Customer guides
Learn the risk before buying the license.
Focused CapitalGuard guides for everyday AI users, freelancers, founders, agencies, and teams giving AI tools sensitive access.
Test an AI-agent kill switch
A five-step pre-flight for exact-session stop requests, connector closure, bounded shutdown, and evidence.
Open pathRespond to an AI-agent incident
A five-step containment and recovery workflow with a private 28-field incident register.
Open pathSecure MCP tools
A five-step review for server identity, tool definitions, least privilege, approvals, and untrusted results.
Open pathAudit AI-agent permissions
A five-step access audit and blank register for files, tools, secrets, networks, approvals, and permission drift.
Open pathOffboard people and agents
A five-step closure workflow and blank register for identities, sessions, repositories, tokens, connectors, and shared secrets.
Open pathVerify an AI-agent license
A five-step fail-closed workflow for authority, signature, expiry, revocation, and exact-session checks.
Open pathGitHub Actions AI-agent gate
A cited eight-control profile and SHA-pinned workflow for least privilege, trusted triggers, OIDC identity, and human approval.
Open pathClient code workflow
A cited pre-flight checklist and blank access register for freelancers and teams using AI with authorized client repositories.
Open pathEveryday AI users
A practical access check for people using AI with private files, client work, cloud apps, folders, or commands.
Open pathScanner intent
Teams looking for AI-agent repo scanning, secret exposure checks, and sample reports.
Open pathThreat research
Customers comparing prompt injection, secret context, automation, and agent-tool bridge risk.
Open pathPolicy intent
Founders who need AI-agent guardrail rules, policy files, and safer coding-agent defaults.
Open pathAgency distribution
Agencies packaging fixed-scope security checks before client onboarding.
Open pathPrimary research
Open controls, test vectors, Guardprint methodology, verification, and the public evidence boundary.
Open pathBottom-funnel library
16 focused pages for people already searching for the problem.
Cursor security
Cursor Security Checklist
A practical checklist for protecting secrets, workflows, commands, instructions, and sensitive repository paths before Cursor receives broad access.
Read guideClaude Code security
Claude Code Security Risks
Review the file, command, tool, prompt-injection, and workflow risks that matter before Claude Code works across a production repository.
Read guideCodex security
Codex Security Checklist
A defensive checklist for repository scope, terminal commands, tool access, secrets, deployment files, and human review when teams use Codex.
Read guideCopilot security
Copilot Security Checklist
Review repository instructions, suggestions, secrets, pull requests, workflows, and protected paths before expanding Copilot across engineering teams.
Read guideAI-agent risk
AI Coding Agent Risks
Understand the financial, operational, legal, reputational, and client-trust exposure created when coding agents gain broad repository and tool access.
Read guidePrompt-injection defense
Prompt Injection in Repositories
How malicious or stale instructions in docs, issues, prompts, logs, comments, and fixtures can influence AI coding agents with repository access.
Read guideSecret exposure
AI Agent Exposed Secrets
What to do when AI coding tools can read environment files, private keys, package credentials, service accounts, or sensitive production configuration.
Read guideGitHub workflow
GitHub AI Security Scanner
What a GitHub-native AI-agent security scanner should cover across repositories, pull requests, status checks, workflows, policies, issues, and verification.
Read guideRepository exposure
AI-Agent Repository Exposure
Map what AI agents can read, change, run, trust, summarize, or leak across code, configuration, docs, workflows, and client context.
Read guideFounder security
AI Security License for Founders
Choose a one-time AI-agent security license before coding tools gain wider access to product code, credentials, customer context, and company workflows.
Read guideAgency security
AI-Agent Security for Agencies
Package AI-agent exposure scans, client-ready reports, policy artifacts, exports, and verification into a repeatable agency service.
Read guideCustomer guide
One-Time AI Agent Security License
Why a fixed-scope license can be a cleaner first purchase than stacking monthly security tools before the AI-agent exposure surface is known.
Read guidePrevention guide
How to Evaluate AI Firewall Claims for Coding Agents
How to distinguish policy guidance from real runtime interception before coding tools gain wider access.
Read guideFounder guide
AI Security Check Before Investor Diligence
What founders should document before investors or enterprise customers ask how AI coding tools touch the product repository.
Read guideChecklist guide
AI Coding Agent Security Checklist
A practical checklist for teams that need to review repository access, protected files, workflow edits, prompts, logs, and policy gaps before agents get more authority.
Read guidePolicy guide
AI Agent Security Policy File Template
What to include in an AI-agent policy file for protected paths, command boundaries, prompt-injection handling, redaction, and approval rules.
Read guide