Autonomous AI agents, under your control.
Built for CISOs, security leads, and platform teams governing autonomous AI agents.
Your agents already take real actions — moving money, changing systems, emailing customers — faster than anyone can watch each one. Guardyx AI checks each consequential action against your rules first. It holds the exceptions for a human and records every decision before any of it happens. And it works with the agents you already run — no rewrites.
Every AI action passes through Guardyx.
Approval requested
Held for a human before it runs.
Agent
Sales Ops Bot
Tool
GMAIL_SEND_EMAIL
Payload
{
"to": "ALL-CUSTOMERS@list.acme.com",
"body": "Effective immediately, new Q3 pricing…"
}Policy
Bulk external email to a distribution list — approval required.
Your AI agents aren't just chatting anymore.
They've crossed the line from answering to acting — and they're doing it on their own, and fast. They email customers, move money, change production systems, and touch sensitive data without waiting for a human. An autonomous agent can take a high-impact action faster than anyone on your team can step in and stop it. That's new, and it's the part your current tooling wasn't built for.
It only takes one.
A few of the things a well-meaning agent can do on its own:
- Issue an out-of-policy refund or payment.
- Change or delete a production resource.
- Send confidential information to the wrong destination.
- Make an external commitment outside approved terms.
- Use a privileged tool or destination that policy should have blocked.
None of these is a bug you fix on Monday — each is an incident the moment it happens. And when it does, you're the one who has to explain how an agent was ever allowed to take that action.
You've already invested in security — this is a different gap.
You already run identity and access management (IAM), endpoint and cloud security, observability, and governance, risk, and compliance (GRC) tooling — and all of it is still essential. But each was built for people, applications, and infrastructure. None of them makes an action-by-action call on whether this agent should do thisthing right now. IAM decides who has access. Observability tells you what already happened. Guardyx AI decides — before the action runs.
| Existing control domain | What it does | What Guardyx adds |
|---|---|---|
| Identity and access management (IAM) | Controls who or what has access | Guardyx controls whether a specific agent action should execute right now. |
| Endpoint / network / cloud security | Protects infrastructure and access paths | Guardyx governs autonomous actions at runtime. |
| Observability / tracing | Shows what happened | Guardyx can stop, hold, or require approval before the action occurs. |
| Governance, risk and compliance (GRC) | Documents controls and evidence | Guardyx enforces runtime controls and produces evidence from actual agent activity. |
Identity and access management (IAM)
Controls who or what has access
Guardyx controls whether a specific agent action should execute right now.
Endpoint / network / cloud security
Protects infrastructure and access paths
Guardyx governs autonomous actions at runtime.
Observability / tracing
Shows what happened
Guardyx can stop, hold, or require approval before the action occurs.
Governance, risk and compliance (GRC)
Documents controls and evidence
Guardyx enforces runtime controls and produces evidence from actual agent activity.

“AI is taking over more of the decisions that used to be ours, and we're losing control of the ones that matter.”
Max C.H. Hwang · Founder, Guardyx AI
Read why I built Guardyx AIControl at the moment of action — not just a log afterward.
Stop the risky moves before they run.
Every consequential action is checked against your rules first; the risky ones are held or denied. Guardyx AI fails closed by default — if the policy check cannot complete, the action does not run.
Bring in a human only where it matters.
Exceptions wait for a sign-off; routine work just flows.
Keep the receipts.
A clean, complete record of what was allowed, blocked, or approved — for security, compliance, and your own peace of mind.
Keep it in your house.
Run Guardyx AI as hosted SaaS or self-hosted in your own VPC / on-prem, right next to the tools you already trust.
This is the screen your team operates.
Not a diagram — the real Guardyx AI approvals surface. Sensitive tool calls held before they run, each with its risk and the policy that stopped it.


Open any held action to see the agent, the payload, and the policy that stopped it — then approve or deny.

Clear the routine in one move: select a batch of low-risk actions and approve or deny together.
If AI risk lands on your desk, this one's for you.
Whether you're a CISO, a security or compliance lead, or the platform team wiring up agents at a company where tech supports the business (rather than being the business) — Guardyx AI is the control layer you've probably been wishing you had.
Pilot
A few internal agents / copilots
Establish least-privilege controls and audit from day one.
Production
Multiple teams, more tools, customer-facing or financial actions
Centralize policies, approvals, and evidence instead of building custom controls into every agent.
Enterprise
Many agents across departments and sensitive systems
Standardize runtime control across agent frameworks, teams, and high-risk workflows.
If you don't have agents in production or approaching it, or if your agents only draft text and never call a real tool, you probably don't need this yet.
Free to start
Start free — on your own, or with your team.
5,000 governed calls a month, connectors included, for up to 3 teammates and as many agents as you like. Every governance feature is in it. Nothing is held back for a paid plan.
- No card, no expiry — 5,000 governed calls a month, connectors included.
- Approvals, toolboxes, and a tamper-evident audit trail from day one.
- One bill for the tools your agents call and the control over them.
Find your world.
Sales Operations
Keep deals moving while off-policy discounts, commitments, and outbound stay behind a human sign-off.
Customer Support
Resolve tickets at volume while privacy risk, over-threshold refunds, and account changes route to a human.
Finance Workflows
Refunds, payments, and transfers get checked against your limits before the money moves.
Legal & Contract Workflows
Drafting and review run free; anything binding or disclosing waits for an attorney.
Internal Copilots
Every copilot action is checked against the real privileges of the person who triggered it.
Research Agents
Long autonomous runs stay boxed into approved tools and destinations, with every call traced.
DevOps Automation
Safe operations run automatically; destructive and production-changing commands wait for a human.
Every action takes a quick trip through your guardrails.
- 1Intercept
- 2Check it against policy
- 3Human sign-off if needed
- 4Run it
- 5Log it
No rewrites, no rip-and-replace — point your existing agents at Guardyx AI and you're off.
See the full platformPlays nicely with the agents you already run.
Native adapters for CrewAI, AutoGen, Google ADK, the OpenAI Agents SDK, the Anthropic Claude Agent SDK, and LangGraph, with LangChain tools governed through that same LangGraph adapter and raw OpenAI tool calling supported directly — plus hosted or self-hosted deployment in your own VPC or on-prem. Connect directly to ChatGPT or Claude desktop applications — no adapter needed. Every governed action becomes an auditor-ready evidence pack you can export.
Security & deploymentThe hard questions, answered.
Before your security team signs off, they'll ask. Here's where each answer lives — including the ones where we tell you what we don't do yet.
- What happens if the policy check itself fails?Guardyx AI fails closed by default — if the check cannot complete, the action does not run.
- Can the audit trail be quietly edited after the fact?No — it's a per-workspace tamper-evident hash chain, verified on demand and embedded in every evidence pack you export.
- Does our data have to leave our environment?No. Run Guardyx AI self-hosted in your own VPC or on-prem, right next to the tools it governs.
- Where does our data live today?In AWS US East (N. Virginia). We don't offer regional data residency options yet.
- What don't you do yet?We don't stream into a SIEM today — we'd rather say so than imply otherwise.
- How does this map to the frameworks we report against?Mapped to ISO/IEC 42001, the NIST AI RMF, and ISO/IEC 27001 Annex A, with the evidence produced on demand.

The receipt your auditor reads: every governed run, its policy decision, and the outcome — exportable as a tamper-evident evidence pack.
Give your agents room to run — and give yourself a good night's sleep.
Guardyx AI is in active development.
We're onboarding a small group of Enterprise design partners — free during the beta, with hands-on onboarding.
Every AI action passes through Guardyx.
What happens after signup
- 1Create your workspace.
- 2Complete guided setup for agent, tool, and policy.
- 3Run your first governed tool call.