Nicheloom

Market intelligence for builders — see what's gaining traction before it's crowded.

Latch

Open-source security middleware for AI agents

Details

External ID
46915813
Source
HN
Company
—
Product
Latch
Website domain
latchagent.com
Launched
Feb. 6, 2026
Cohort
—
Upvotes
5
Upvotes percentile
0.10512129380053908
Tags
—
Fetched at
Sept. 7, 2026, 9:26 p.m.
Updated at
Sept. 7, 2026, 9:26 p.m.

Description

Latch is an open-source proxy that sits between AI agents and the tools they use. It intercepts all tool calls and applies security policies in real-time:Safe operations pass through instantly. Risky operations require human approval via dashboard or Telegram. Dangerous operations are blocked completelyI built Latch to address the growing security risks of AI agents accessing critical systems. There have been 1,800+ exposed agent gateways discovered in the wild and recent security audits showing multiple vulnerabilities in agent frameworks, so this was motivated by the clear urgent need for better controls.Implementation is simple: a CLI wrapper around MCP servers that takes a few minutes to set up. You can do it through your dashboard or with quick command (npx @latchhq/cli wrap)Key features:Policy engine using natural language rules, or create rule-based policies by tool name, action class, or domain.Audit loggingTelegram integration for mobile approvalsThe project addresses what security researchers call the "lethal trifecta" - when AI agents have access to private data, process untrusted content, and can communicate externally. This creates a new attack vector traditional security tools don't address.I think the space is wide open and looking for contributors!GitHub: https://github.com/latchagent/latch Docs: https://latch.mintlify.app

Enrichment

Theme
AI agent frameworks and developer tools
Vertical
Security
Function
Compliance & governance
Audience
Developer
AI stance
AI feature
Project type
Hobby / open-source project
Normalized one-liner
security middleware for ai agents
Manually corrected
False

Could you build this?

Yes Building an API proxy/middleware in Node.js or Go that inspects JSON payloads against rule sets and sends Telegram or webhook alerts for human confirmation is a standard integration task.

Discussion

5 comments analyzed.

Competitors mentioned: openclaw

Concerns raised: hesitation to try due to fear/uncertainty

Feature requests: Slack integration, email notifications, additional notification channels

Competitors

Other products that read as similar to this one — 157 launches clear the similarity bar, closest 8 shown.

Attention rank: #152 of 158 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).

Launched 93 days after the earliest competitor.

Other launches for this product

Same idea, different domain

Nobody's really built a compliance & governance tool for Media & entertainment yet.