License delivery vault

Your license. Your tools. One secure vault.

Activate the key, confirm authorized scope, and download the permanent package included with your purchase.

Private customer delivery

Keep the Stripe receipt. License recovery requires the purchase email and payment evidence.

Payment is verified before delivery.

Private license key

Authorization-first scan intake

Raw secret redaction

Permanent delivered files

One year of updates

Access recovery

Lost the license email?

Request a private delivery resend with the purchase email and Stripe receipt reference. CapitalGuard verifies the payment record before any key is resent.

The browser never displays the plaintext license key. Recovery sends private delivery only to the verified purchase email.

Permanent customer kit

Everything needed to start safely.

Verified customer access

Unlock your permanent customer kit.

Use the purchase email and license key sent after verified payment. Credentials remain in this browser tab only.

Quick-start guide

A concise installation, local-scan, authorization, and licensed-workflow guide for the customer team.

Complete license kit

Quick start, package entitlements, license terms, fulfillment standard, scan intake, safe-use guide, Update Trust verifier and pinned root, Agent Surface Compiler, Privilege Diff, Security Flight Recorder, default-deny policy evaluator, Agent Action Gateway, Context Provenance Gate, Runtime Sequence Firewall, Sensitive Egress Gate, Economic Action Firewall, Agent Intent Firewall, Agent Delegation Firewall, MCP Integrity Gate, Memory Integrity Firewall, Adaptive Attack Lab, Workspace Integrity Ledger, Enforced Mode, Agent Change Gate, Managed Session Supervisor and kill switch, Agent Identity Gate, Reviewable AutoFix, signed Risk Chronicle, guardrail installer, and delivery checklist.

Update Trust 0.1 verifier

A self-contained, offline verifier with an embedded pinned root that checks signed role thresholds, freshness, release consistency, rollback state, and exact artifact bytes before installation.

Update Trust 0.1 pinned root

The exact 2-of-3 signed bootstrap root delivered with the licensed verifier for independent custody and digest comparison.

Update Trust operating guide

Bootstrap, metadata refresh, external state-anchor, artifact verification, key-custody, and residual-risk instructions for Update Trust 0.1.

Package entitlement manifest

The exact Starter, Pro, and Agency deliverables, access paths, update window, and scan allowances.

Commercial license summary

Permanent internal-use rights, customer responsibilities, boundaries, and the enterprise replacement path.

License certificate template

The permanent internal-use rights and delivery terms included with the verified purchase certificate.

Fulfillment standard

Delivery standards for license issuance, scan-start criteria, reports, and monitored scope.

Secure scan intake

Authorization-first intake that keeps repository scanning defensive, traceable, and controlled.

AI-agent policy pack

Starter guardrails for blocked files, protected paths, human approvals, and redaction.

Policy Language 0.1 evaluator

Deterministically returns allow, redact, approve, simulate, or block decisions from privacy-safe request metadata. It does not intercept runtime operations.

Default-deny policy baseline

A versioned starter policy with stable control IDs, strict request shapes, and a fail-closed default decision.

Agent Action Gateway 0.1

A fail-closed local gate for routed file, command, and metadata-only network operations with one-time approval leases and a tamper-evident event chain.

Context Provenance Gate 0.1

Signs privacy-reduced context graphs, derives conservative trust instead of accepting caller claims, binds exact review approvals, rejects replay, and routes the derived request through Agent Action Gateway.

Context Provenance Gate operating guide

The protected key-isolation, manifest, selection, exact review, authorization, gateway execution, state-anchor, privacy, and residual-boundary workflow.

Runtime Sequence Firewall 0.1

Atomically carries privacy-safe taint across routed operations and blocks credential exfiltration, sensitive-data transfer, untrusted control mutation, privilege-expansion chains, and runaway loops before the terminal action.

Runtime Sequence Firewall operating guide

The protected key-isolation, exact exception, signed reset, external state-anchor, integration, privacy, and residual-boundary workflow.

Sensitive Egress Gate 0.1

Inspects exact outbound file-write, command, MCP, and network fields in memory, blocks fixed high-confidence credential classes, fails closed on uninspectable payloads, and emits a signed receipt without raw values.

Sensitive Egress Gate operating guide

Authority-key setup, exact request binding, offline inspection, signed receipt verification, incident response, privacy, and residual-boundary instructions.

Economic Action Firewall 0.1

Binds an exact one-use human approval to a protected MCP economic action, atomically reserves configured budget before provider invocation, rejects replay, and conservatively accounts for uncertain outcomes.

Economic Action Firewall authority CLI

Creates isolated signing authorities, signed action registries, privacy-reduced action records, exact approvals, and offline verification evidence for Economic Action Firewall 0.1.

Economic Action Firewall operating guide

Authority isolation, signed registry, exact approval, atomic budget, MCP composition, uncertain-outcome, receipt verification, privacy, and residual-boundary instructions.

Agent Intent Firewall 0.1

Enforces a threshold-signed, actor-bound, task-bound, session-bound execution graph with exact operation selectors, prerequisite order, bounded uses, replay refusal, and atomic pre-invocation reservation.

Agent Intent Firewall authority CLI

Creates isolated authorities and closed execution contracts, collects independent signatures, and verifies contracts, receipts, signed state, and external anchor continuity.

Agent Intent Firewall operating guide

Threshold-authority isolation, objective-digest, closed-DAG, exact-selector, runtime-composition, uncertain-outcome, recovery, privacy, and residual-boundary instructions.

Secretless Execution Broker 0.1

Keeps reusable provider credentials outside the repository and agent runtime, compiles only exact capability-bound HTTPS requests, blocks replay and credential reflection, and returns an allowlisted response projection.

Secretless Execution authority CLI

Creates isolated authorities and keys, signs closed provider registries, issues short-lived one-use capabilities, and verifies registry and capability bindings offline.

Secretless Execution Broker operating guide

Vault separation, provider-registry, capability, response-projection, uncertain-outcome, Agent Intent, Enforced Mode, recovery, privacy, and residual-boundary instructions.

Data Boundary Firewall 0.1

Applies a signed default-deny destination policy and deterministic block, redact, or one-way tokenization controls to exact broker payloads before any transformed request can be re-authorized.

Data Boundary Firewall authority CLI

Creates isolated policy and fingerprint authorities, derives owner-designated value fingerprints, signs and verifies policies, inspects exact payloads, and verifies privacy-reduced receipts.

Data Boundary Firewall operating guide

Destination policy, deterministic detector, HMAC fingerprint, signed selector, transformed-request reauthorization, privacy, and residual-boundary instructions.

Agent Delegation Firewall 0.1

Issues target-bound, policy-bound, task-bound, single-use delegation chains that cannot amplify or fan out a parent agent's authority.

MCP Integrity Gate 0.1

Pins signed MCP server and tool inventories, blocks identity or schema drift, approval-gates side effects, and quarantines untrusted result content outside agent context.

Agent Memory Integrity Firewall 0.1

Encrypts, signs, scopes, expires, revisions, and revokes approved durable memory while keeping retrieval, model, and MCP open text outside the instruction channel.

Memory Integrity approval policy

A default-deny Policy Language rule requiring one exact Agent Action Gateway approval for every durable memory commit or revocation.

Enforced Mode 0.7 broker

Creates policy-filtered workspaces and routes every authenticated task-bound operation through a full-hash workspace check before authority, host-derived provenance, data controls, sequence enforcement, the Agent Action Gateway, and signed Agent Change quarantine for file writes.

Enforced Mode 0.7 launcher

A fail-closed plan and run CLI requiring a digest-pinned image, supported OCI runtime, five separate owner-only signing authorities, signed data, workspace, and Agent Change policies, and isolated fingerprint keys.

Enforced Mode MCP bridge

Routes file, command, network, MCP, and handoff requests from the contained session to the authenticated CapitalGuard broker.

Enforced Mode MCP configuration

A minimal MCP server configuration for the contained CapitalGuard bridge.

Enforced Mode 0.7 operator guide

Authority and policy setup, workspace baseline and retained anchor, plan and run commands, task binding, transformed-request reauthorization, signed write quarantine, separate review, fail-closed recovery, and the exact protection boundary for the unified runtime trust chain.

Workspace Integrity Ledger 0.1

Creates signed full-hash repository checkpoints, detects exact in-scope drift, rejects unsafe filesystem ambiguity, and binds immutable history to a separately retained rollback anchor.

Workspace Integrity authority CLI

Creates separate gate and reviewer authorities, signs bounded policies, initializes and verifies baselines, issues exact expiring one-use approvals, reconciles reviewed drift, and verifies signed receipts.

Workspace Integrity operating guide

Key isolation, signed policy, full-hash verification, retained-anchor custody, privacy-reduced drift review, exact approval, recovery, and residual-boundary instructions.

Agent Change Gate 0.1

Quarantines exact UTF-8 file-write candidates outside the repository, binds signed evidence to exact preimages and session state, and applies approved changes atomically without granting direct agent write authority.

Agent Change Gate authority CLI

Creates separate gate and reviewer authorities, signs repository policies, stages candidates, issues exact expiring one-use approvals, and applies approved change sets with replay and preimage checks.

Agent Change Gate operating guide

Gate and reviewer key separation, signed policy, quarantine review, exact approval, atomic apply, recovery, privacy, and residual-boundary instructions.

Personal AI Safety 0.1

Runs local deterministic scam-signal, sensitive-data preflight, AI-account, connector, and risky-action checks and produces privacy-reduced signed evidence without declaring content safe or fraudulent.

Personal AI Safety command line

Creates an isolated local authority, signs a bounded safety policy, assesses supported personal AI risks, redacts supported sensitive values, and verifies signed reports offline.

Personal AI Safety operating guide

Plain-language setup, independent verification, sensitive-data preflight, AI-account hygiene, connector reduction, default-deny action rules, privacy, and protection-boundary instructions.

AccessGraph standard

The CapitalGuard action-to-asset model, Guardprint semantics, privacy boundary, and responsible claim standard.

Attack Lab runner

Runs nine non-destructive architecture-aware control challenges and retains exposed categories as local regression checks.

Adaptive Attack Lab 0.1

Runs six authorized, deterministic multi-turn scenarios against bundled synthetic profiles, then signs the hash-chained transcript, before/after comparison, and retained regression pack.

Agent Surface Compiler 0.1

Locally compiles supported workflow, MCP, agent, tool, model, handoff, instruction, secret-category, and CODEOWNERS declarations into private and shareable inventories, a CapitalGuard A-BOM, and one signed integrity receipt without executing repository code or using the network.

Privilege Diff 0.1

Verifies two exact signed Agent Surface snapshots, classifies declared authority expansion and control loss, fails closed on evidence degradation, and emits a deterministic CI decision with signed private and shareable evidence.

Privilege Diff operating guide

The protected baseline, candidate, key-isolation, CI exit-code, exact acknowledgement, and signed-evidence workflow for Privilege Diff 0.1.

Security Flight Recorder 0.1

Locally records privacy-reduced, pseudonymous agent activity in a tamper-evident chain with searchable attribution, retention receipts, evidence-only replay, and Ed25519-signed exports.

Managed Session Supervisor 0.1

Authenticates exact-session stop requests, initiates Enforced Mode broker shutdown before termination, records the closure outcome, rejects replay, and binds privacy-reduced lifecycle evidence to the supervised session.

Managed Session run, stop, and status CLI

Launches supervised Enforced Mode sessions and provides session-bound stop and signed-status commands without exposing an arbitrary PID kill path.

Agent Security License 1.0

Issues owner-controlled Ed25519 agent security licenses with signed revocation history and short-lived proofs bound to the exact authenticated Enforced Mode and Managed Session launch.

Agent Security License operating guide

A concise owner workflow for authority isolation, enrollment, license issuance, revocation, exact selector creation, verification, and authenticated managed launch.

Reviewable AutoFix 0.1

Proposes ten bounded configuration remediations with exact preimage binding, separate one-time apply, verify, and rollback approvals, template retests, and no automatic commits or repository execution.

Risk Chronicle 0.1

Creates customer-signed fresh-evidence recalculation requests and verifies CapitalGuard-signed append-only score history while persistent records retain only aggregate remediation and runtime evidence.

GitHub regression workflow

A least-privilege pull-request, manual, and scheduled workflow for the redacted local scanner and retained Attack Lab checks.

Local guardrail installer

Writes local policy declarations and the defensive scanner without uploading repository code, printing secret values, or claiming runtime interception.

Safe-use guide

Practical operating rules for teams using AI coding tools with repository access.

Delivery checklist

The fulfillment and operating checklist for every paid CapitalGuard license.

Every download re-verifies the active license and purchase email. License keys are hashed for normal lookup and are never placed in a download URL.

Exact package scope

Every promised entitlement, in writing.

Starter License

Local Personal AI Safety plus one authorized repository

1 repo scan

CapitalGuard Risk Score

AccessGraph snapshot and top findings

A-BOM and tamper-evident scan chain

Official Risk Score, signed AI Agent Security License record, and public verification URL

Print-ready report with PDF export

Local guardrail installer

Default-deny Policy Language 0.1 evaluator

Agent Action Gateway 0.1 local runtime gate

Sensitive Egress and Data Boundary firewalls with pre-adapter blocking, redaction, and one-way tokenization

Single-use Agent Delegation Firewall 0.1

Signed MCP Integrity Gate 0.1 inventory lock and output quarantine

Economic Action Firewall 0.1 exact approval and budget gate

Agent Intent Firewall 0.1 threshold-signed execution contract

Agent Memory Integrity Firewall 0.1 with retrieval quarantine

Adaptive Attack Lab 0.1 signed multi-turn regression kit

Agent Surface Compiler 0.1 private inventory and signed A-BOM

Privacy-reduced Security Flight Recorder 0.1 with signed evidence

Enforced Mode 0.7 unified runtime trust chain with full-hash workspace verification before authority

Workspace Integrity Ledger 0.1 signed full-hash baseline and exact drift approval

Agent Change Gate 0.1 signed quarantine and exact one-use review

Personal AI Safety 0.1 for scam signals, sensitive-data preflight, account checks, connectors, and risky AI actions

Managed Session Kill Switch 0.1 for supervised Enforced Mode sessions

Reviewable AutoFix 0.1 with ten bounded remediation templates

Signed Risk Chronicle 0.1 score history and fresh-evidence recalculation

Update Trust 0.1 threshold-signed artifact verification

One year of updates

Pro License

Five authorized repository scans

5 repo scans

AccessGraph change history and license console

Versioned A-BOM and event-chain evidence

Policy generator

Deterministic Policy Language 0.1 evaluator

Agent Action Gateway with signed approval leases

Sensitive Egress and Data Boundary firewalls with signed privacy-safe receipts

Cryptographically attenuated multi-agent delegation chains

MCP Integrity Gate with side-effect approvals and closed-data output

Economic Action Firewall with atomic budgets and uncertain-outcome refusal

Agent Intent Firewall with closed DAG, exact selectors, and runtime receipt binding

Memory Integrity Firewall with signed scope, expiry, and revocation

Adaptive multi-turn Attack Lab with signed before/after comparison

Agent Surface Compiler topology, ownership, permissions, and signed shareable evidence

Searchable Security Flight Recorder with retention and Ed25519 evidence export

Enforced Mode 0.7 with full-hash workspace verification, authenticated broker, provenance, data controls, sequence firewall, Agent Change quarantine, and MCP bridge

Workspace Integrity Ledger with two-pass full hashing, rollback anchors, and separate reviewer approval

Agent Change Gate with exact preimage binding, separate reviewer key, one-use approval, and atomic apply

Personal AI Safety for scam signals, sensitive-data preflight, AI-account identity, connector exposure, and protected actions

Authenticated Managed Session Supervisor with signed stop evidence

Signed Reviewable AutoFix plans, retests, and exact rollback

Risk Chronicle with signed remediation and runtime evidence summaries

Update Trust 0.1 threshold-signed artifact verification

Print-ready executive report

Remediation checklist

Signed AI Agent Security License record after completed review

One year of updates

Agency License

Twenty-five authorized repository scans

25 repo scans

Client AccessGraph portfolio

Client A-BOM and tamper-evident scan evidence

Client policy evaluation kit with stable control IDs

Client runtime-gate kit with replay-protected approvals

Client Sensitive Egress and Data Boundary Firewall deployment and receipt-verification kit

Client Agent Delegation Firewall deployment kit

Client MCP Integrity Gate deployment kit

Client Economic Action Firewall deployment and verification kit

Client Agent Intent Firewall authority, deployment, and verification kit

Client Memory Integrity Firewall deployment kit

Client-safe adaptive Attack Lab deployment and regression kit

Client-safe Agent Surface Compiler inventory, A-BOM, and signed receipt kit

Client-safe Flight Recorder audit, retention, and signed evidence kit

Client Enforced Mode 0.7 deployment kit with full-hash workspace verification and signed write quarantine

Client Workspace Integrity authority, reviewer, signed-baseline, drift, recovery, and evidence kit

Client Agent Change Gate policy, reviewer, quarantine, approval, and signed evidence kit

Client Personal AI Safety deployment kit for scam, data, identity, connector, and AI-action checks

Client-safe managed-session control and kill-switch evidence kit

Client-safe Reviewable AutoFix plan, approval, retest, and rollback kit

Client-safe signed Risk Chronicle history and verification kit

Client Update Trust 0.1 verifier, pinned root, and signed artifact chain

Signed client AI Agent Security License records and Guardprints

Client-ready print/PDF reports

Agency scan inventory workflow

Resale and partner tools

Custom partner attribution code activation

Client export reports

Priority support through support@capitalguard.io

One year of updates

Upgrade credit through verified difference