Block the leak or the injection before it ever runs
Guard evaluates every tool call on-device before execution - catching secrets and prompt injection pre-flight, and failing closed whenever a call is ambiguous.
The chain that removes it
Agents can run shell commands, hit the network, or paste a secret. Most of the time it is fine; occasionally it is not, and by then it has happened.
Screen every call
The secret firewall and OWASP-scored injection checks run on-device before any payload can leave.
Simulate before enforce
See exactly what would have been blocked on real traffic before a single rule ever goes live.
Enforce fail-closed
Ambiguous or high-risk calls are blocked by default and routed to human approval, not allowed by default.
How it stays out of the way
No fixed injection rate
Scores are OWASP-aligned and measured per environment; we never publish a fixed marketing detection number.
Invisible until needed
Safe, expected calls pass straight through, so Guard never becomes the thing quietly slowing the team down.
Nothing runs unchecked
Risky shell and network actions execute inside a sandbox instead of directly on your bare machine.
More in this view
Same spine, a neighbouring starting point.
Cut token spend
Surfil trims the context agents never needed, measures the cache premium you are paying, and names the writes that are never read back - then signs the measured saving.
See this path →Portable memory
Mind gives your agents local, encrypted memory with provenance on every fact - and it follows you across agents instead of living inside one tool's silo.
See this path →Prove compliance
Surfil turns agent activity into offline-verifiable evidence: signed attestations, control-mapped bundles, and a tamper-evident trail your auditors check themselves.
See this path →Turn on the first stage today
The install is reversible byte-for-byte, and the first signed receipt arrives after one normal week of traffic.