Nicheloom

Market intelligence for builders — see what's gaining traction before it's crowded.

OpenAPPA

open-source deterministic guardrails that don't break agents

Details

External ID
49877515
Source
HN
Company
—
Product
OpenAPPA
Website domain
openappa.com
Launched
Sept. 28, 2026
Cohort
—
Upvotes
24
Upvotes percentile
0.7559808612440191
Tags
—
Fetched at
Oct. 1, 2026, 1:01 a.m.
Updated at
Oct. 1, 2026, 1:01 a.m.

Description

Hi Hacker News! Matvey, one of the authors, is here.While building enterprise agents, we ran into a problem: the more tools you connect to the AI, the higher the chance it will run out of control and leak sensitive data.Guardrails, in theory, should prevent this, but the situation is worrying: - Non-deterministic guardrails (LLM as a judge, auto modes, etc.) are vulnerable to prompt injections, or they lack knowledge of the data, making them inefficient (~10% data leaks on our benchmarks). - Existing deterministic guardrails (Cedar, OPA, FIDES, Dogwood) require massive case-specific IF-ELSE-like policies and break agents (~59% utility loss on our benchmarks).We did something differently.We’ve taken the best of existing deterministic guardrails and built a policy language that is data-specific, not use-case specific. It lets you scale agents without updating a policy.On top of that, we’ve added multiple tricks (like a remedy plan or a DualLLM pattern) to help agents operate within those restrictions, raising utility from ~40% to ~90% and making it the first deterministic guardrail that doesn't break agents.Finally, we’ve designed it to be pluggable into any agent loop with pre- and post-tool-call hooks.We invite you to check out our benchmarks: https://www.openappa.com/evaluationPlay with it in Claude Code: https://www.openappa.com/claude-codeTry plugging it into your agent: https://www.openappa.com/add-to-agentOr check the academic paper: https://arxiv.org/abs/2607.24625We'd love to hear any feedback!

Enrichment

Theme
AI agent frameworks and developer tools
Vertical
Horizontal
Function
Compliance & governance
Audience
Developer
AI stance
AI-native
Project type
Hobby / open-source project
Normalized one-liner
open source guardrails for ai agents
Manually corrected
False

Could you build this?

No Building a deterministic, provably secure cross-tool data flow analysis engine resistant to prompt injection requires deep cybersecurity and formal language/security policy engineering.

What it would actually take: A proper implementation requires a dedicated engine (often written in Rust or Go) implementing dynamic information flow control (IFC) or taint analysis across arbitrary tool inputs and outputs. The hard parts are formally verifying non-interference without relying on probabilistic LLM judges, tracking data lineage across asynchronous multi-hop tool invocations, and designing sound policy DSLs (like Datalog or Cedar variants). It requires senior security researchers and static/dynamic program analysis experts.

Discussion

12 comments analyzed.

Competitors mentioned: aegis-devops

Concerns raised: Policy authoring at scale, Adoption challenges

Competitors

Other products that read as similar to this one — 336 launches clear the similarity bar, closest 8 shown.

Attention rank: #77 of 337 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).

Launched 329 days after the earliest competitor.

Other launches for this product

Same idea, different domain

Nobody's really built a compliance & governance tool for Media & entertainment yet.