Skip to content
Kontext Security

Agent security. Enforced before execution.

Kontext applies identity-aware policy to AI agent actions.
Sandy contains AI coding agents with native macOS and Linux sandboxing.

Get started with Kontext · Documentation · Website

GitHub Stars Follow on X

Control what AI agents can do

AI agents can chain individually permitted operations into outcomes nobody intended.

Kontext gives agents a runtime identity, evaluates supported tool calls against policy, and blocks disallowed actions before they reach protected systems. Every decision produces evidence showing what the agent attempted, which policy applied, and why the action was allowed or denied.

brew install kontext-security/tap/kontext

View the Kontext repository →

Add process containment with Sandy

Sandy confines AI coding agents to explicitly permitted files, network destinations, and processes using native operating-system sandboxing on macOS and Linux.

brew install kontext-security/tap/sandy

View the Sandy repository →

Two complementary security layers

Layer Question it answers Project
Runtime authorization Should this supported agent action proceed under policy? Kontext
Process containment What can this agent process access on the machine? Sandy for macOS and Linux

Use them independently or together for defense in depth.

Open-source projects

Repository Description
kontext Identity-aware runtime policy enforcement for AI agents
sandy Native process containment for AI coding agents on macOS and Linux
agent-skills Skills and integrations for using Kontext with AI agents

Join the community

Pinned Loading

  1. kontext kontext Public

    Secure agents in seconds with permissions enforced at runtime.

    Go 212 7

Repositories

Showing 10 of 14 repositories

People

This organization has no public members. You must be a member to see who’s a part of this organization.

Top languages

Loading…

Most used topics

Loading…