א Golem preview
Free public preview · security for AI agents

Your agents act.
Golem

Golem watches every action your AI agents take, blocks the dangerous ones the moment they happen, and keeps a tamper-proof record you own — so you can finally prove what an agent did, and stop it when it goes wrong. Not a log the agent wrote about itself; proof that survives a hostile question.

Sees every call Holds the risky ones Proves what happened

Free while in preview · set up in one line · your data never leaves your cloud.

Why this exists

An agent with your credentials is a stranger with your keys.

It reads untrusted content, calls tools, hits the network — headlessly, faster than you can watch. Three questions have no good answer today.

Danger

Is this safe to touch?

A poisoned web page or PR comment can turn your agent against you — the lethal trifecta. Nothing checks the URL or tool call at the moment it fires.

Proof

What did it actually do?

“An agent called an endpoint” is not evidence. Logs can be edited. You can't prove which agent, with what scope, touched what — after the fact.

Blind spots

What's even running?

Shadow MCP servers, unvetted tool calls, silent token burn. The agent surface grows faster than anyone's map of it.

True attestation

A trace the agent wrote about itself isn't evidence.

“Check the logs” fails the moment it matters. The record of an action has to be captured by something other than the actor — and be tamper-evident — or it proves nothing. Planes have flight recorders the pilot can't edit. We shipped agents with production credentials and skipped that step. Golem is the witness.

vs observability

LangSmith, Langfuse, Datadog help you make the agent better — self-reported traces in a store you don't control. Golem proves what it actually did.

vs agent security

Gateways and guardrails try to stop bad things; the logs are a byproduct. Golem proves what happened — including proving the control worked.

vs governance

Policies and model cards don't survive a subpoena. A signed, tamper-proof record — with the raw data still in your storage — does.

Secure every tool & MCP call

From the moment your agent acts to proof you can hand an auditor.

Golem sits inline, so every action your agent takes runs this path. The highlighted step is the one only an inline layer can do: decide and record at the exact moment of action.

Watch from outside the agent

Golem sits in front of everything your agent touches — its commands, its edits, its network calls, its AI-model traffic, even the browser. It watches from outside the agent, not from a library the agent controls. And because it sits in the middle, it can act, not just observe.

Check & hold the moment it happens

Because every call passes through it, Golem can let it through, block it outright, or hold it for a human — the edit, the shell command, the deploy, the fetch to a sketchy host, each one stoppable at the wire. Run /safely before a risky task and it locks the agent down to a safe, allow-listed set of tools it can't widen from inside the session. Everyone blocks things; the point is that afterward you can prove the block worked.

Edit src/app.ts — blocked evil-cdn.ru — blocked ⏸ held for approval

Sign & seal tamper-proof · machine-locked

Every action is sealed with a cryptographic signature and linked to the one before it — change any past record and the break is obvious. The signing key can be locked to the machine itself, so a signature ties to a real device. And nothing is ever lost, even if the network blips.

Store BYOB · your bucket

Raw payloads are split off and written to your own storage — S3, GCS, Azure, or local. The hosted plane only ever holds hashes and signatures. Your data never leaves your infrastructure.

See & govern the console

Open the console to the Agentic Security Graph, a shadow-AI inventory, a review queue, and one-click compliance-evidence export. It even flags ghost sessions — a session that spawned a background process and then went dark. The agent was headless; the human arrives to control.

A full security stack, built for agents

Watch it, defend it, prove it — from one inline layer.

Not an after-the-fact log. A control point that sees every action, stops the dangerous ones, and turns the rest into evidence you own.

Independent capture

Watched, not self-reported

Golem watches your agents from the outside — your IDE, your coding agents, your AI-model calls, even the browser. A record the agent writes about itself isn't evidence. This is.

watches from outside
Non-repudiation

Tamper-proof record

A permanent, append-only record. Every action is signed and linked to the one before it, so nothing can be altered or back-dated. Export the whole verified history for an auditor in one click.

what · when · with what context
Real-time defense

Check, hold, or block

Golem checks the target of every call against known threats and your own policy, then allows it, blocks it, or holds it for a human — before anything happens. And proves the block worked.

before the action lands
Anti-injection

Safely

A one-way safety lock. /safely restricts the agent to a safe set of tools — blocking edits, shell commands, and the rest — and only a human can loosen it, never the agent. So content that tries to hijack your agent can't widen its own reach.

locks tighter, never looser
Data sovereignty

Your data stays yours

Bring Your Own Bucket. Raw prompts and payloads live in your S3/GCS/Azure/local storage. Golem proves that it happened without ever holding the content.

S3 · GCS · Azure · local
Rooted in silicon

Hardware-backed keys

Signatures can be bound to a key that never leaves real hardware — a TPM 2.0 on Linux or Apple's Secure Enclave — so a signature ties to a specific machine, not just a process.

TPM 2.0 · Secure Enclave
Visibility

Agentic Security Graph

The live topology — Hosts → Agents → MCP Servers → Tools — plus a shadow-AI inventory that surfaces MCP servers nobody registered running on your fleet.

shadow-AI detection
Anomaly

Ghost-session detection

Flags ghost sessions — one that spawned a background process (nohup, &, tmux…) and then went silent. The classic runaway-cost pattern nobody notices until the bill lands.

backgrounded, then gone quiet
Provenance

Verified agent attribution

Each agent gets its own short-lived, revocable identity. The record shows exactly which agent did what — proven by the signature itself, not just claimed by the agent.

scoped · signed · revocable
Audit-ready

Compliance evidence export

One click turns the record into an auditor package — chain-of-custody, an integrity attestation, and control→evidence maps for SOC 2, ISO 27001, and EU AI Act Article 12.

SOC 2 · ISO 27001 · EU AI Act Art. 12

Drop-in

It already speaks to your stack.

Golem rides the Model Context Protocol, so it wraps the tools you already run — usually in one line of config. No rewrite, no SDK lock-in.

Claude Code Cursor Windsurf Antigravity OpenClaw LangChain OpenAI Agents SDK CrewAI LlamaIndex Semantic Kernel ChatGPT · Claude.ai · Gemini (browser) Anthropic · OpenAI · Gemini APIs

For agents and humans

Same wire, two customers.

The agent onboards for its own benefit; the human converts for control. Both live on one inline layer.

The agent

onboards for value

// headlessly, for free

  • A safety check on the URLs and tools it's about to touch, before it acts
  • Durable context and memory across runs
  • An answer to “is it safe to connect?” at action-time

The human / org

converts for control

// once the value is undeniable

  • A tamper-evident record of everything the agent did
  • Attribution: which verified agent, which scope
  • Governance, flagging, and compliance-evidence export

AI-native · agents defending agents

An agent can't investigate itself. It takes an army — of golems.

The thing that watches an agent can't be the agent. So Golem is AI-native to the core: every action is embedded and handed back through its own MCP server — so agents can investigate agents, and the guardrails that come out of it keep the whole fleet safe.

Investigate

Ask the record anything

Every action is indexed the moment it happens, so an agent can ask — in plain language — what another agent did, replay a whole session, and confirm nothing was tampered with. No dashboard required.

ask in plain language
Rule

Turn a finding into a guardrail

Write a rule once — “never touch production right after reading untrusted content” — and it watches every agent automatically, forever. The whole fleet learns from one golem's catch.

write once · watches everyone
Defend

Safety that travels headless

Safety verdicts and /safely clamps ride the same wire, so a guardrail earned on one host protects the next agent that connects. Golems watching golems.

headless · scoped · revocable

The defensible middle

A sandbox asks “how much can it break?” Golem asks “should this action happen — and can you prove what did?”

Prompt injection rides your agent's own credentials and permissions, so a sandbox can't catch it — it's a question of what the agent is allowed to do, not how far it can reach. Golem is the only layer that can both stop an action and prove it happened, from the same point inline. That signed, tamper-proof record is exactly the evidence EU AI Act Article 12, SOC 2, and ISO 27001 ask for — which isolation can't produce.

✓ EU AI Act Art. 12 ✓ SOC 2 · ISO 27001 Cryptographically signed
א

The next signup isn't a person.
Be the layer it lands on.

Golem is in free public preview while we figure out what teams need most. Start now, protect your agents, and see everything they do.

Sign in with Google or email · your data stays in your cloud