How Runline works

An agent on every endpoint.Signed policy at the exec boundary.

Runline Console · acme-corp
AlertsLast 24h

AI agent blocked terraform destroy

cursor · macbook-pro-12 · 2m ago

kubectl delete namespace, denied

claude-code · ci-runner-04 · 18m ago

aws s3 cp upload, approval pending

cursor · eng-laptop-07 · 1h ago

98%

Fleet online

47

AI blocks

4m

MTTR

The tools your AI agents reach, guarded

From cloud CLIs and Kubernetes to MCP servers and AI clients, Runline ships 36 managed CLI shims plus an MCP proxy for the tools your fleet already runs, enforcing signed policy at the managed exec boundary.

AWS, Azure, Google Cloud, kubectl, Helm, Docker, Terraform, Git, PostgreSQL, curl, Windows PowerShell, cmd.exe, ssh, MCP, Cursor, Claude Code

Three pillars

From PKG install to signed audit, in three moves.

Not a scanner. Not an LLM gateway. Runtime enforcement at the exec boundary, deployed and operated like every other security agent on the fleet.

01

Deploy to the fleet

MDM-delivered PKG and DEB on Mac, Linux, and CI runners. Managed-install markers and fail-closed behaviour when the daemon is unreachable. Same shape your endpoint protection vendor already lives in.

  • PKG / DEB installers (Windows preview)
  • Heartbeat + telemetry to your console
  • mTLS enrollment with rotating certs
02

Classify human vs AI

Every invocation is stamped with an actor class (cursor, claude-code, codex, mcp) by walking the process ancestry. Engineers using their own terminal pass through. AI shells hit modify denies.

  • Process tree + tty heuristics
  • Cursor + Claude + MCP fingerprints
  • Audit envelope on every exec
03

Deny destructive modifies

AI agents read and explore freely. Terraform apply, IAM deletes, force-push, and high-risk MCP tools are blocked at the exec boundary by signed YAML before the side effect.

  • Signed default policy pack
  • Sigstore-signed published bundles
  • Approval workflow for sensitive grants

Operate Runline like any other agent

Daily lifecycle for your security team.

Same shape as your endpoint protection rollout. MDM-delivered, mTLS-enrolled, signed bundles, fleet posture in one console.

Day zero

Install + enroll

Signed PKG / DEB hits the fleet via MDM. Agent enrolls over mTLS using a one-time install token, gets its tenant cert + initial policy bundle.

Daily

Intercept + decide

Shims sit on PATH. MCP proxy sits in front of Cursor + Claude tool calls. Every invocation is classified, evaluated against signed policy, and stamped.

On change

Publish signed policy

Security publishes a policy bundle from the console. Bundle is Sigstore-signed, distributed to the fleet, and verified before activation without an agent restart.

Always

Heartbeat + audit

Agents heartbeat every 30s. Decision records stream to your operator console. If you use Splunk, Sumo, or similar, Runline can forward copies to that system. Runline is not a SIEM.

Ready to see it on your fleet?

From first call to POV install in under a week.

Bring 25 endpoints. We'll bring the agent, the policy pack, and the audit evidence your CISO can defend.