Independent boundary · Guided redirect · Routed action gates

Independent control for AI agent actions.

Use agents through routed tools. Put risky actions behind one policy boundary before they send, deploy, push, publish, install, or spend.

Pre-runtime detection
Redirects, not retry loops
Bounded evidence
Control flow

Detect, redirect, gate, record

One routed path for risky agent actions, from detection to bounded evidence.

AgentVeil · controlled actionwalkthroughConfigured project route
Illustrative walkthrough, not live telemetryConfigured connectors and explicitly routed MCP calls only
Action surfaces

Where agents cross the line from thinking to acting

Choose an action surface to see where the routed control path applies.

Action packetrouted
Boundary truth

The route is the control point

AgentVeil controls configured routes, not the entire host.

Routed through AgentVeilcontrolled · recordedNot routed · can bypassreaches your systems uncontrolledrecorded · evidenceAgentVeilMCP Proxy tool callsConfigured connector routesRaw shell commandsVisible credentialsUnmanaged SDK or API callsYoursystemsBoth reach your systems — only routed actions are controlled and recorded.
Configured route

Routed actions stay visible

MCP Proxy and configured connector actions can be classified, redirected, approved, blocked and recorded.

  • MCP Proxy tool calls
  • Configured connector routes
  • Local approval and evidence
Privacy and evidence

Keep sensitive data local. Share only bounded proof.

Raw workflow data stays local; shared review uses bounded action facts and hashes.

On your machinestays local · never sent
Prompts and private logskept local
Source code and MCP argumentskept local
Secrets and credentialsnot sent
only a bounded record is shared
0x…
evidence-record.jsonbounded
risk_classhigh
decisionredirect
target_hashsha256:8f2a…c91e
payload_hashsha256:34bd…7aa0
this is the entire shared record
Raw workflow data stays local — only bounded hashes and decision facts are shared.
Start here

Connectors

Pick a runtime. The terminal shows the current setup path.

bash

Source: github.com/agentveil-protocol/agentveil-sdk · PyPI: agentveil-mcp-proxy

Delegate actions without handing over control.

Start locally. Add hosted records and team-scoped controls when agents move closer to code, credentials, and sensitive systems.

CORE

Core

$0 forever

Open-source control layer for AI-agent workflows.

  • Open-source AgentVeil CLI
  • Local approval loop
  • Basic redirect guidance
  • Local evidence and status
  • Public fallback path
  • No license required
Install Core
TEAM

Team

$399 / month

For teams controlling agent actions across shared development workflows.

  • Shared workspace and team policy controls
  • Team approval routing
  • Shared action history and decision records
  • 90-day shared record retention
  • 300,000 routed action decisions / month
  • Development workflow controls
Request Team Access
ENTERPRISE

Enterprise

Contact us

For organizations with custom security, deployment, and compliance requirements.

  • Custom controlled-action volume
  • SSO / SCIM options
  • Custom retention and legal hold
  • Security review
  • Private deployment options
  • Custom support and SLA terms
Talk to us

Monthly allowances are based on routed action checks: agent actions evaluated by AgentVeil before execution. Routine checks can allow actions automatically; higher-risk checks can require approval, block, or redirect. Local-only Core usage is free.

FAQ

What does AgentVeil do?

AgentVeil puts a policy boundary in front of configured AI-agent actions. It can allow routine work, ask for approval, block risky actions, redirect to the approved workflow, and keep bounded evidence of the decision.

Does AgentVeil control actions outside routed paths?

No. AgentVeil enforces only on paths explicitly routed through supported connectors, MCP Proxy, SDK gates, wrappers, or custom controlled paths. If an agent still has raw shell, visible credentials, or direct API access, those paths must be removed, sandboxed, or treated as bypassable.

Does AgentVeil guarantee complete agent safety?

No. AgentVeil is not a model-safety layer, EDR, or host-wide sandbox. It reduces risk by moving sensitive actions onto controlled paths and showing what remains bypassable.

What makes AgentVeil different from a plain allow/deny gate?

Block is only one outcome. AgentVeil is designed to return the safer next move: create a draft, open a PR, inspect package risk, request scoped approval, use staging, or stop.

Who is AgentVeil for?

AgentVeil is for developers and teams giving agents real authority: code changes, repo operations, deploys, package installs, external sends, credentials, databases, or sensitive APIs.

How do I install AgentVeil?

Use a connector for Cursor, Claude Code, Codex, or Gemini CLI when that is your agent surface. Use standalone MCP Proxy for MCP tools. Use SDK/API routes for workflows that need a controlled action path beyond MCP.

What counts toward monthly allowances?

Hosted plans count routed action checks: agent action requests evaluated by AgentVeil before execution. Routine allows count because AgentVeil evaluated them; local-only Core usage is free.

Can I use AgentVeil alongside observability tools like Datadog or Sentry?

Yes. Observability helps teams inspect systems after telemetry exists. AgentVeil sits before execution on routed action paths, then records bounded decision evidence your existing tools can reference.

Does AgentVeil help with EU AI Act readiness?

AgentVeil can help produce technical evidence for configured routed actions and policy decisions. It is not legal advice, certification, or a complete compliance program.

Control what your AI agents can actually do.