Runtime authorization

Every agent actiongets a decision.

ALLOW, REVIEW, or BLOCK before the action runs, with the score, the reasons, and an audit row that is already written.

  • ALLOW
  • REVIEW
  • BLOCK
Launch · October 20, 2026

How it works

The verdict comes first.

Vulnify sits in front of the sensitive tool call. It sees who is acting, which action, where it goes, and how many records. Not the records.

  1. 01

    The agent proposes

    One call carries the agent, the action, the destination, and a count. The payload never leaves your side.

  2. 02

    Policy decides

    A score from 0 to 100 becomes ALLOW, REVIEW, or BLOCK, with the reasons that produced it.

  3. 03

    The action follows

    ALLOW runs. REVIEW waits for a different person. BLOCK never starts. The audit row is already written.

If Vulnify is unreachable, the action does not run, unless you choose fail open. It is not a scanner, not an antivirus, and not a prompt filter.

The product

In front of the tool call, start to finish.

Decision feed

Every action, with the reason attached.

The feed shows what each agent tried to do, the score it got, and the sentence that explains the verdict. Nothing is a black box.

  • An explainable score from 0 to 100.
  • Reasons on every verdict, not just the blocks.
  • Monitor mode records the verdict and stops nothing yet.

Policies as code

The policy lives in your repository.

The CLI pulls one YAML file per policy, applies the files you changed, and runs the cases. Review a decision rule the way you review code.

  • pull, apply, and test against /v1/policies.
  • apply --dry-run plans the change and writes nothing.
  • test --local exits 1 on a failing case, so CI can gate it.

Audit

The proof is written before the action.

Each decision appends a row that is hash-chained to the one before it. A blocked action never runs, and the evidence is already written.

  • Append-only and hash-chained per organization.
  • Verify the chain from inside the app.
  • Download the audit log as JSON or CSV.

Reviews

REVIEW waits for a different person.Beta

A review lands where the team already is. Approve or deny from the alert, and the action runs once or never starts.

  • Approve or deny from the Slack alert.
  • An incoming webhook posts alerts and does not approve.
  • A high-risk approval can ask for a fresh MFA code.

For developers

One call. Before the action.

Wrap the sensitive tool call. Vulnify answers with a decision, a score, and the reasons. The action runs, waits for a person, or never starts.

  • npm install @vulnify/sdk and pip install vulnify.
  • A test key decides inside a sandbox.
  • Webhook deliveries are signed with HMAC-SHA256.
import { Vulnify } from '@vulnify/sdk';

const vulnify = new Vulnify({
  apiKey: process.env.VULNIFY_API_KEY,
});

await vulnify.guard(
  {
    agent: 'sales-copilot',
    action: 'EXPORT_DATA',
    resource: 'crm.contacts',
    destination: 'EXTERNAL_EMAIL',
    recordsAffected: 48120,
  },
  () => exportContacts(),
);

BLOCKResponse · 91 / 100

{
  "decision": "BLOCK",
  "riskScore": 91,
  "reasons": [
    "Bulk export of personal data",
    "Destination outside the policy"
  ]
}

Trust

Metadata crosses the boundary. Contents do not.

Vulnify stores the action, the score, the policy, and the reviewer. It does not store the records, and this site does not claim a certification.

Pricing

The prices are on the page.

Developer is free. Team and Business are a monthly price in USD. Enterprise is a conversation. No annual plan, and no overage charge.

See pricing

Design partners

For teams already shipping agents.

Three months at no charge, in exchange for weekly feedback and a direct line to the people building Vulnify.