Every tool call signed. Every action auditable. Every mandate revocable. Zero LLM calls. Deterministic.
Every decision is deterministic. No LLM calls. No probabilistic filtering.
Reject path traversal, oversized payloads, null bytes
Check if mandate has been revoked before TTL
ed25519 verification with domain separation
Reject expired mandates (max 1 year)
Allow/deny list, filesystem and network globs
Region, environment, operating hours
Pattern-matched human approval triggers
Per-minute call caps from mandate
Drop-in governance for your existing agent stack. 3 lines of code.
MIT License. Self-hosted. No vendor lock-in. Works with any LLM, any framework.