HOL Guard features

Stop risky agent actions before they execute

On supported integrations, Guard evaluates covered shell, file, MCP, skill, and package actions against your active policy before execution. Policy can allow, observe, request approval, or block.

Shell commandsChecked before execution
MCP callsChecked on supported paths
Package changesPolicy controlled
Blocked before it ran

Blocked: action stopped

Paused action

OpenCode wants to run a destructive command

From OpenCode

Blocked

What Guard paused

Requests a sensitive native tool action: destructive shell command.

Command
Command
rm -rf /

Risk detected

1 of 2

Executing rm -rf / would delete the entire filesystem.

Category guide

Evaluate the security boundary before the product name

These answers use the same coverage and limitation evidence published elsewhere on this site. They separate prevention, detection, scanning, and response so a buyer can decide whether Guard is a fit before comparing vendors.

What is an AI firewall?

An AI firewall is a policy enforcement layer placed on a consequential AI boundary. Depending on the product, that boundary can be model traffic, agent tools, MCP calls, files, shell commands, or outbound actions. For coding agents, the useful question is whether the control can evaluate an action before side effects occur. An AI firewall is not the same thing as a network firewall, WAF, EDR, DLP product, or package scanner.

When is HOL Guard an AI firewall fit?

HOL Guard fits the AI firewall category when the requirement is policy-driven, pre-action control over supported AI coding-agent action surfaces. It can allow, observe, ask, block, or report unsupported behavior according to the active harness and event surface. It is not a perimeter network firewall or a universal prompt filter, and it does not replace endpoint, DLP, identity, or secrets-management controls.

How should teams secure AI coding agents?

Use multiple layers: least-privilege identities, isolated execution, native harness controls, pre-action policy, supply-chain checks, secret management, audit evidence, and incident response. Guard focuses on supported agent action boundaries and separate artifact inspection. Harness coverage is versioned because the available hooks and failure modes differ between Claude Code, Cursor, Codex, Gemini CLI, OpenCode, and other integrations.

Can runtime controls prevent prompt-injection damage?

Runtime controls cannot guarantee that a model will recognize every malicious instruction. They can reduce impact by applying policy when influenced reasoning reaches a supported consequential action. Guard publishes those action boundaries and the paths it cannot reliably intercept instead of treating prompt-injection detection as a complete defense.

How should teams prevent secret and data exfiltration?

Keep secrets out of agent scope where possible, use scoped credentials, isolate environments, mediate supported sensitive reads and outbound actions, and retain evidence for response. Guard can apply policy to Guard-visible supported boundaries, but unsupported, already-completed, encrypted, or out-of-band egress still requires complementary controls such as DLP, EDR, network policy, and a secrets manager.

How is AI plugin and MCP supply-chain security different from runtime security?

Supply-chain controls evaluate identity, provenance, manifests, versions, install behavior, permissions, and artifacts before or during installation. Runtime controls evaluate what the installed capability actually tries to do. A scan is evidence about an artifact at a point in time, not a certification that future behavior is safe. Strong deployments use both layers.

Product preview

Every component below is the real Guard product in read-only demo mode. Scroll to explore each surface.

Runtime protection

See connected agents, machines, and integrations

Guard intercepts supported agent launches before covered actions run. The live topology maps connected machines, harnesses, MCP servers, skills, and repositories so risk stays visible at a glance.

  • Launch interception
  • Live topology graph
  • Machine and harness grouping
  • Agent and MCP inventory
  • Action controls
  • Local enforcement
Coverage
Harness-specific
Interception layer
Wrappers + hooks
Policy routing

Visual workflow builder for policy routing

Route each supported action to block, review, warn, or allow. Trace the policy path from launch to decision, then layer project and team overrides without losing precedence.

  • Block, review, warn, allow
  • Visual policy canvas
  • Decision flow tracing
  • Per-project overrides
Decision outcomes
4 modes
Policy layers
Machine to team
Review workbench

Live queue of blocked actions

Blocked actions arrive with redacted request context, a recommended action, and linked evidence. Review one or many, then export the decision trail for audit or incident review.

  • Decision memory
  • Shared review assignment
  • Bulk approve and deny
  • CSV and JSON export
Decision context
Policy-redacted
Export format
CSV + JSON

Compare Guard with AI security vendors

Compare the control boundary, not a marketing checklist. Every status below is tied to first-party documentation accessed 2026-07-14.

Execution boundary
Before supported actions run
Operating model
Local-first control
Decision proof
Receipts + export integrity
Open the evidence-backed vendor matrixDocumented, partially documented, and not publicly documented
DocumentedCapability described in first-party documentation.
PartialCapability partially documented; details incomplete at cited sources.
Not publicly documentedNot described in cited first-party sources.

HOL Guard versus Palo Alto Prisma AIRS comparison

CapabilityHOL GuardPrisma AIRS
Runtime action interception
Documented
On documented harness surfaces, intercepts supported shell, file, MCP, skill, and package actions before execution.
Documented
API Intercept screens agent requests and responses before execution.
Policy enforcement
Documented
Local and team policy can allow, observe, ask, or block on supported action surfaces.
Not documented
Policy enforcement model not detailed at cited sources.
Human review workflow
Documented
Dedicated review workbench with queue, decision controls, and routing.
Not documented
Dedicated human review workflow not documented at cited sources.
MCP and tool coverage
Documented
Screens supported MCP, shell, file, package, and skill surfaces.
Partial
Agent protection via API Intercept documented; MCP-specific coverage not detailed.
Routing and failover
Documented
Primary and failover route lanes with health monitoring and decision preview.
Not documented
Routing or failover model not documented at cited sources.
Evidence and audit
Documented
Retains local receipts, an evidence timeline, and decision replay; configured exports can include an integrity digest.
Partial
API reference and agent discovery documented; receipt or audit model not detailed.
Deployment model
Documented
Local-first on macOS, Linux, and Windows; optional Cloud sync.
Documented
Cloud-based API Intercept.

Public documentation gaps reflect the cited sources only and do not indicate a product lacks a capability. Vendors may document features elsewhere or offer them privately. This comparison makes no pricing or superiority claims.

Plans

Start with local enforcement for free. Add sync, alerts, shared policy, and team evidence when you need them.

MonthlyAnnual
Feature
Pro
$15/mo
Local protection
Local protection modules
Cloud-connected devices5
Cloud approval and receipt sync
Module settings across Cloud devices
Cloud retention180 days
Included cloud storage5 GB
Weekly personal security digest
Matched critical advisories
Real-time activity alerts
Policy versioning and rollback
Advanced search and full evidence
Searchable module decision history
Organization module policy
Shared policy and team workflows
Choose a planStart Free Trial
Decision memory

Turn review patterns into proposed rules

Guard turns recurring review decisions into proposed memory rules with risk and scope attached. Nothing changes until you confirm the suggestion.

  • Suggested rules from review patterns
  • Risk classification per suggestion
  • Scope selection: machine to team
  • One-time approval boundary
  • Cross-device memory sync
Scope options
4 levels
Confirmation
Always required
Evidence

Decision receipts with integrity-aware exports

Guard receipts record the supported action, policy decision, outcome, and linked evidence. Sensitive values are redacted before Cloud sync, and supported exports include an integrity digest when signing is configured.

  • Action and policy decision receipts
  • Secrets redacted before sync
  • Evidence hashes and provenance
  • CSV and JSON evidence exports
Receipt scope
Supported actions
Export integrity
HMAC when configured
Supply chain

Cloud Firewall for MCP, skills, and packages

Inspect supported MCP servers, skills, and packages before they reach an agent. Unknown or changed entries follow the configured policy, which can allow, warn, require review, or block.

  • MCP server inspection
  • Skill definition scanning
  • Package registry checks
  • Policy handling for new entries
Unknown entries
Policy-controlled
Inspection
MCP + skills + packages
Policy and memory

Turn reviewed activity into policy

Layer machine, project, workspace, and team policy with predictable precedence. Shared decisions can sync across devices, while local enforcement continues with the last available policy when Cloud is unavailable.

  • Policy suggestions from review history
  • Layered scope: machine to team
  • Shared policy memory
  • Cross-device sync
  • Cloud outage independence
Layer precedence
Most specific wins
Sync
Cross-device

Capabilities

Every Guard capability, grouped by surface. Filter by plan, surface, or search to compare.

33 of 33 capabilities

Runtime interception

4 capabilities

Launch interception and wrappers

Installs supported harness launchers and wrappers so Guard can evaluate actions before they run.

LocalProTeam
Claude CodeCodex CLICursorOpenCodeGemini CLIGoose

Action controls

Checks supported shell, file, MCP, skill, prompt-sensitive, and package actions before side effects.

LocalProTeam
ShellFilesMCPSkillsPromptsPackages

Safe Decode

Inspects supported encoded command content without executing it.

LocalProTeam
Encoded shell content

Cloud-outage independence

Continues local policy checks when Guard Cloud is unavailable.

LocalProTeam
Local enforcement

Policy and enforcement

5 capabilities

Local policy and project overrides

Applies machine policy with project-level overrides for supported agent actions.

LocalProTeam
Machine policyProject policy

Local blocking and warnings

Blocks denied actions and warns when policy requires a human decision.

LocalProTeam
BlockWarnApproval

Policy integrity tooling

Detects and repairs supported policy integrity problems on the local machine.

LocalProTeam
Policy verificationPolicy repair

Policy suggestions

Turns reviewed activity into suggested policy updates for an operator to accept or reject.

ProTeam
Policy review

Shared policy memory

Shares reviewed policy decisions across authorized workspace members.

Team
Workspace policyDecision memory

Review and decisions

2 capabilities

Decision memory

Reuses scoped approval decisions across connected Guard sessions.

ProTeam
ApprovalsDecision scopes

Shared review and assignment

Lets teams review and assign Guard requests in a shared workflow.

Team
Review queueAssignments

Evidence and history

7 capabilities

Receipts, explain output, and approval center

Keeps local receipts and exposes policy explanations and pending approvals.

LocalProTeam
ReceiptsExplainApproval center

Cross-session and cross-device history

Brings synchronized Guard activity together across connected sessions and machines.

ProTeam
SessionsMachines

Searchable activity

Searches synchronized action and decision evidence in Guard Cloud.

ProTeam
Action historyDecision history

Incident summaries

Groups relevant Guard evidence into incident summaries for investigation.

ProTeam
Incidents

Evidence exports

Exports synchronized Guard activity for offline review and retention workflows.

ProTeam
ActivityAudit evidence

Shareable records

Creates controlled records that teammates can use during review and response.

ProTeam
Evidence records

Cases and audit history

Maintains team cases and an auditable history of supported administrative and review actions.

Team
CasesAudit history

Supply-chain protection

2 capabilities

MCP and Skill drift visibility

Shows changes to connected MCP servers and skills so operators can review drift.

ProTeam
MCP serversSkills

Cloud Firewall UI

Reviews supported MCP, skill, and package changes in the Guard Cloud firewall.

ProTeam
MCPSkillsPackages

Fleet controls and administration

7 capabilities

Machine pairing

Connects a local Guard installation to Guard Cloud with a short-lived pairing flow.

ProTeam
Interactive machines

Headless pairing

Connects supported remote and automated machines without an interactive browser on the host.

ProTeam
Remote hostsCI runners

Workspaces and roles

Organizes Guard resources in workspaces with role-based access.

Team
WorkspacesRoles

Service principals

Provides non-human workspace identities for supported automation.

Team
AutomationAPI access

Resource ownership

Assigns accountable owners to supported Guard resources.

Team
MachinesPoliciesCases

Team billing and limits

Manages workspace billing and plan limits for Guard Cloud teams.

Team
BillingUsage limits

Team administration and exports

Provides workspace administration and supported team-level exports.

Team
AdministrationExports

Integrations

6 capabilities

Digests and notifications

Sends Guard activity digests and supported operational notifications.

ProTeam
DigestNotification

Slack integration

Routes supported Guard notifications and review actions through Slack.

Team
Slack

GitHub integration

Connects supported Guard review and evidence workflows with GitHub.

Team
GitHub

Jira integration

Connects supported Guard case and review workflows with Jira.

Team
Jira

PagerDuty integration

Routes supported Guard incidents into PagerDuty response workflows.

Team
PagerDuty

Email and webhook integrations

Delivers supported Guard notifications through email and outbound webhooks.

Team
EmailWebhooks

Compatibility

Guard installs on macOS, Linux, and Windows and supports the AI coding agents below.

Platforms

macOSLinuxWindows

Supported AI coding agents

Codex
Claude Code
OpenCode
Copilot CLI
Cursor
Gemini CLI
Hermes
OpenClaw
Antigravity
Kimi
Grok
Pi
Z Code

Security model

Guard is local-first. Supported policy enforcement, evidence, and review paths run on your machine. Guard Cloud adds optional synchronization and team operations.

Local-first enforcement

Policy checks run on your machine. Guard Cloud adds sync and team operations, but local enforcement works without it.

Action-level interception

Guard evaluates covered shell, file, MCP, skill, prompt-sensitive, and package actions on supported integrations before side effects occur.

Auditable evidence

Receipts, explanations, and approval decisions are captured locally and can be synchronized to Guard Cloud after configured redaction.

No forced upgrades

Local Guard is useful on its own. Cloud tiers add capabilities without degrading the local experience.

Risk-report privacy

Raw self-assessment answers are retained for up to 90 days. Private report links expire after 30 days. Report delivery does not opt you into marketing.

PrivacyTerms

Frequently asked questions

An AI firewall is a policy enforcement layer placed on a consequential AI boundary such as model traffic, agent tools, MCP calls, files, shell commands, or outbound actions. For coding agents, the key distinction is whether a control can evaluate an action before side effects occur. AI firewalls complement rather than replace network firewalls, WAFs, EDR, DLP, identity controls, and package scanners.

HOL Guard fits the AI firewall category when the requirement is policy-driven pre-action control over supported AI coding-agent action surfaces. It is not a perimeter network firewall or a universal prompt filter. Coverage is harness- and event-specific, and unsupported paths are published separately.

The HOL Guard core runtime is open source under the Apache-2.0 license. The public source repository is hashgraph-online/hol-guard. Guard Cloud is a separately scoped service, so the core runtime license should not be read as a claim that every hosted capability is open source.

The right alternative depends on the security job. Native harness controls provide per-agent permissions, model guardrails screen prompts and responses, static and software-composition tools scan code and dependencies, MCP gateways mediate protocol traffic, and EDR or DLP products protect broader endpoint and data boundaries. These controls can also be complementary rather than substitutes.

Guard uses harness-specific hooks, proxies, and managed runtime boundaries. On supported surfaces, policy can allow, observe, ask for approval, or block an action before execution. Coverage and fallback behavior are published per harness rather than claimed universally.

Local Guard controls can run without Guard Cloud. Cloud synchronization, shared team policy, remote intelligence, and other online features are separate capabilities and require connectivity when enabled.

Guard publishes release-specific compatibility only while the support snapshot is current. Supported and partial harnesses are listed in the compatibility section and harness security guides; coverage is event-specific. Devin is not currently verified as supported because no Devin adapter exists in the pinned stable or 3.0 alpha contract.

Both controls exist, but they are distinct. Guard can scan packages, skills, plugins, and MCP configuration for supply-chain risk, and it can also enforce policy before supported runtime actions. A scan result is not the same thing as runtime interception or a certification that an artifact is safe.

No product can guarantee that a model will recognize every malicious instruction. Guard can reduce impact when influenced reasoning reaches a supported consequential action because that action can still be evaluated before execution. Unsupported actions, model-internal reasoning, and paths outside the supported integration boundary remain separate risks.

Guard can apply policy on Guard-visible supported secret-bearing reads and consequential actions, but it cannot retroactively protect data already exposed or control every encrypted, unsupported, or out-of-band egress path. Teams should also use scoped credentials, environment isolation, secrets management, DLP or network policy where appropriate.

No. Guard uses policy-driven allow, observe, ask, block, and explicit unsupported outcomes. Approval delivery depends on the harness and event surface.

HOL Guard focuses on AI-agent artifacts and supported agent action boundaries. It complements rather than replaces EDR, endpoint antivirus, software composition analysis, dependency scanning, DLP, IAM, or general secrets-management controls.

More questions? Read the Guard documentation or run the self-assessment.

HOL Guard combines separate artifact inspection with policy-driven pre-action enforcement on supported AI coding-agent surfaces. Current publishable stable coverage includes Codex, Claude Code, OpenCode, GitHub Copilot CLI, Cursor, and 9 other published harnesses. Coverage is event-specific, and unsupported paths remain documented. See the benchmark results and non-coverage record before treating any feature claim as universal.