Control Zero Documentation
Define what your AI agents are allowed to do. Deterministically enforce it at runtime. Audit every decision and its coverage.
Quickstart → · What is Control Zero
How you enforce
Pick the surface that matches where your agents run.
Coding hooks
Hard-block denied tool calls before execution in Claude Code, Gemini CLI, Cursor IDE, and Kiro CLI. Coverage is recorded per event.
SDK
Wrap tool calls in Python or Node.js with guard(). Works with LangChain, custom agents, and provider SDKs.
Gateway
Point existing apps at a proxy URL. Zero code changes — LLM traffic is governed in flight.
Browser extension (BETA)
Blocks and masks PII and secrets before they are pasted into claude.ai, ChatGPT, Gemini, and Perplexity. Distributed as a Teams admin bundle; the Chrome Web Store listing is still in review.
MCP server
Let Claude read audit logs, draft policies, and manage projects through natural language.
Find your path
Start from a job, a role, a recipe, or a short decision tree.
Quickstart
Five minutes to a real allow/deny decision with the dashboard or a local policy.
Use cases
Govern coding assistants, apps, chat UIs, DLP, approvals, compliance, and offline setups.
Setup by role
AI engineer, DBA, developer, DevOps, security, or intern — starter policy for your job.
Policy recipes
Copy-paste policies for read-only databases, secret egress, model allow-lists, and more.
Choose your path
Not sure where to start? Answer five questions and get one recommendation.
What is Control Zero
Product overview, hello world, and why teams put a governance layer in front of agents.
Integrations
Connect Control Zero to the providers, frameworks, and tools you already use. See the full integrations overview for logos and short descriptions.