Governance for AI coding agents

Let your engineers use Claude Code. Prove it's safe.

A hardened, deterministic control baseline for AI coding agents — enforce the guardrails on every endpoint, capture tamper-evident evidence, and map it to your compliance obligations. Built for regulated environments.

Book a demo → See how it works
30 hardening controls 10 deterministic hooks Tamper-evident evidence CPS 230/234 mapped
endpoint · pre-tool-use hook
# agent attempts:
$ rm -rf /var/data
⛔ DENY destructive command · control H-09 · blocked pre-execution
$ cat ~/.aws/credentials
⛔ DENY protected path · control H-11 · path redacted in evidence
$ git status
✓ ALLOW read-only · evidence record written
$
01 / THE PROBLEM

AI coding agents arrive with a new attack surface — and security can't say yes.

These tools read local context, run shell commands under the developer's privileges, and pull in external content. Without enforceable controls, adoption stalls in risk review — or gets waved through.

// shell

Destructive execution

Commands run with the developer's full local permissions.

// secrets

Credential exposure

Agents can reach .env, SSH keys, and cloud creds.

// injection

Prompt injection

Repo files, MCP and web content can hijack the agent.

// egress

Data exfiltration

Unbounded network access can move code and data out.

// supply chain

Dependency risk

Unreviewed installs and pipe-to-shell vectors.

// assurance

No proof

No evidence the controls worked, or that they map to obligations.

02 / THE APPROACH

Enforce. Prove. Comply.

A control plane you manage, with enforcement that runs locally on every endpoint — working even offline. It can't be silently weakened: any tampering breaks the evidence chain.

01 — ENFORCE

Deterministic guardrails

Managed settings, pre/post-execution hooks and a sandbox block dangerous commands, secrets, protected paths, unapproved egress and MCP — before they run. Denials are explained at the terminal, with an audit-logged exception path for legitimate work.

02 — PROVE

Tamper-evident evidence

Every decision is captured as a redacted, hash-chained audit record and forwarded to your SIEM. Code and secrets never leave the endpoint. Edit one byte and the chain breaks.

See a sample evidence record →
03 — COMPLY

Mapped to obligations

Control coverage mapped to APRA CPS 230/234, SOC 2 and ISO 27001 — with an audit-ready evidence pack your risk owner can sign off.

03 / WHAT'S INSIDE

A validated control baseline, not a config you assemble yourself.

Settings and hooks ship free with the agent. What doesn't: a validated thirty-control baseline, adversarial tests proving each control blocks what it claims, and independent evidence mapped to your obligations.

Managed settings

Non-overridable, enterprise-owned baseline delivered via MDM.

Deterministic hooks

Pre/post-execution enforcement — not model judgement.

Policy engine

Command, path, egress and MCP rules as a single source of truth.

Hash-chained evidence

Redacted, tamper-evident audit trail, SIEM-ready.

Adversarial tests

Prove every control blocks what it claims — and detect drift.

Compliance mapping

Control coverage to CPS 230/234, SOC 2, ISO 27001.

Sandboxing

OS-level isolation for shell and child processes where supported.

Drift detection

Re-validate after every agent version or model change.

Deployment runbook

From lab to fleet — gated rollout, evidence at every step.

APRA CPS 230 · operational risk APRA CPS 234 · information security SOC 2 ISO 27001
04 / PRICING

Start with a fixed-scope pilot. Expand when it earns it.

Get a regulated rollout approved, then scale to a fleet subscription. Pilot fees credit against an annual plan.

Baseline
Licence
The hardened control pack + docs, for teams who self-implement.
  • 30-control hardened baseline
  • Hooks, policies, evidence model
  • Adversarial test suite
  • Deployment runbook
Talk to us
Assurance Pilot
Fixed scope · 30–45 days · from AUD $15,000
We deploy, validate and evidence it — with a compliance sign-off pack.
  • Everything in Baseline
  • Deployment + validation support
  • Tamper-evident evidence capture
  • CPS 230/234 mapping
  • Risk sign-off pack for your risk owner
Book a pilot →
Platform
Annual · per fleet
Central management, SIEM-fed assurance and ongoing coverage.
  • Fleet rollout & central policy
  • SOC dashboards & alerting
  • Drift detection & regression
  • New-version & multi-agent coverage
Talk to us
05 / FAQ

The questions risk review will ask.

What platforms does Toren support?

Toren deploys through your existing MDM to macOS, Windows and Linux endpoints. [CONFIRM: exact OS and MDM coverage before publishing]

Does enforcement work offline?

Yes. All enforcement runs locally on the endpoint. Evidence records queue locally and forward to your SIEM when connectivity returns. [CONFIRM: queueing behaviour]

What does a developer see when a command is denied?

A one-line explanation at the terminal naming the control that fired. Legitimate work has an audit-logged exception path — denials are designed to be rare, explained and appealable.

What data leaves the endpoint?

Redacted, hash-chained evidence records only. Code, file contents and secrets never leave the machine.

What happens when Claude Code ships a new version?

Drift detection re-runs the adversarial test suite against the new version and flags any control regressions before wider rollout.

Unblock AI coding — without waving through the risk.

See the controls enforce live, and the evidence prove it. Ten minutes.