HOL Guard for enterprise

Let your developers move fast with AI.
Keep every action inside policy.

Guard Local enforces policy on every developer machine, even offline. Guard Cloud adds shared policy, org-wide visibility, and deployment review without making enforcement cloud-dependent.

Download the enterprise brief
Local enforcementApache-2.0 local runtimeWorks offline13+ supported AI coding agents
guard.local / enterprise-review
Policy is evaluated before executionRisky requests remain reviewableDecisions leave an evidence trail

Verified coverage

13 supported agents

Codex, Claude Code, Cursor, Gemini CLI, OpenCode, and more.

Open-source status

Guard Local · Apache-2.0

The local enforcement layer is inspectable and self-serve.

Visible result

Blocked before execution

Decision, reason, and next action shown together.

Evidence posture

Redacted decision records

Shared evidence omits source and secret material.

Supported AI coding agents

CodexClaude CodeCursorGemini CLI+ 9 more

One control layer across the supported agent ecosystem.

System architecture

Keep enforcement local.
Share only what security needs.

Guard Local sits between every agent action and the operating system. Shared policy, evidence, and deployment review are optional layers around that protected boundary.

Developer machine · local enforcementRequired for enforcement

Developer Machine

Code, credentials, and infrastructure

AI coding agents

13+ supported harnesses

HOL Guard Local

Intercept · block · ask · save decision

Policy decision · localoffline-ready

Protected machine resources / actions

File system, shell, network, secrets

Optional shared layerNot required

Guard Cloud

Shared policy & org-wide telemetry

redacted policy & evidence only

Security team workflows

Dashboards and trend analysis.

SIEM

Route redacted decision records.

Deployment review

Bounded rollout with named owners.

Your code stays local. · Your secrets stay local. · Enforcement stays local.

Enforcement remains on each developer machine.
Policy and evidence can be shared when the team is ready.

Three core outcomes

Prevent, govern, and prove — on every developer machine.

Prevent

Stop risky agent actions before execution

Guard Local intercepts the next agent action and blocks, asks, or allows it against policy before any side effect is created.

Blocked before runFile system · shell · network
Govern

Apply policy consistently across supported agents

One policy layer governs 13 supported AI coding agents, so the same decision surface applies no matter which harness the team adopts.

CodexClaude CodeCursorGemini CLI+9 more
Prove

Create reviewable evidence of policy decisions

Every decision leaves a redacted, reviewable record — so security can audit what happened without source or secret material leaving the machine.

decision.saved · sha256

REDACTED · source omitted

Enterprise controls

Fit the control plane to the way your team operates.

Identity, evidence, threat context, support, and deployment boundaries each get a deliberate place in the rollout.

Identity boundary

SSO / SAML identity federation

Connect Guard workspaces to the identity system your security team already governs, with role-aware access to policy and evidence.

Identity flowSAML assertion verified

Identity provider

Team directory

SSO / SAML

Role mapping

Guard workspace

Policy access

Security operations

SIEM and log pipeline export

Route redacted decision records into the log pipeline that already holds your security evidence.

Redacted event streamconnected

12:04:18ALLOWpolicy.check · workspace

12:04:21BLOCKcommand.review · redacted

12:04:21RECEIPTdecision.saved · sha256

Source and secret material omitted
Signal layer

Custom curated threat feeds

Bring the signals that matter to your environment into the same policy decision surface.

Signal → match → decision
Curated threat signalnew
Policy matchready
Review thresholdhigh
Operating model

Volume pricing and dedicated support

Scale the rollout with a commercial path and a clear support relationship.

Rollout support

Named

owner

Bounded

review

Ready

next step

Deployment boundary

On-premises Guard Cloud option

Keep the shared control plane inside the network and operating boundary your team chooses.

Deployment boundary

VPCGuard Cloud

Keep the shared layer inside the operating boundary your security team approves.

A bounded path to rollout

Make the next decision with evidence in hand.

Keep the first step small, make the local boundary visible, and decide on broader rollout only after the team has a reviewable record of how Guard behaves.

  1. Start here

    Bounded review

    Choose the initial harnesses, owners, and action boundary for a controlled evaluation.

  2. Install and evaluate

    Install Guard Local on the selected machines and observe policy decisions before actions run.

  3. Decide on rollout

    Review the decision trail, align with the named owner, and expand the boundary when it is ready.

Enterprise FAQ

HOL Guard is a runtime security layer for AI coding agents. The enterprise path adds shared policy, org-wide telemetry, and a bounded deployment review so teams can adopt AI coding tools without ceding control over code, credentials, or infrastructure.

No. Guard Local runs entirely on the developer machine and enforces policy without any cloud dependency. Guard Cloud adds dashboards, shared policy, and org-wide telemetry on top of the local enforcement layer, but enforcement never depends on cloud connectivity.

Guard supports 13 harnesses including Codex, Claude Code, OpenCode, Copilot, Cursor, Gemini, Hermes, OpenClaw, Antigravity, Kimi, Grok, Pi, and ZCode.

A deployment review covers your control boundary, developer workflow constraints, evidence and audit requirements, and deployment operations. It produces a bounded rollout plan with success criteria, an owner, and an exit decision for each stage.

Guard Cloud provides centralized policy management so teams share definitions. Individual developers still enforce locally with Guard Local, so enforcement never depends on cloud connectivity.

Guard Local collects minimal telemetry (session hashes, timing, policy decisions). Guard Cloud adds org-wide dashboards and trend analysis. All data is configurable per policy.

Yes. Guard Local operates fully offline with no cloud dependency. Guard Cloud is an optional add-on for teams that want dashboards and shared policy.

Ready for a bounded rollout?

Give security a clear way to say yes.

Walk through the local enforcement boundary, shared evidence posture, and deployment review path with the HOL Guard team.

Book a 20-minute security review