · nothing blocked
// capabilities

Authorization for actions, not just access

Allow, block, or approve

Three decisions on every action. Approvals are async and bound to the exact action, so they can't be replayed.

Parameter-aware policy

Rules on amounts, targets, and scopes, not just endpoints. Written as code, versioned, and testable.

Limits & agent budgets

Per-transaction and cumulative caps per agent, session, or day. Stop runaway agents before the bill arrives.

Secret & PII detection

Catch credentials and personal data in outbound calls. Redacted before anything is stored.

Session-aware rules

An agent that just read customer PII can't email it outside. Context carries across the session.

Kill switch

Stop one agent or all of them instantly, whatever the policy mode.

Credential brokering

Agents never hold upstream keys. GrubX injects them at runtime, so agents can't go around the control.

Evidence, exportable

Tamper-evident, hash-chained decision records. Export an evidence pack for your security review.

// security by design

A control in your request path has to be safer than what it protects

That's the bar we build to: fast, fail-safe, and careful with your data.

// why we're building this

Built by engineers who lived this problem

We've spent more than a decade as SREs and platform engineers running production Kubernetes and cloud infrastructure. We watched the cloud grow up, and one rule never changed: nothing touches production without admission control, scoped permissions, approvals for risky changes, and an audit trail.

AI agents are now among the fastest-growing sources of change in production systems. They issue refunds, edit records, call internal APIs, and act for real users, usually with nothing more than an API key and a prompt. So security says no, and the agents stay stuck in pilot.

GrubX is admission control for agent actions. It's the layer we wanted every time someone asked whether an automated system could be trusted with write access: fast enough to sit in the request path, safe when it fails, and clear about what it did and why.

// pricing

Start free. Scale when you're ready.

Free
$0

Run the 5-minute test and protect your first agents.

  • Up to 3 agents
  • 50,000 actions per month
  • Audit and Active modes
  • Starter policies and kill switch
  • 7-day decision history
Get started
// questions

What teams ask first

Do we have to change our agent code?

No. There's no SDK. You change the MCP server URL or API base URL your agent already uses. It works with any agent framework.

How is GrubX different from NVIDIA OpenShell?

They work at different layers and fit together. OpenShell sandboxes the agent: which files, processes, network destinations, MCP tools, and credentials it can use. GrubX governs the actions themselves. It reads the arguments of each tool call or API request, including amounts, targets, and data in the parameters, and decides whether this specific action, for this user and session, should run, needs human approval, or should be blocked, with a tamper-evident record for your security review. GrubX works wherever your agents already run, including inside an OpenShell sandbox. OpenShell decides where your agent can connect; GrubX decides what it's allowed to do there.

How much latency does GrubX add?

Policy is evaluated in-process inside the gateway, with no extra network call per decision. Our target is under 2 ms at p99 for the decision and under 10 ms end to end.

What happens if GrubX is unavailable?

Gateways keep enforcing the last known policy if the control plane is unreachable. You choose the failure mode per action: fail-closed for payments, writes, and deletes; fail-open only for read-only actions if you allow it.

Do you see or store our secrets and data?

Secrets are never stored or logged. Parameters are redacted or hashed field by field before anything is written, and raw PII is not retained. With brokered credentials, keys stay in your secrets manager and are referenced, not copied.

Can an agent just bypass GrubX?

Only if it holds its own keys. With credential brokering, agents authenticate to GrubX and never see the upstream credentials, so there is no way around the control.

What about our internal APIs?

MCP tools and common SaaS APIs are recognized out of the box. For internal services, upload an OpenAPI spec and GrubX maps each operation to a named action with typed parameters.

// get started

Run the 5-minute test

Tell us what your agents do and what they should never be allowed to do. We'll set up your endpoint and walk through the results with you.

hello@grubx.io