Default-deny execution gate for AI agents, APIs, and distributed systems. Policies, drift detection, hard invariants, post-quantum signed permits.Written in Rust. Says no unless policy says yes.
-
Updated
Jul 13, 2026 - Rust
Default-deny execution gate for AI agents, APIs, and distributed systems. Policies, drift detection, hard invariants, post-quantum signed permits.Written in Rust. Says no unless policy says yes.
AXIOM Mesh 0.12.0-dev.3: local-first, fail-closed coordination substrate for human and machine principals, with policy-bound execution, cryptographic evidence, constrained-machine discovery and receipts, and governed runtime boundaries. No live deployment or production promotion claimed.
The firewall for AI agents. Default-deny action broker with tap-to-approve on Telegram/WhatsApp and a tamper-evident audit log - for OpenClaw, Hermes, and friends.
Security-first programming language for building high-assurance services, secure communications, privacy-aware networking tools, policy-enforced runtimes, secret-safe data pipelines, and auditable least-authority systems.
The official "kavach" skill repository
Destination-aware, default-deny egress control for AI coding agents, at the tool-dispatch layer across Claude Code and Codex from one shared policy.
Classify every column or fail the build — a runtime registry cannot see the module that forgot to register.
Default-deny local execution and model-runner boundary for broker workflows, with bounded JSON results, resource controls, model verification and JSONL streaming.
Open default-deny policy and protocol foundation for securing AI-agent capabilities.
Default-deny outbound filter
Security-first AI artifact registry — digest-based storage, policy-gated promotion, signed provenance, and reproducible trust metadata for local models, adapters, and tokenizers
The SQL firewall for AI agents: a default-deny sidecar / MCP enforcement point that governs what an AI agent runs against your database. Open core, AGPL-3.0.
Governance controls for edge AI that either fire, or do not. A signed model card is checked before the model loads, every actuation is refused unless a rule allows it, the stop channel starts engaged and needs a named operator, and the journal names the entry where it was altered.
Default-deny policy gateway for LLM/agent tool calls. Rate limiting, path validation, argument filtering, audit logging.
Settlement-rail enforcement for DORA-compliant payment infrastructure. Companion to hsm + gatekeeper.
ZDOS Lab: source-first forge for ZDOS and Zlang contracts, evidence, gates, and portable release bundles.
Governed execution kernel for AI agents. Default-deny policy, bounded capabilities, typed execution, transactional Git. Evidence over claims.
To associate your repository with the default-deny topic, visit your repo's landing page and select "manage topics."