How Runline works
An agent on every endpoint.Signed policy at the exec boundary.
AI agent blocked terraform destroy
cursor · macbook-pro-12 · 2m ago
kubectl delete namespace, denied
claude-code · ci-runner-04 · 18m ago
aws s3 cp upload, approval pending
cursor · eng-laptop-07 · 1h ago
98%
Fleet online
47
AI blocks
4m
MTTR
The tools your AI agents reach, guarded
From cloud CLIs and Kubernetes to MCP servers and AI clients, Runline ships 36 managed CLI shims plus an MCP proxy for the tools your fleet already runs, enforcing signed policy at the managed exec boundary.
Three pillars
From PKG install to signed audit, in three moves.
Not a scanner. Not an LLM gateway. Runtime enforcement at the exec boundary, deployed and operated like every other security agent on the fleet.
Deploy to the fleet
MDM-delivered PKG and DEB on Mac, Linux, and CI runners. Managed-install markers and fail-closed behaviour when the daemon is unreachable. Same shape your endpoint protection vendor already lives in.
- PKG / DEB installers (Windows preview)
- Heartbeat + telemetry to your console
- mTLS enrollment with rotating certs
Classify human vs AI
Every invocation is stamped with an actor class (cursor, claude-code, codex, mcp) by walking the process ancestry. Engineers using their own terminal pass through. AI shells hit modify denies.
- Process tree + tty heuristics
- Cursor + Claude + MCP fingerprints
- Audit envelope on every exec
Deny destructive modifies
AI agents read and explore freely. Terraform apply, IAM deletes, force-push, and high-risk MCP tools are blocked at the exec boundary by signed YAML before the side effect.
- Signed default policy pack
- Sigstore-signed published bundles
- Approval workflow for sensitive grants
Operate Runline like any other agent
Daily lifecycle for your security team.
Same shape as your endpoint protection rollout. MDM-delivered, mTLS-enrolled, signed bundles, fleet posture in one console.
Day zero
Install + enroll
Signed PKG / DEB hits the fleet via MDM. Agent enrolls over mTLS using a one-time install token, gets its tenant cert + initial policy bundle.
Daily
Intercept + decide
Shims sit on PATH. MCP proxy sits in front of Cursor + Claude tool calls. Every invocation is classified, evaluated against signed policy, and stamped.
On change
Publish signed policy
Security publishes a policy bundle from the console. Bundle is Sigstore-signed, distributed to the fleet, and verified before activation without an agent restart.
Always
Heartbeat + audit
Agents heartbeat every 30s. Decision records stream to your operator console. If you use Splunk, Sumo, or similar, Runline can forward copies to that system. Runline is not a SIEM.
Ready to see it on your fleet?
From first call to POV install in under a week.
Bring 25 endpoints. We'll bring the agent, the policy pack, and the audit evidence your CISO can defend.