Runtime enforcement boundary for AI agents: a local sidecar that gates every outbound call against Cedar policies you own. Deterministic, call-level, no model on the hot path
-
Updated
Sep 12, 2026 - Rust
Runtime enforcement boundary for AI agents: a local sidecar that gates every outbound call against Cedar policies you own. Deterministic, call-level, no model on the hot path
Open-source infrastructure for groups of AI agents — identity, capability, accountability, and norms. Framework-agnostic.
MCP server for Cedar policy language - validate, authorize, diff, and plan policy changes for Amazon Verified Permissions from your AI assistant.
Agent Run Config — an open specification for declaring, packaging, securing, and sharing portable, governed AI agents. Like a Dockerfile for agents: one reviewable Agentfile for identity, tools, boundaries, policy, and OCI packaging.
Wallet-side transaction and signature policy engine for Web3 signing safety
Tamper-evident audit trail for AI agent actions. An MCP gateway that enforces signed Cedar policies, proves who delegated what, and emits evidence packs an auditor can verify offline.
Cedar for .NET — a C#/.NET port of the Cedar Java bindings, enabling .NET applications to parse, validate, format, convert, and evaluate Cedar policies using the native Cedar engine.
Apache-2.0 licensed lightweight agent sandbox: Cedar policy + Ed25519-signed receipts in one Rust binary. Design-partner preview.
Deterministic, policy-as-code authorization for what an AI agent is allowed to do. Every tool call checked before it runs, logged after. A runnable reference build, not output guardrails. https://demo.sarthak-gupta.com
Open-source AI agent governance kernel — cryptographic audit trails, consent-checked data access, and verifiable decision records.
Vendor-neutral authorization for AI agents. Run the check inside the agent controls you already use (LlamaFirewall, NeMo Guardrails, FastMCP, A2A) and decide with the Policy-as-Code engine you already trust (OPA, Cedar, OpenFGA, or any AuthZEN PDP). One fail-closed allow/block/human-review verdict on every agent action.
Policy platform for AI agents: Cedar policy over network, filesystem, and process access. Container sandboxing with observe-then-enforce workflow.
The Zero-Trust Action Hub is a standalone, Zero-Trust Policy Decision Point (PDP) designed for autonomous AI agent ecosystems. It enforces cryptographic governance over high-risk agent actions using AWS Cedar policies and Ed25519 digital signatures, requiring agents to collect and present cryptographic proofs from trusted external microservices.
OpenAgentTrustStack (OATS) Specification
Local-first, zero-trust MCP security gateway and credential broker for AI agents. Deterministic Cedar authorization, JIT credential isolation, network sandboxing, and cryptographically signed DSSE evidence.
PaediatricClinic Spring Boot application to demonstrate Cedar.
Experimental trust and governance ideas for autonomous AI agents — captcha, permit, mesh, eval, memory.
Embeddable Cedar policy engine for Rust
Zero-trust API firewall and security integrity layer for autonomous AI agents & Model Context Protocol (MCP) tool execution. Secure, TOCTOU-proof, fail-closed.
To associate your repository with the cedar-policy topic, visit your repo's landing page and select "manage topics."