Latch
Open-source security middleware for AI agents
Details
- External ID
- 46915813
- Source
- HN
- Company
- —
- Product
- Latch
- Website domain
- latchagent.com
- Launched
- Feb. 6, 2026
- Cohort
- —
- Upvotes
- 5
- Upvotes percentile
- 0.10512129380053908
- Tags
- —
- Fetched at
- Sept. 7, 2026, 9:26 p.m.
- Updated at
- Sept. 7, 2026, 9:26 p.m.
Description
Latch is an open-source proxy that sits between AI agents and the tools they use. It intercepts all tool calls and applies security policies in real-time:Safe operations pass through instantly. Risky operations require human approval via dashboard or Telegram. Dangerous operations are blocked completelyI built Latch to address the growing security risks of AI agents accessing critical systems. There have been 1,800+ exposed agent gateways discovered in the wild and recent security audits showing multiple vulnerabilities in agent frameworks, so this was motivated by the clear urgent need for better controls.Implementation is simple: a CLI wrapper around MCP servers that takes a few minutes to set up. You can do it through your dashboard or with quick command (npx @latchhq/cli wrap)Key features:Policy engine using natural language rules, or create rule-based policies by tool name, action class, or domain.Audit loggingTelegram integration for mobile approvalsThe project addresses what security researchers call the "lethal trifecta" - when AI agents have access to private data, process untrusted content, and can communicate externally. This creates a new attack vector traditional security tools don't address.I think the space is wide open and looking for contributors!GitHub: https://github.com/latchagent/latch Docs: https://latch.mintlify.app
Enrichment
- Theme
- AI agent frameworks and developer tools
- Vertical
- Security
- Function
- Compliance & governance
- Audience
- Developer
- AI stance
- AI feature
- Project type
- Hobby / open-source project
- Normalized one-liner
- security middleware for ai agents
- Manually corrected
- False
Could you build this?
Yes Building an API proxy/middleware in Node.js or Go that inspects JSON payloads against rule sets and sends Telegram or webhook alerts for human confirmation is a standard integration task.
Discussion
5 comments analyzed.
Competitors mentioned: openclaw
Concerns raised: hesitation to try due to fear/uncertainty
Feature requests: Slack integration, email notifications, additional notification channels
Competitors
Other products that read as similar to this one — 157 launches clear the similarity bar, closest 8 shown.
Attention rank: #152 of 158 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).
Launched 93 days after the earliest competitor.
- Latchkey · hn · 2026-02-03 · 12 upvotes · similarity 0.52
- Agent Vault · hn · 2026-04-22 · 156 upvotes · similarity 0.48
- GuardAgent · ph · 2026-09-21 · 2 upvotes · similarity 0.48
- FireClaw · hn · 2026-03-17 · 5 upvotes · similarity 0.46
- SentinelAgent Guard · ph · 2026-09-23 · 2 upvotes · similarity 0.44
- OpenAPPA · hn · 2026-09-28 · 23 upvotes · similarity 0.43
- Clay Seal Identity · hn · 2026-07-13 · 5 upvotes · similarity 0.43
- ClawSecure · ph · 2026-03-15 · 316 upvotes · similarity 0.42
Other launches for this product
- No other launches for this product.
Same idea, different domain
Nobody's really built a compliance & governance tool for Media & entertainment yet.