Skip to content
G

GUARDYX AI

The Runtime Control Layer for Autonomous AI

Autonomous AI agents, under your control.

Built for CISOs, security leads, and platform teams governing autonomous AI agents.

Your agents already take real actions — moving money, changing systems, emailing customers — faster than anyone can watch each one. Guardyx AI checks each consequential action against your rules first. It holds the exceptions for a human and records every decision before any of it happens. And it works with the agents you already run — no rewrites.

Every AI action passes through Guardyx.

Approval requested

Held for a human before it runs.

high riskpending

Agent

Sales Ops Bot

Tool

GMAIL_SEND_EMAIL

Payload

{
  "to": "ALL-CUSTOMERS@list.acme.com",
  "body": "Effective immediately, new Q3 pricing…"
}

Policy

Bulk external email to a distribution list — approval required.

Your AI agents aren't just chatting anymore.

They've crossed the line from answering to acting — and they're doing it on their own, and fast. They email customers, move money, change production systems, and touch sensitive data without waiting for a human. An autonomous agent can take a high-impact action faster than anyone on your team can step in and stop it. That's new, and it's the part your current tooling wasn't built for.

It only takes one.

A few of the things a well-meaning agent can do on its own:

  • Issue an out-of-policy refund or payment.
  • Change or delete a production resource.
  • Send confidential information to the wrong destination.
  • Make an external commitment outside approved terms.
  • Use a privileged tool or destination that policy should have blocked.

None of these is a bug you fix on Monday — each is an incident the moment it happens. And when it does, you're the one who has to explain how an agent was ever allowed to take that action.

You've already invested in security — this is a different gap.

You already run identity and access management (IAM), endpoint and cloud security, observability, and governance, risk, and compliance (GRC) tooling — and all of it is still essential. But each was built for people, applications, and infrastructure. None of them makes an action-by-action call on whether this agent should do thisthing right now. IAM decides who has access. Observability tells you what already happened. Guardyx AI decides — before the action runs.

  • Identity and access management (IAM)

    Controls who or what has access

    Guardyx controls whether a specific agent action should execute right now.

  • Endpoint / network / cloud security

    Protects infrastructure and access paths

    Guardyx governs autonomous actions at runtime.

  • Observability / tracing

    Shows what happened

    Guardyx can stop, hold, or require approval before the action occurs.

  • Governance, risk and compliance (GRC)

    Documents controls and evidence

    Guardyx enforces runtime controls and produces evidence from actual agent activity.

See where Guardyx AI fits in your control stack
Max C.H. Hwang, founder of Guardyx AI.
“AI is taking over more of the decisions that used to be ours, and we're losing control of the ones that matter.”

Max C.H. Hwang · Founder, Guardyx AI

Read why I built Guardyx AI

Control at the moment of action — not just a log afterward.

Stop the risky moves before they run.

Every consequential action is checked against your rules first; the risky ones are held or denied. Guardyx AI fails closed by default — if the policy check cannot complete, the action does not run.

Bring in a human only where it matters.

Exceptions wait for a sign-off; routine work just flows.

Keep the receipts.

A clean, complete record of what was allowed, blocked, or approved — for security, compliance, and your own peace of mind.

Keep it in your house.

Run Guardyx AI as hosted SaaS or self-hosted in your own VPC / on-prem, right next to the tools you already trust.

This is the screen your team operates.

Not a diagram — the real Guardyx AI approvals surface. Sensitive tool calls held before they run, each with its risk and the policy that stopped it.

The Guardyx AI approvals queue: pending agent tool calls such as GMAIL_SEND_EMAIL and NOTION_CREATE_PAGE, each tagged high or critical risk and held for a human to review before they run.
An approval's detail panel in Guardyx AI: the agent, the tool it called, the request payload, and the policy that required review, with approve and deny actions and the recorded outcome.

Open any held action to see the agent, the payload, and the policy that stopped it — then approve or deny.

Batch review in Guardyx AI: several low-risk email actions selected together, with controls to approve or deny all of them at once.

Clear the routine in one move: select a batch of low-risk actions and approve or deny together.

If AI risk lands on your desk, this one's for you.

Whether you're a CISO, a security or compliance lead, or the platform team wiring up agents at a company where tech supports the business (rather than being the business) — Guardyx AI is the control layer you've probably been wishing you had.

Pilot

A few internal agents / copilots

Establish least-privilege controls and audit from day one.

Production

Multiple teams, more tools, customer-facing or financial actions

Centralize policies, approvals, and evidence instead of building custom controls into every agent.

Enterprise

Many agents across departments and sensitive systems

Standardize runtime control across agent frameworks, teams, and high-risk workflows.

If you don't have agents in production or approaching it, or if your agents only draft text and never call a real tool, you probably don't need this yet.

Free to start

Start free — on your own, or with your team.

5,000 governed calls a month, connectors included, for up to 3 teammates and as many agents as you like. Every governance feature is in it. Nothing is held back for a paid plan.

  • No card, no expiry — 5,000 governed calls a month, connectors included.
  • Approvals, toolboxes, and a tamper-evident audit trail from day one.
  • One bill for the tools your agents call and the control over them.

Find your world.

Every action takes a quick trip through your guardrails.

  1. 1Intercept
  2. 2Check it against policy
  3. 3Human sign-off if needed
  4. 4Run it
  5. 5Log it

No rewrites, no rip-and-replace — point your existing agents at Guardyx AI and you're off.

See the full platform

Plays nicely with the agents you already run.

Native adapters for CrewAI, AutoGen, Google ADK, the OpenAI Agents SDK, the Anthropic Claude Agent SDK, and LangGraph, with LangChain tools governed through that same LangGraph adapter and raw OpenAI tool calling supported directly — plus hosted or self-hosted deployment in your own VPC or on-prem. Connect directly to ChatGPT or Claude desktop applications — no adapter needed. Every governed action becomes an auditor-ready evidence pack you can export.

Security & deployment

The hard questions, answered.

Before your security team signs off, they'll ask. Here's where each answer lives — including the ones where we tell you what we don't do yet.

Read the full security posture

Give your agents room to run — and give yourself a good night's sleep.

Guardyx AI is in active development.

We're onboarding a small group of Enterprise design partners — free during the beta, with hands-on onboarding.

Every AI action passes through Guardyx.

What happens after signup

  1. 1Create your workspace.
  2. 2Complete guided setup for agent, tool, and policy.
  3. 3Run your first governed tool call.
Engineers on your team? Here are the docs
or
Create an account