Integrations
Add Control Zero to the providers, frameworks, and tools you already use. On supported events in Claude Code, Gemini CLI, Cursor IDE, and Kiro CLI, enforcement is deterministic: a deny stops the tool call before it executes. Python SDK hooks on Claude Code and Gemini CLI can instead mask a secret in place and let the call continue.
Control Zero fails closed by default when it cannot establish coverage, verifies signed policy bundles for tampering, and records an audit trail that distinguishes “did not run” from “ran and found nothing.” Coverage is declared per event rather than per host, so an integration never implies protection on a surface that does not provide it. The capability matrix is derived from the adapters' own capability declarations; run controlzero coverage --json to export them for your installation (a bare controlzero coverage prints only a short per-host summary).
Browse by where you are in the stack: model → framework → gateway → coding agent → MCP → observability.