
LOCAL-FIRST · SUB-100MS · FAIL-CLOSED
Put a hard boundary in front of your AI agents.
Belay sits at the tool-call boundary of your AI coding agents and blocks the dangerous ones — secret exfiltration, rm -rf, reverse shells — before they run. It asks you about the gray areas and never lets a single misstep wreck your host, in under 100 milliseconds, with no LLM in the decision path.
Detect · Block · Notify — a defense and monitoring layer for AI coding agents.
Direct downloads: Apple SiliconIntel MacWindowsLinux .debAppImage
curl -fsSL https://dl.belay.secblok.io/install.sh | bashTHE 75-SECOND TOUR
Watch it stop an agent mid-attack.
A real session — from detecting the agents on your machine to blocking a live tool call, with the verdict on screen in milliseconds.
LIVE
Every tool call, judged in real time.
The Overview is your posture at a glance: everything monitored, everything approved, and everything blocked — counted live as your agents work.

DENY
The calls that should never run, don’t.
Destructive commands, secret reads, reverse shells, prompt-injection markers — matched deterministically against a compiled rule catalog and stopped at the boundary, before the call ever runs. No model in the hot path, so the same call always gets the same verdict.

ASK
Approve the gray-area calls from your phone.
Not every call is clear-cut. When one is ambiguous-but-risky, Belay pauses the agent and pings you for a one-tap Allow or Deny — in your terminal, or over Telegram, Discord, WhatsApp, Slack, Matrix, and more. Don’t answer in time? It denies.
Two-way approvals · pairing-code enrolment · a stale prompt auto-denies.

BEYOND THE AGENT
A native firewall, quarantine, and a tamper-evident log.
Host control ships built in, in pure Rust — a native firewall, a bundled vulnerability database with CISA KEV and EPSS badges, and honeypot canaries. Every verdict lands in a hash-chained audit log you can prove was never touched.

60 SECONDS
Scan, protect, done.
One installer detects the agents you already run and wires in the right way for each — running as you, never root. Scan code before you install it, then flip protection on.
belay detectFinds the AI coding agents already on your machine and flags the risky settings they run with.belay protect <agent>Wires Belay in at the tool-call boundary. Start with --observe to tune, then switch to enforcing.belay serveRuns the local backend the desktop app reads — posture, activity, and a live feed with one-click Allow/Deny.

WORKS WITH
Detects and protects the agents you already run.
Belay auto-detects the AI coding agents already on your machine. Claude Code and Codex get native PreToolUse/PostToolUse hooks; anything that speaks MCP — including Hermes and OpenClaw — gets wrapped so its tool calls are gated too.
Claude Code
Codex
Hermes
OpenClawProduct names and logos are trademarks of their respective owners.
GET PROTECTED
Put the boundary up before your next session.
Free and open source under AGPL-3.0. Local-first, and it never phones home.
Direct downloads: Apple SiliconIntel MacWindowsLinux .debAppImage
