Isonapse is the independent runtime governance layer between your AI agents and what they can touch: files, the shell, the web, and your tools. You set the rules. Isonapse enforces them before every action and creates a verifiable audit trail.
macOS and Linux · Claude Code required · runs locally · zero code changes
A replay of a governed session, exactly as the hook renders it. Every action resolves to a verdict before it runs, and every advancing decision writes a signed receipt you can verify offline. Read it top to bottom.
Three verbs run the whole system. Everything else is detail that lives in the docs.
You set the rules: what an agent may do, what needs a human, what is never allowed. Your rules are the source of truth, not the model's mood.
Every action passes a checkpoint that allows, asks, or blocks it before it runs. The agent can't route around it.
Every decision is written to a tamper-evident, signed ledger you can verify offline.
It's tempting to assume governance comes for free with whichever model or tool you picked. It doesn't, and it structurally can't.
The neutral layer: any agent, any model, any harness, by design.
Every agent harness and model vendor ships its own controls. But once you use multiple frameworks, open-weights models, or your own harness, those controls stop at the vendor boundary.
Governance has to be the neutral layer across all of them: owned by you, with one policy and one audit chain across every runtime.
We govern the agents you run. We never run them for you. We are not another agent or model. We are the control plane around them.
Where it stands today: the Claude Code hook ships now, and enforcement for the self-hosted path exists as real code. Multi-host adapters and a universal SDK are the next release.
Approving every prompt and trusting blindly are the same failure. Isonapse learns your normal, waves the routine through, and speaks up only for the genuinely odd.
A poisoned web page can turn your agent against you. The gate sits outside the agent, so a hijacked agent can't argue with it.
On the supported paths, secrets and model-visible strings can be tokenised before they travel. Secret placeholders keep plaintext out of model-authored input.
Every advancing decision has a signed, tamper-evident record anyone can verify offline with the pinned public key.
"AI safety" that is itself an AI is circular: a model you have to trust, policing a model you don't. In Isonapse the critical decisions are made by deterministic code. The system learns your normal so it can flag the abnormal, but that learned judgement is advice, never authority.
A learned hunch can turn a "yes" into an "ask." It can never turn a "no" into a "yes." That single rule is why a fooled model can't escalate its own privileges.
Your policy, not the model's mood.
Built for enterprise scale, and honest about what ships when.
What one machine learns and one team writes can travel across the fleet: learned behaviour as a signal, policies as versioned logic. Signing never centralizes, so there is no central brain to compromise. Proof travels; secrets and memory stay home.
This is the furthest-out capability, and we say so plainly: witness federation arrives with the next release, and full fleet sync is the Enterprise tier. The design is settled; the wiring is the work.
The critical control path is deterministic policy and bounded local state: no network round-trip, no SaaS in the loop. Everything degrades gracefully and keeps enforcing offline. A pulled network cable doesn't stop enforcement.
Hard per-session and rolling-hour limits that survive a restart. A runaway loop gets stopped, not invoiced.
The same enforcement engine everywhere. Choose how far it reaches: your machine, your server, your organisation.
A local safety layer that learns what you do, catches what's off, and never calls home. One Homebrew line, zero code change.
The full Isonapse control plane on your own hardware: one dashboard for every agent you run. Free under its own license. No SaaS account.
Public beta · early September 2026Everything in Community, scaled to an organisation: SSO, organisational trust, fleet-wide budgets, compliance reporting.
Q4 2026No cloud service, no account, no telemetry. Enforcement keeps working with the network unplugged.
Built with European expectations in mind: the audit trails and human oversight regulation such as the EU AI Act calls for, and the security practice frameworks like OWASP and NIS2 describe. The compliance detail lives in the docs.
A private technical community for people building the agentic future.
A daemon is a process that runs in the background without needing to be constantly instructed or supervised. It quietly does the work that keeps a system alive. That is the mindset behind Isonapse Daemons: a small, focused group of experienced engineers, builders and technical thinkers working with AI agents and agentic systems.
Not another large community. Not another place to collect badges. We are starting small.
About the program →Tell us who you are, what you are working on, what drives you and how you believe you could contribute.
Apply to joinThe agent-tooling gold rush is full of overnight wrappers: a hook script, a regex, a dashboard. The thing that polices your agents has to hold up under adversarial review, not just a demo.
A replay of the attack-shaped tests the suite runs in CI. Pick an attack; watch it fail.
"Trust us" is replaced by "verify the record yourself." That isn't a metaphor for the witness chain. It is the witness chain.
macOS and Linux · Claude Code required · runs locally · zero code changes
Agent Hook beta today · Community Edition September 2026 · Enterprise Q4 2026