Quick-start guide
A concise installation, local-scan, authorization, and licensed-workflow guide for the customer team.
License delivery vault
Activate the key, confirm authorized scope, and download the permanent package included with your purchase.
Private customer delivery
Keep the Stripe receipt. License recovery requires the purchase email and payment evidence.
Private license key
Authorization-first scan intake
Raw secret redaction
Permanent delivered files
One year of updates
Access recovery
Request a private delivery resend with the purchase email and Stripe receipt reference. CapitalGuard verifies the payment record before any key is resent.
The browser never displays the plaintext license key. Recovery sends private delivery only to the verified purchase email.
Permanent customer kit
Verified customer access
Use the purchase email and license key sent after verified payment. Credentials remain in this browser tab only.
A concise installation, local-scan, authorization, and licensed-workflow guide for the customer team.
Quick start, package entitlements, license terms, fulfillment standard, scan intake, safe-use guide, Update Trust verifier and pinned root, Agent Surface Compiler, Privilege Diff, Security Flight Recorder, default-deny policy evaluator, Agent Action Gateway, Context Provenance Gate, Runtime Sequence Firewall, Sensitive Egress Gate, Economic Action Firewall, Agent Intent Firewall, Agent Delegation Firewall, MCP Integrity Gate, Memory Integrity Firewall, Adaptive Attack Lab, Workspace Integrity Ledger, Enforced Mode, Agent Change Gate, Managed Session Supervisor and kill switch, Agent Identity Gate, Reviewable AutoFix, signed Risk Chronicle, guardrail installer, and delivery checklist.
A self-contained, offline verifier with an embedded pinned root that checks signed role thresholds, freshness, release consistency, rollback state, and exact artifact bytes before installation.
The exact 2-of-3 signed bootstrap root delivered with the licensed verifier for independent custody and digest comparison.
Bootstrap, metadata refresh, external state-anchor, artifact verification, key-custody, and residual-risk instructions for Update Trust 0.1.
The exact Starter, Pro, and Agency deliverables, access paths, update window, and scan allowances.
Permanent internal-use rights, customer responsibilities, boundaries, and the enterprise replacement path.
The permanent internal-use rights and delivery terms included with the verified purchase certificate.
Delivery standards for license issuance, scan-start criteria, reports, and monitored scope.
Authorization-first intake that keeps repository scanning defensive, traceable, and controlled.
Starter guardrails for blocked files, protected paths, human approvals, and redaction.
Deterministically returns allow, redact, approve, simulate, or block decisions from privacy-safe request metadata. It does not intercept runtime operations.
A versioned starter policy with stable control IDs, strict request shapes, and a fail-closed default decision.
A fail-closed local gate for routed file, command, and metadata-only network operations with one-time approval leases and a tamper-evident event chain.
Signs privacy-reduced context graphs, derives conservative trust instead of accepting caller claims, binds exact review approvals, rejects replay, and routes the derived request through Agent Action Gateway.
The protected key-isolation, manifest, selection, exact review, authorization, gateway execution, state-anchor, privacy, and residual-boundary workflow.
Atomically carries privacy-safe taint across routed operations and blocks credential exfiltration, sensitive-data transfer, untrusted control mutation, privilege-expansion chains, and runaway loops before the terminal action.
The protected key-isolation, exact exception, signed reset, external state-anchor, integration, privacy, and residual-boundary workflow.
Inspects exact outbound file-write, command, MCP, and network fields in memory, blocks fixed high-confidence credential classes, fails closed on uninspectable payloads, and emits a signed receipt without raw values.
Authority-key setup, exact request binding, offline inspection, signed receipt verification, incident response, privacy, and residual-boundary instructions.
Binds an exact one-use human approval to a protected MCP economic action, atomically reserves configured budget before provider invocation, rejects replay, and conservatively accounts for uncertain outcomes.
Creates isolated signing authorities, signed action registries, privacy-reduced action records, exact approvals, and offline verification evidence for Economic Action Firewall 0.1.
Authority isolation, signed registry, exact approval, atomic budget, MCP composition, uncertain-outcome, receipt verification, privacy, and residual-boundary instructions.
Enforces a threshold-signed, actor-bound, task-bound, session-bound execution graph with exact operation selectors, prerequisite order, bounded uses, replay refusal, and atomic pre-invocation reservation.
Creates isolated authorities and closed execution contracts, collects independent signatures, and verifies contracts, receipts, signed state, and external anchor continuity.
Threshold-authority isolation, objective-digest, closed-DAG, exact-selector, runtime-composition, uncertain-outcome, recovery, privacy, and residual-boundary instructions.
Keeps reusable provider credentials outside the repository and agent runtime, compiles only exact capability-bound HTTPS requests, blocks replay and credential reflection, and returns an allowlisted response projection.
Creates isolated authorities and keys, signs closed provider registries, issues short-lived one-use capabilities, and verifies registry and capability bindings offline.
Vault separation, provider-registry, capability, response-projection, uncertain-outcome, Agent Intent, Enforced Mode, recovery, privacy, and residual-boundary instructions.
Applies a signed default-deny destination policy and deterministic block, redact, or one-way tokenization controls to exact broker payloads before any transformed request can be re-authorized.
Creates isolated policy and fingerprint authorities, derives owner-designated value fingerprints, signs and verifies policies, inspects exact payloads, and verifies privacy-reduced receipts.
Destination policy, deterministic detector, HMAC fingerprint, signed selector, transformed-request reauthorization, privacy, and residual-boundary instructions.
Issues target-bound, policy-bound, task-bound, single-use delegation chains that cannot amplify or fan out a parent agent's authority.
Pins signed MCP server and tool inventories, blocks identity or schema drift, approval-gates side effects, and quarantines untrusted result content outside agent context.
Encrypts, signs, scopes, expires, revisions, and revokes approved durable memory while keeping retrieval, model, and MCP open text outside the instruction channel.
A default-deny Policy Language rule requiring one exact Agent Action Gateway approval for every durable memory commit or revocation.
Creates policy-filtered workspaces and routes every authenticated task-bound operation through a full-hash workspace check before authority, host-derived provenance, data controls, sequence enforcement, the Agent Action Gateway, and signed Agent Change quarantine for file writes.
A fail-closed plan and run CLI requiring a digest-pinned image, supported OCI runtime, five separate owner-only signing authorities, signed data, workspace, and Agent Change policies, and isolated fingerprint keys.
Routes file, command, network, MCP, and handoff requests from the contained session to the authenticated CapitalGuard broker.
A minimal MCP server configuration for the contained CapitalGuard bridge.
Authority and policy setup, workspace baseline and retained anchor, plan and run commands, task binding, transformed-request reauthorization, signed write quarantine, separate review, fail-closed recovery, and the exact protection boundary for the unified runtime trust chain.
Creates signed full-hash repository checkpoints, detects exact in-scope drift, rejects unsafe filesystem ambiguity, and binds immutable history to a separately retained rollback anchor.
Creates separate gate and reviewer authorities, signs bounded policies, initializes and verifies baselines, issues exact expiring one-use approvals, reconciles reviewed drift, and verifies signed receipts.
Key isolation, signed policy, full-hash verification, retained-anchor custody, privacy-reduced drift review, exact approval, recovery, and residual-boundary instructions.
Quarantines exact UTF-8 file-write candidates outside the repository, binds signed evidence to exact preimages and session state, and applies approved changes atomically without granting direct agent write authority.
Creates separate gate and reviewer authorities, signs repository policies, stages candidates, issues exact expiring one-use approvals, and applies approved change sets with replay and preimage checks.
Gate and reviewer key separation, signed policy, quarantine review, exact approval, atomic apply, recovery, privacy, and residual-boundary instructions.
Runs local deterministic scam-signal, sensitive-data preflight, AI-account, connector, and risky-action checks and produces privacy-reduced signed evidence without declaring content safe or fraudulent.
Creates an isolated local authority, signs a bounded safety policy, assesses supported personal AI risks, redacts supported sensitive values, and verifies signed reports offline.
Plain-language setup, independent verification, sensitive-data preflight, AI-account hygiene, connector reduction, default-deny action rules, privacy, and protection-boundary instructions.
The CapitalGuard action-to-asset model, Guardprint semantics, privacy boundary, and responsible claim standard.
Runs nine non-destructive architecture-aware control challenges and retains exposed categories as local regression checks.
Runs six authorized, deterministic multi-turn scenarios against bundled synthetic profiles, then signs the hash-chained transcript, before/after comparison, and retained regression pack.
Locally compiles supported workflow, MCP, agent, tool, model, handoff, instruction, secret-category, and CODEOWNERS declarations into private and shareable inventories, a CapitalGuard A-BOM, and one signed integrity receipt without executing repository code or using the network.
Verifies two exact signed Agent Surface snapshots, classifies declared authority expansion and control loss, fails closed on evidence degradation, and emits a deterministic CI decision with signed private and shareable evidence.
The protected baseline, candidate, key-isolation, CI exit-code, exact acknowledgement, and signed-evidence workflow for Privilege Diff 0.1.
Locally records privacy-reduced, pseudonymous agent activity in a tamper-evident chain with searchable attribution, retention receipts, evidence-only replay, and Ed25519-signed exports.
Authenticates exact-session stop requests, initiates Enforced Mode broker shutdown before termination, records the closure outcome, rejects replay, and binds privacy-reduced lifecycle evidence to the supervised session.
Launches supervised Enforced Mode sessions and provides session-bound stop and signed-status commands without exposing an arbitrary PID kill path.
Issues owner-controlled Ed25519 agent security licenses with signed revocation history and short-lived proofs bound to the exact authenticated Enforced Mode and Managed Session launch.
A concise owner workflow for authority isolation, enrollment, license issuance, revocation, exact selector creation, verification, and authenticated managed launch.
Proposes ten bounded configuration remediations with exact preimage binding, separate one-time apply, verify, and rollback approvals, template retests, and no automatic commits or repository execution.
Creates customer-signed fresh-evidence recalculation requests and verifies CapitalGuard-signed append-only score history while persistent records retain only aggregate remediation and runtime evidence.
A least-privilege pull-request, manual, and scheduled workflow for the redacted local scanner and retained Attack Lab checks.
Writes local policy declarations and the defensive scanner without uploading repository code, printing secret values, or claiming runtime interception.
Practical operating rules for teams using AI coding tools with repository access.
The fulfillment and operating checklist for every paid CapitalGuard license.
Exact package scope
Local Personal AI Safety plus one authorized repository
1 repo scan
CapitalGuard Risk Score
AccessGraph snapshot and top findings
A-BOM and tamper-evident scan chain
Official Risk Score, signed AI Agent Security License record, and public verification URL
Print-ready report with PDF export
Local guardrail installer
Default-deny Policy Language 0.1 evaluator
Agent Action Gateway 0.1 local runtime gate
Sensitive Egress and Data Boundary firewalls with pre-adapter blocking, redaction, and one-way tokenization
Single-use Agent Delegation Firewall 0.1
Signed MCP Integrity Gate 0.1 inventory lock and output quarantine
Economic Action Firewall 0.1 exact approval and budget gate
Agent Intent Firewall 0.1 threshold-signed execution contract
Agent Memory Integrity Firewall 0.1 with retrieval quarantine
Adaptive Attack Lab 0.1 signed multi-turn regression kit
Agent Surface Compiler 0.1 private inventory and signed A-BOM
Privacy-reduced Security Flight Recorder 0.1 with signed evidence
Enforced Mode 0.7 unified runtime trust chain with full-hash workspace verification before authority
Workspace Integrity Ledger 0.1 signed full-hash baseline and exact drift approval
Agent Change Gate 0.1 signed quarantine and exact one-use review
Personal AI Safety 0.1 for scam signals, sensitive-data preflight, account checks, connectors, and risky AI actions
Managed Session Kill Switch 0.1 for supervised Enforced Mode sessions
Reviewable AutoFix 0.1 with ten bounded remediation templates
Signed Risk Chronicle 0.1 score history and fresh-evidence recalculation
Update Trust 0.1 threshold-signed artifact verification
One year of updates
Five authorized repository scans
5 repo scans
AccessGraph change history and license console
Versioned A-BOM and event-chain evidence
Policy generator
Deterministic Policy Language 0.1 evaluator
Agent Action Gateway with signed approval leases
Sensitive Egress and Data Boundary firewalls with signed privacy-safe receipts
Cryptographically attenuated multi-agent delegation chains
MCP Integrity Gate with side-effect approvals and closed-data output
Economic Action Firewall with atomic budgets and uncertain-outcome refusal
Agent Intent Firewall with closed DAG, exact selectors, and runtime receipt binding
Memory Integrity Firewall with signed scope, expiry, and revocation
Adaptive multi-turn Attack Lab with signed before/after comparison
Agent Surface Compiler topology, ownership, permissions, and signed shareable evidence
Searchable Security Flight Recorder with retention and Ed25519 evidence export
Enforced Mode 0.7 with full-hash workspace verification, authenticated broker, provenance, data controls, sequence firewall, Agent Change quarantine, and MCP bridge
Workspace Integrity Ledger with two-pass full hashing, rollback anchors, and separate reviewer approval
Agent Change Gate with exact preimage binding, separate reviewer key, one-use approval, and atomic apply
Personal AI Safety for scam signals, sensitive-data preflight, AI-account identity, connector exposure, and protected actions
Authenticated Managed Session Supervisor with signed stop evidence
Signed Reviewable AutoFix plans, retests, and exact rollback
Risk Chronicle with signed remediation and runtime evidence summaries
Update Trust 0.1 threshold-signed artifact verification
Print-ready executive report
Remediation checklist
Signed AI Agent Security License record after completed review
One year of updates
Twenty-five authorized repository scans
25 repo scans
Client AccessGraph portfolio
Client A-BOM and tamper-evident scan evidence
Client policy evaluation kit with stable control IDs
Client runtime-gate kit with replay-protected approvals
Client Sensitive Egress and Data Boundary Firewall deployment and receipt-verification kit
Client Agent Delegation Firewall deployment kit
Client MCP Integrity Gate deployment kit
Client Economic Action Firewall deployment and verification kit
Client Agent Intent Firewall authority, deployment, and verification kit
Client Memory Integrity Firewall deployment kit
Client-safe adaptive Attack Lab deployment and regression kit
Client-safe Agent Surface Compiler inventory, A-BOM, and signed receipt kit
Client-safe Flight Recorder audit, retention, and signed evidence kit
Client Enforced Mode 0.7 deployment kit with full-hash workspace verification and signed write quarantine
Client Workspace Integrity authority, reviewer, signed-baseline, drift, recovery, and evidence kit
Client Agent Change Gate policy, reviewer, quarantine, approval, and signed evidence kit
Client Personal AI Safety deployment kit for scam, data, identity, connector, and AI-action checks
Client-safe managed-session control and kill-switch evidence kit
Client-safe Reviewable AutoFix plan, approval, retest, and rollback kit
Client-safe signed Risk Chronicle history and verification kit
Client Update Trust 0.1 verifier, pinned root, and signed artifact chain
Signed client AI Agent Security License records and Guardprints
Client-ready print/PDF reports
Agency scan inventory workflow
Resale and partner tools
Custom partner attribution code activation
Client export reports
Priority support through support@capitalguard.io
One year of updates
Upgrade credit through verified difference