AI Agent Governance · Public beta · Available now for Claude Code · Swiss-engineered

Let AI agents do real work, without giving up control.

Decide·Enforce·Prove

Isonapse is the independent runtime governance layer between your AI agents and what they can touch: files, the shell, the web, and your tools. You set the rules. Isonapse enforces them before every action and creates a verifiable audit trail.

macOS and Linux · Claude Code required · runs locally · zero code changes

Watch the gate decide.

A replay of a governed session, exactly as the hook renders it. Every action resolves to a verdict before it runs, and every advancing decision writes a signed receipt you can verify offline. Read it top to bottom.

isonapse hook
ALLOW within your rules, runs ASK paused for a human BLOCK denied, and the agent can't route around it

Your rules, enforced on every action.

Three verbs run the whole system. Everything else is detail that lives in the docs.

01 · DECIDE

Policy decides

You set the rules: what an agent may do, what needs a human, what is never allowed. Your rules are the source of truth, not the model's mood.

02 · ENFORCE

The gate enforces

Every action passes a checkpoint that allows, asks, or blocks it before it runs. The agent can't route around it.

03 · PROVE

The witness proves

Every decision is written to a tamper-evident, signed ledger you can verify offline.

No vendor can govern the others.

It's tempting to assume governance comes for free with whichever model or tool you picked. It doesn't, and it structurally can't.

Claude Code Codex Hermes pi.dev Open-weights Your harness
ISONAPSE One policy · one gate · one audit chain
Files · shell · web · your tools

The neutral layer: any agent, any model, any harness, by design.

The market thesis

Governance has to be the layer you own.

Every agent harness and model vendor ships its own controls. But once you use multiple frameworks, open-weights models, or your own harness, those controls stop at the vendor boundary.

Governance has to be the neutral layer across all of them: owned by you, with one policy and one audit chain across every runtime.

We govern the agents you run. We never run them for you. We are not another agent or model. We are the control plane around them.

Where it stands today: the Claude Code hook ships now, and enforcement for the self-hosted path exists as real code. Multi-host adapters and a universal SDK are the next release.

Four problems it removes.

01

Permission fatigue isn't a guardrail.

Approving every prompt and trusting blindly are the same failure. Isonapse learns your normal, waves the routine through, and speaks up only for the genuinely odd.

02

Prompt injection can't talk its way past it.

A poisoned web page can turn your agent against you. The gate sits outside the agent, so a hijacked agent can't argue with it.

03

Your data stops leaking quietly.

On the supported paths, secrets and model-visible strings can be tokenised before they travel. Secret placeholders keep plaintext out of model-authored input.

04

"What did the agent do?" gets a provable answer.

Every advancing decision has a signed, tamper-evident record anyone can verify offline with the pinned public key.

Deterministic first

Zero LLMs in the decision path.

"AI safety" that is itself an AI is circular: a model you have to trust, policing a model you don't. In Isonapse the critical decisions are made by deterministic code. The system learns your normal so it can flag the abnormal, but that learned judgement is advice, never authority.

A learned hunch can turn a "yes" into an "ask." It can never turn a "no" into a "yes." That single rule is why a fooled model can't escalate its own privileges.

Your policy, not the model's mood.

One machine today. A fleet tomorrow.

Built for enterprise scale, and honest about what ships when.

The swarm

Shared intelligence, shareable logic

What one machine learns and one team writes can travel across the fleet: learned behaviour as a signal, policies as versioned logic. Signing never centralizes, so there is no central brain to compromise. Proof travels; secrets and memory stay home.

This is the furthest-out capability, and we say so plainly: witness federation arrives with the next release, and full fleet sync is the Enterprise tier. The design is settled; the wiring is the work.

Local by construction

Local decisions from day one

The critical control path is deterministic policy and bounded local state: no network round-trip, no SaaS in the loop. Everything degrades gracefully and keeps enforcing offline. A pulled network cable doesn't stop enforcement.

Cost control

Budget caps that hold

Hard per-session and rolling-hour limits that survive a restart. A runaway loop gets stopped, not invoiced.

One engine. Three levels of adoption.

The same enforcement engine everywhere. Choose how far it reaches: your machine, your server, your organisation.

Level 01 · On your machine

A local safety layer that learns what you do, catches what's off, and never calls home. One Homebrew line, zero code change.

Agent Hook for Claude Code For agents built on Claude Code. Public beta · available now
Agent Hook for Hermes Agent For agents built on Hermes Agent. August 2026
Agent Hook for pi.dev For agents built on pi.dev. August 2026
Level 02 · On your server

Community Edition

The full Isonapse control plane on your own hardware: one dashboard for every agent you run. Free under its own license. No SaaS account.

Public beta · early September 2026
Level 03 · Across your organisation

Enterprise Edition

Everything in Community, scaled to an organisation: SSO, organisational trust, fleet-wide budgets, compliance reporting.

Q4 2026
Same gate, same receipts, at every level. Full product details
EU flag Built for Europe

Swiss-engineered. On your hardware. A license, not a SaaS account. It never calls home.

No cloud service, no account, no telemetry. Enforcement keeps working with the network unplugged.

Built with European expectations in mind: the audit trails and human oversight regulation such as the EU AI Act calls for, and the security practice frameworks like OWASP and NIS2 describe. The compliance detail lives in the docs.

Isonapse Daemons.

A private technical community for people building the agentic future.

A daemon is a process that runs in the background without needing to be constantly instructed or supervised. It quietly does the work that keeps a system alive. That is the mindset behind Isonapse Daemons: a small, focused group of experienced engineers, builders and technical thinkers working with AI agents and agentic systems.

Not another large community. Not another place to collect badges. We are starting small.

About the program →

Tell us who you are, what you are working on, what drives you and how you believe you could contribute.

Apply to join

Built like security software.

The agent-tooling gold rush is full of overnight wrappers: a hook script, a regex, a dashboard. The thing that polices your agents has to hold up under adversarial review, not just a demo.

isonapse selftest · adversarial replay

A replay of the attack-shaped tests the suite runs in CI. Pick an attack; watch it fail.

"Trust us" is replaced by "verify the record yourself." That isn't a metaphor for the witness chain. It is the witness chain.

Install it before your agents' next task.

macOS and Linux · Claude Code required · runs locally · zero code changes

Agent Hook beta today · Community Edition September 2026 · Enterprise Q4 2026

Copied to clipboard