Nicheloom

Market intelligence for builders — see what's gaining traction before it's crowded.

Policy enforcement for Claude Code, Cursor, and Codex

Details

External ID
48847526
Source
HN
Company
—
Product
Policy enforcement for Claude Code, Cursor, and Codex
Website domain
kastra.ai
Launched
July 9, 2026
Cohort
—
Upvotes
13
Upvotes percentile
0.6200716845878136
Tags
—
Fetched at
Sept. 7, 2026, 9:26 p.m.
Updated at
Sept. 7, 2026, 9:26 p.m.

Description

Show HN: Runtime authorization for Claude Code, Cursor, and CodexHi HN, Fernando and I built Kastra. Kastra intercepts AI agent tool calls and evaluates them against deterministic policies before they execute. This is aimed at developers using coding agents like Claude Code, Codex, Cursor, and OpenClaw.We built Kastra after one of our Cursor agents almost executed DELETE FROM customers WHERE status='test' against a production database. We caught it before it ran, but it made us realize that nothing in our stack actually decided what the agent was allowed to do. What mattered for us wasn't the mistake; it was realizing nothing in our setup would have stopped it if we weren't actively on top of it. LLMs are probabilistic, and prompts influence behavior, but they don't deterministically decide what an agent is allowed to do. Without a deterministic policy system, nothing could have decided what it was allowed to do.Kastra pushes an allow, hold, and deny decision before the action runs. You can build these policies in plain English from the web app. The interception engine evaluates the tools, targets, and parameters of every action. We also shipped many policy packs covering common high-risk scenarios, and every decision is recorded in an immutable audit trail. The desktop app, CLI, dashboard, and Recon scan are free to use for developers.If you often use Claude, Codex, Openclaw, and Cursor, Kastra can run a scan command on which risky actions your agents have already taken and automatically build rules to avoid them from happening again. Recon is a feature of Kastra that scans your local agent history. In order to run this scan, execute the commands below in your coding agent.brew install kastra-labs/tap/kastra-edgekastra-edge scanThe scan reads your local agent session history, and it shows all the risky actions your agent has already taken before, the secrets written to tracked files, production databases touched, force pushes, curl-to-shell, and more. This runs on your machine, and secrets never leave. In our own use cases, we kept finding things we'd forgotten or didnt know agents had done.Each finding can be converted into a runtime policy, letting you delegate more work to AI without trusting the model itself. Kastra intercepts all workloads at runtime and makes sure these policy evaluations typically complete in under a millisecond. Instead of trusting the model, you trust the deterministic rules that govern its actions.One problem we are still working on to improve the stack is how to manage teams of agents with conflicting policies. We would love feedback from anyone building multi-agent systems. Fernando and I will be reviewing the comments. We are super curious what your first scan finds. Please post results below so we can see what the most common patterns are and adjust policy packs for our users based on your feedback.Documentation: https://kastra.ai/docsDownload for MacOS Kastra Edge: https://kastra.ai/edge/download.htmlCheck Kastra in action today: https://www.youtube.com/watch?v=6TUETu5lb3Q&feature=youtu.be

Enrichment

Theme
AI agent frameworks and developer tools
Vertical
Security
Function
Compliance & governance
Audience
Developer
AI stance
AI feature
Project type
Commercial product
Normalized one-liner
policy enforcement for ai code editors
Manually corrected
False

Could you build this?

Partial Building an API proxy or local shim to intercept LLM tool calls is easy, but sub-millisecond deterministic policy evaluation and zero-trust security audit guarantees across varied IDEs/agents require advanced security engineering.

What it would actually take: The stack typically uses a high-performance proxy/interceptor written in Rust or Go integrated with a deterministic policy engine like Open Policy Agent (Rego) or Cedar. The hard parts are achieving sub-millisecond evaluation latency, hooking cleanly into heterogeneous AI agent environments (local CLI, Cursor plugins, remote MCP servers), and cryptographically signing tamper-proof audit trails. This requires experienced security infrastructure engineers knowledgeable about enterprise access control paradigms.

Discussion

5 comments analyzed.

Competitors mentioned: AWS IAM, Cursor

Concerns raised: AI probabilistic nature makes it unsuitable for final authorization decisions, Risk of agents executing destructive production queries, Latency introduced by policy enforcement layers, Difficulty managing disagreements between agents

Feature requests: Sandboxed execution environments for agents and orchestrators, Agent-specific short-lived credentials, Multi-pass validation with agent quorum oversight, Deterministic authorization separate from model decisions

Competitors

Other products that read as similar to this one — 366 launches clear the similarity bar, closest 8 shown.

Attention rank: #159 of 367 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).

Launched 245 days after the earliest competitor.

Other launches for this product

Same idea, different domain

Nobody's really built a compliance & governance tool for Media & entertainment yet.