The circuit breaker
for AI agents.

Policy as Code for Continuous Compliance and Continuous Enforcement. Intutic sits in the tool-call path between your AI agents and production — every file write, API call, and shell command passes through a synchronous, in-process evaluation chain, turning every decision into compliance evidence and enforcement action in real time.

# Install the Intutic developer CLI & native Rust proxy
npm install -g @intutic/cli @intutic/proxy

# Start the native proxy gateway. No account needed.
intutic start
209µs
P95 proxy overhead — 1 KB, standalone, M4 Pro
43
Supported Harnesses
5
Enforcement Actions

AI agents ship fast. Governance doesn't. Agents make tool calls, write code, and access production data — all without guardrails. Intutic stops leaks, runaway loops, and destructive tool calls in real time.

An exfiltration attempt, blocked mid-flight

The agent reaches for curl -d @.env. The policy chain evaluates in-process, before the request leaves the machine. SOP-004 returns KILL, and the loop halts with zero secrets leaked.

From governance complexity to intelligent control in minutes.

Together, these capabilities form shared infrastructure for AI agent governance across enterprise systems.

Powerful Governance
Intercepts non-compliant tool calls in real time across your entire agent stack with semantic, policy-aware, and context-driven enforcement.
intutic · audit feed
live
12:04:31
✓ allow
tool:db.read
12:04:33
⊘ block
tool:shell.exec
12:04:34
✓ allow
prompt:agent.plan
12:04:36
⚑ flag
data:pii.export
12:04:38
✓ allow
tool:http.get
Real-time Trace Sync
Every tool call, prompt, and response captured and indexed instantly. No stale logs. No blind spots.
Prebuilt Policies
Governance policy engine supporting SOC 2, GDPR, and custom enterprise rules.
✓ Redact card numbers & IBANs
(PII)
DLP
✓ Block destructive shell
(rm -rf)
SOC 2
Framework Friendly
Drop Intutic into LangChain, CrewAI, the Anthropic SDK, Mastra or your own agent stack. Five minutes from install to first enforced call.
Open Source Core
Trust and transparency are core tenets. Intutic's policy engine is built in the open and improved by the community.
Open-core on GitHub

Observability measures the model call. Intutic governs the tool call.

Capability LLM Observability
(Langfuse, Arize, LangSmith)
Intutic
(Agent Governance)
Where it acts On the model call: traces, evaluations, and guardrails on model input and output On the agent’s tool call, before it runs
Tracing & evaluation Deep traces and LLM-as-judge evaluations — their core strength Traces every model call through the proxy with its enforcement decision; gate decisions can stream to your SIEM
Blocking a tool call Guardrails act on model input and output, not on the shell command, file write or MCP call the agent then runs Native pre-execution hooks; the call waits on the verdict and fails closed if the gate crashes
Human approval Review happens after the run Risky calls are held until an owner, admin or engineering manager approves in Slack or the CLI; with the review-hold bypass on, the identical retry then passes
Sensitive data Langfuse and LangSmith mask trace data; LangSmith’s gateway also redacts PII and keys on model traffic API keys, cloud credentials, tokens, checksum-validated card numbers, IBANs, US Social Security numbers and patterns you define redacted or blocked before they leave the machine, and in responses before the agent sees them
Cost control Cost tracking; LangSmith’s gateway adds hard spend caps Daily spend caps enforced before the request leaves
Coding agents Instrument your own application through an SDK or OpenTelemetry 43 harnesses, from Claude Code, Cursor and Gemini CLI to Copilot and LangGraph
Containment Outside their scope Default-deny egress firewall and sandboxed runs, so an agent cannot route around governance
Custom policy Custom evaluators and scorers SOPs in git, WASM rules and Rego policies, evaluated in the call path

One hop in the path. Nothing else moves.

A local Rust proxy on port 4000 and a config sync daemon. Your agent talks to the proxy, the proxy talks to your provider, and policy is evaluated in between.

Intutic request flow An AI coding agent sends a tool call to the local Intutic proxy on port 4000. Local SOP rules sync to the sync daemon, which hot-reloads them into the WASM policy engine. The proxy forwards the cleaned request to upstream providers, and returns a block or hijack verdict to the agent. DEVELOPER ENVIRONMENT AI Coding Agent Claude Code · Cursor · Aider · LangGraph Local SOP Rules CLAUDE.md · .cursorrules · SKILL.md SYNC DAEMON Config Reconciler bidirectional INTUTIC HOT-PATH PROXY  :4000 WASM Policy Engine in-process evaluation Secret DLP & Masking PCAS Action Primitives BYPASS · ENHANCE · HIJACK · REASK · KILL UPSTREAM PROVIDERS Anthropic · OpenAI LiteLLM · Ollama 1 · tool call 2 · rule sync 3 · hot-reload 4 · clean request 5 · verdict

From individual developer to CISO — one platform.

Intutic provides the shared infrastructure to run, observe, and secure AI agents across enterprise perimeters.

Deployment comparison
SaaS (Cloud-Hosted)

Fully managed on Intutic's infrastructure.
Zero ops burden. Automatic updates and scaling.

Your VPC

Deploy to your AWS, GCP, or Azure account.
Data never leaves your network boundary (BYOC).

Air-Gapped On-Prem

Full Kubernetes Helm charts + Docker Compose profiles.
Zero data egress.

EU AI Act Mapping GDPR Compliance Engine
IC Developer

IC Developer — Active steering, not hard limits

Unlike rigid security tools, Intutic steers agents via real-time corrective context, performing continuous audits and breaking off recursive failure chains.

Engineering Manager

Eng Manager — One SOP registry

Centralized rules that sync to every developer's machine in real time. No more divergent .cursorrules files. Manage rules, policies and workspace settings as code with the Terraform provider.

VP of Eng / CFO

VP of Eng & CFO — Spending safeguards

Daily cost thresholds and session budgets prevent runaway agent loops. Cost safety controls that actually work. Cost by developer, team, branch and pull request shows where the spend goes.

CIO / CISO

CIO & CISO — Security & safety perimeters

Zero-trust tool firewalls, active stream interception, OBO credential gating, and real-time safety alerts. SSO and SCIM groups decide who may run high-risk tools, in every gate, and an AI inventory flags the harnesses and MCP servers on developer machines that run outside governance.

Simple, transparent plans for teams of all sizes

Self-serve

Pay only for what you govern

$ 1.50 /1,000 requests
$5,000/mo minimum · billed monthly in arrears
  • No seats, no annual commitment
  • $500/day monitored LLM volume
  • 5 API keys
  • Response caching
  • SOP registry, Config Sync & trace query API
  • 3-year trace retention

Enterprise

Up to 2,500 seats

$ 15,500 /mo
Billed monthly
  • Includes 10.3M governed requests/mo, then $1.50 per 1,000
  • $12,500/day monitored LLM volume
  • Unlimited API keys
  • Everything in Biz Org
  • SCIM provisioning, with cost per team
  • Self-hosted gateway
  • Daily compliance evidence collection
  • Data residency: US; EU on request
  • 3-year trace retention

Self-host

Annual license for your VPC or air-gapped network

How Self-host installs →
  • Unlimited seats and requests
  • Everything in Enterprise
  • Runs in your VPC or air-gapped network
  • Signed license file, no phone‑home
$ 168,000 /year
Invoiced annually in advance
Contact sales →
Aider
Antigravity
Claude Code
Cline
Codex
Confluence
Continue
Cursor
GitHub
Goose
Hermes
Jira
n8n
Notion
Open WebUI
OpenClaw
OpenHands
PagerDuty
Pi
Roo Code
Slack
Windsurf
INTEGRATIONS & HARNESSES

AI-First Governance for Any Harness

Governs Claude Code, Cursor, Gemini CLI, AWS Bedrock AgentCore Runtime, LangGraph, and proprietary custom agent harnesses. Autonomous self-configuration via the Kitkat agent skill, and self-hosted or air-gapped deployment under a Self-host license. QM, Anthropic Managed Agents, and the AWS Bedrock AgentCore Gateway integrate server-side over HTTP, outside the auto-detected harness list.

Built on open-source infrastructure.
Governed by proprietary intelligence.

DEV TOOLKIT

@intutic ecosystem

TypeScript Python MIT License
@intutic/mcp-governance-proxy MCP

Intercepts, filters, and logs stdio JSON-RPC tool frames.

@intutic/sync-daemon Daemon

Bidirectional config synchronization running locally on workstations.

@intutic/clawde SDK

Programmatic TypeScript client wrappers and proxy connection adapters.

What Intutic enforces.

"In between the workflow, things should be flagged and stopped — not discovered after the fact."
— The Intutic Design Principle
P95 proxy overhead: 209µs at 1 KB · standalone, M4 Pro
"A wrong answer that looks right is more dangerous than no answer at all. Enforcement must be synchronous."
— Why Active Enforcement Matters
5 enforcement actions: BYPASS / ENHANCE / HIJACK / REASK / KILL
"You can't govern what you can't see. Every tool call, every LLM response, every agent decision — recorded."
— Full Trace Visibility
Audit ledger with complete trace capture
"Loop burn isn't a bug report, it's a bill. Cap the spend before the agent racks it up, not after."
— Session Spend Ceilings
Per-session budgets enforced natively by the local Rust proxy
"AgentCore Runtime hosts your framework code, not ours. We govern what's already there — nothing to rewrite."
— AWS Bedrock AgentCore Runtime
Delegates to whichever supported framework adapter your code already uses
"A multi-agent graph is only as governed as its least-watched node. Every framework gets the same gate."
— SDK-Gated Multi-Agent Governance
17 frameworks gated in-process via @intutic/gate / intutic-clawde
FAQ

EVERYTHING YOU NEED TO KNOW
BEFORE GETTING STARTED

/ 001 What is Intutic?
Intutic is an Agentic Workforce Management (AWM) platform — the active firewall, compliance auditor, and self-healing configuration engine for multi-agent AI pipelines. The client-side workstation interceptors are open-source, while the central control plane (enforcing organizational policies and optimizing prompts in real time) is commercial.
/ 002 How is Intutic different from Langfuse, Arize, or LangSmith?
Those platforms are excellent at tracing and evaluating LLM applications, and some now add guardrails on model input and output. Intutic governs the agent’s tool call itself: it decides each shell command, file write and MCP call before it runs, can hold a risky call for human approval, and keeps the agent from routing around governance. We complement observability; we don’t replace it.
/ 003 Which AI agent harnesses does Intutic support?
43 harness adapters across five categories, all auto-detected via npx @intutic/cli init. Hook gates need no change to your agent code; SDK-gated frameworks add an in-process gate to your agent code:
  • Native hook gates (18, installed in the harness's own configuration) — Claude Code, Cursor, Windsurf, Codex, Cline, Gemini CLI and Google Antigravity, GitHub Copilot, Goose, OpenHands, OpenClaw, Hermes, n8n, and more, including newer adapters like Muse Code, Grok Build, OpenCode, and dsh (preview).
  • SDK-gated frameworks (17, dedicated in-process gate via @intutic/gate / intutic-clawde) — LangGraph, LangChain, CrewAI, AutoGen, Google ADK, OpenAI Agents SDK, Pydantic AI, AWS Strands Agents, Microsoft Agent Framework, Mastra, Vercel AI SDK, and more.
  • Proxy-governed (4, no tool-call hook to attach to) — Aider, Continue, Roo Code, and Claude Desktop, governed through the proxy or the MCP governance proxy.
  • Orchestrators (3, delegate to an already-gated harness) — Spotify Xirp, DoorDash Agentic Orchestrator, and AWS Bedrock AgentCore Runtime.
  • Bridge-gated (1) — TrueForge run as a standalone server, governed by an Intutic-operated bridge service.
Anything else that speaks an OpenAI- or Anthropic-compatible API is governed the same way by pointing its base URL at the proxy. Three server-side platform integrations — QM's securityScreen contract, Anthropic Managed Agents, and the AWS Bedrock AgentCore Gateway — call Intutic directly over HTTP and sit outside the 43, since they have no HarnessType and aren't auto-detected.
/ 004 How long does setup take?
30 seconds: run npx @intutic/cli init and npx @intutic/cli connect — it auto-detects your harness and configures the proxy redirect. intutic disconnect undoes it: every harness config connect changed goes back the way it was, and its background services are removed. Full SOP Registry setup typically takes 1–2 hours. Enterprise deployment with SSO takes 1–2 weeks with our deployment team.
/ 005 Does Intutic add latency to my agent sessions?
Layer 1 synchronous enforcement (budget gate, DLP scan, hostname filter, WASM rules) is in-process and adds no network hop. Measured end to end against a stub upstream on an Apple M4 Pro in standalone mode: 152µs p50 / 209µs p95 at a 1 KB body, rising to 430µs / 490µs at 32 KB. The policy chain itself is 1.3µs on clean traffic and 8.7µs with every SOP declared. Deployments that use the hosted control plane add HTTP round trips, so treat these as a floor rather than a ceiling. Benchmark source: packages/proxy/benches/ab_latency_bench.rs. The high-reasoning evaluator runs asynchronously (out-of-band) — it never blocks the agent unless a hard kill is triggered.
/ 006 Can I self-host Intutic?
Yes, two ways. The open-core proxy, CLI and sync daemon are free and run entirely on your own machines (npm install -g @intutic/cli @intutic/proxy). The full platform, with the control plane and dashboard, is available as a Self-host annual license for your VPC or an air-gapped network: it installs from a signed bundle and needs no route to the internet. Contact sales for a license, and read the Self-host guide. Yes — the open-core proxy, CLI, and sync daemon run entirely on your own machines. Traffic goes straight from the local proxy to your LLM provider; nothing is routed through us. Install with npm install -g @intutic/cli @intutic/proxy.
/ 007 What does Intutic provide for compliance?
Evidence for your own audits: eleven compliance probes scored hourly against live workspace state, a SOC 2 evidence export built on them (signed when a signing key is configured), a tamper-evident trace log, GDPR erasure on request, and data residency in the US, with EU on request. The same evidence is mapped, as partial coverage, to the EU AI Act, ISO/IEC 42001, the NIST AI RMF and MITRE ATLAS, with coverage reports as JSON, Markdown, CSV or PDF and an EU AI Act Article 14 human-oversight export. Real-time proxy checks keep data handling inside the policies you set.
/ 008 Is Intutic open source?
Intutic is open-core. The client-side workstation stack — including the Rust proxy gateway (intutic-proxy / @intutic/proxy), onboarding CLI (@intutic/cli), TypeScript SDK (@intutic/clawde), stdio interceptor (@intutic/mcp-governance-proxy), rule syncer (@intutic/sync-daemon), and shared types — is fully open-source (MIT licensed) and runs against a local Valkey cache. Centralized governance registries, SOP Optimizer compilers, compliance dashboards, and active network controllers are commercial.
/ 009 What works in standalone Open-Core without a cloud connection?
Almost all local governance features work completely offline. The local sync daemon automatically merges guidelines into CLAUDE.md/.cursorrules, and the local Rust proxy evaluates prompts/responses against them in a WASM sandbox on your machine. All spend metrics are saved to local JSONL files, and daily limits are enforced natively by the local Rust proxy. Only team-wide dashboards and remote LLM-as-a-judge reviews require the GKE control plane.
/ 010 How does Intutic enforce rules? Can the agent LLM just ignore them?
Enforcement is active and protocol-level. Outbound tool calls are intercepted and blocked before execution (PCAS gate), and output streams are scanned line by line as they arrive, and secrets are redacted before the agent sees them (DLP gate). If an agent violates a rule (such as writing hardcoded hex values in CSS or using a deprecated API), the proxy injects corrective steering advice into the stream or kills the generation entirely. If database/Valkey cache layers are unreachable, the budget gate fails closed by default to prevent runaway token spend. Enforcement is not limited to security; any design system, architecture, or style guideline written in markdown rules is validated.
/ 011 How does pre-flight cost estimation account for multi-turn agent conversations?
Instead of predicting a single prompt turn, Intutic maps the current context size into input token buckets. The Token Intelligence Engine then queries the historical ledger (local JSONL files or cloud Valkey) for complete, multi-turn session traces that match the active model and task profile (e.g. debugging vs. refactoring). Static multipliers based on model benchmarks are used as a fallback if no historical data is available.
/ 012 How does Intutic prevent the same AI agent mistakes from repeating?
Instead of acting as a simple reactive check or warning card, Intutic runs a closed-loop policy optimization cycle. The platform collects telemetry from stream violations, blocked tool calls, and behavioral drift — a measured fall in how closely agents follow a given SOP — and clusters them to detect recurring error patterns. Once a pattern is identified, it auto-proposes and generates target-specific rule updates (such as a tightened CLAUDE.md or .cursorrules policy) as proposals for review. Once approved (or automatically, if the workspace turns on auto-apply), the update syncs to the developer's local editor or environment, so the agent is steered away on its next prompt turn.
/ 013 Can I write custom, fine-grained validation logic in AssemblyScript?
Yes. For complex rule checks that go beyond regex or simple pattern matchers, developers can use the @intutic/wasm-sdk to author custom validation logic in AssemblyScript. The compiled WebAssembly module is executed inside the proxy's isolated, fuel-limited WASM sandbox, which enforces a hard fuel and wall-clock limit per rule. You can test rules locally using the CLI command intutic policy test --wasm before dynamically hot-reloading them into the running proxy. Rules can also be written in Rego: intutic rules build compiles a policy with OPA into the same kind of WebAssembly module, which runs in the same sandbox in the proxy and the MCP governance proxy and can allow, deny, hold for approval or re-ask.
/ 014 How does Intutic govern MCP servers?
Every MCP server your developers' proxies and machines report lands in a registry, where an owner or admin approves or blocks it and switches individual tools off. A workspace can also refuse every server nobody has approved yet; that setting is off by default, so the servers your developers already use keep working until you switch it on. Call budgets cap calls per hour or per day for a server, a tool or a member, and every change to a server's tool set gets a rule-based risk score that can send the server back to the approval queue. The MCP governance proxy enforces all of this on each call, and the harness hook gates refuse blocked, held and unapproved servers by name as a backstop.
/ 015 How do security teams get alerts and records out of Intutic?
Notification rules send events to Slack, email, PagerDuty or a webhook, including a gate that has stopped reporting for 48 hours, a failed trace integrity check, and an ungoverned AI tool found in a machine's inventory. SIEM export streams traces, incidents, sign-ins, settings changes, governance alerts and, if you opt in, every gate decision to Splunk, Datadog, syslog, Amazon S3, Google Cloud Storage or a webhook. Every webhook, from a notification rule or a SIEM destination, is signed with an HMAC-SHA256 over a timestamp and the body.

Don't let your agents ship vibes.

Intutic gives AI teams the governance layer to deploy agents with confidence.