Five buyers.
One control layer.
Cirvix is an in-process runtime tool-call authorization layer: every agent action is evaluated against policy before it runs, and the decision is recorded in the unsigned hash-chained log. The mechanism never changes between teams. What changes is which question you need answered first — pick your role.
Find yourself: Developer · Platform · Security engineer · CISO · CTO
Ship agents without
betting the company.
Your question: if we let agents touch production, what is the blast radius — and can we prove it stayed inside? One control layer, a recorded verdict on every action, and failure modes that deny instead of waving through.
Your path: a Free pilot this week, the evaluation answers for your architects, and an Enterprise scoping call when the deployment itself is the requirement.
A boundary you can point at
Agents reach models, tools, and databases through one layer. There is no second path that a team can add without it becoming visible.
Scope that cannot drift
org_id scoping is enforced in routing. A query that was never scoped is refused rather than quietly widened.
Keys that stay yours
CIRVIX_MASTER_KEY is customer managed with no escrow path, so the vendor cannot decrypt on your behalf.
One rail, many teams
Product teams keep their own runtimes. Platform sets the rules once and every team inherits the same evaluation path.
Rules ship like code
Policies are JSON, reviewed in a pull request, scanned in CI, and published as SARIF with stable fingerprints.
Two SDKs, one verdict
Node and Python evaluators are held to a shared conformance fixture, so a team cannot get a different answer by changing language.
Shared
operational rails.
Your question: how do we give every team the same guardrails without owning every team's runtime? You set the rules once; every team inherits the same evaluation path.
Your path: pilot Free on one team's agents, then shared policy with RBAC on Team via the waitlist. Scope it with the plan audit.
Evidence without
assembly.
Your question: when the auditor — or the board — asks what the agents did, how long does the answer take, and does it hold up?
Your path: evidence reports on Team, scoped Enterprise deployment with your own keys and IdP — via a scoping call. The evaluation answers cover what your architects will ask first.
The record is the byproduct
Evidence is produced by the decision path itself, so there is nothing to reconstruct from raw logs afterwards.
Reports that do not overclaim
Coverage reports describe what is covered. They contain no word for “compliant” — that is enforced by test, not by tone. SOC 2 and ISO 27001 are in progress; we do not describe ourselves as certified. Trust center →
Approvals bind to content
An approval is bound to the hash of what was approved. Editing the request un-approves it, so a stale sign-off cannot be inherited.
Fails closed
If the policy engine or the audit store is unreachable, actions are denied. There is no pass-through mode to discover during an incident.
Answers after the fact
cirvix why explains a verdict. cirvix replay re-evaluates it against today’s rules and never re-executes the original action.
Held, not dropped
An execution that needs a human decision is held with its request intact rather than failed and retried blindly.
Safer
automation.
Your question: when an agent does something surprising at 3am, what stops it — and what tells you why? The engine denies first and explains after.
Your path: Free now; human-in-the-loop holds arrive from Pro via the waitlist. Threat-model skeptics start at what is out of scope.
See a DENY
in minutes.
Your question: how fast can I watch this refuse my own agent? Run npx @cirvix_ai/agent-control scan — no account, nothing leaves your machine — then write your first rule and break it on purpose.
Your path: Free tier now — 100 decisions a day, custom rules from Starter via the waitlist.
Deny by default
An unmatched action is denied and recorded as unmatched, so a new capability has to be granted deliberately rather than discovered. Policy engine →
Observe without authorizing
audit_only records what a rule saw and grants nothing. Watching an action is never the same as permitting it — and if it is the only match, the engine still denies.
Rules ship like code
Policies are JSON, reviewed in a pull request, scanned in CI, and published as SARIF. Node and Python evaluators share one conformance fixture, so both SDKs return the same verdict. SDKs →
Not sure which of these you are?
Describe the agent you are worried about and we will tell you which part of this actually applies.
Bring every agent
under control.
Set durable policy, preserve a verifiable record, and give teams a safer way to put intelligent systems to work.
Contact Enterprise Sales
Discuss custom VPC deployments, policy requirements, or dedicated enterprise support.
Prefer to talk? Book a 30-minute call