Boundary Security
Boundary
Security
Join Validation
Controlled Private Alpha · External Validation

See the dangerous path before the agent takes it.

Boundary is a predictive security layer for autonomous AI agents and MCP systems. It evaluates what a modeled action makes reachable next — not only whether the action is allowed right now.

Experimental / non-production. Current predictive validation is scoped to modeled sensitive external disclosure.

Predictive enforcement
Illustrative modeled tool trace
MCP Gateway
01
public_healthcheck
No modeled sensitive external disclosure is reachable.
ALLOW
02
modeled_action
The action is safe now, but a sensitive external disclosure becomes reachable downstream.
REQUIRE APPROVAL
03
unmodeled_tool
Unknown upstream capability is denied before execution.
BLOCK
The difference

Traditional security checks the action.
Boundary checks the future it creates.

Agentic systems can chain individually legitimate actions into a dangerous outcome. Boundary reasons across information flows, capabilities, derivations and communication paths to detect when modeled sensitive external disclosure becomes reachable.

01

Model

Describe agents, capabilities, information flows, communication paths and safety invariants.

02

Predict

Before execution, Boundary determines whether the proposed action makes a modeled sensitive external disclosure reachable.

03

Enforce

Allow safe actions, require human approval for predictive risk, and block prohibited behavior.

MCP security gateway

Put Boundary in front of the tools you already use.

Boundary discovers tools from an existing MCP server, mirrors their interface and evaluates each modeled action before it is forwarded upstream.

Predictive reachability

Reason about modeled sensitive external disclosure before the terminal action.

Human approval

Pause predictively risky actions and require explicit one-shot approval.

Deny-by-default

New or unmodeled upstream capabilities cannot silently bypass the security model.

Audit trail

Record enforcement, approvals and execution decisions for investigation and governance.

AI Agent / MCP Client
Claude · Codex · custom agents
↓
Boundary Security Gateway
Predict before execution
ENFORCING
Reachability
Safety invariants
Approval control
Audit
Tool discovery
Deny unknown
ALLOW
APPROVAL
BLOCK
↓
Existing MCP Server
CRM · DB · filesystem · APIs · SaaS
Controlled validation evidence

Tested through a real MCP execution path.

Boundary has moved beyond an in-memory security model. The current alpha has been exercised through real MCP processes and reproduced in a fresh internal environment.

These are controlled internal validation results — not independent external validation. External reproduction and tester-selected workflows are the next milestone.

Real MCP chain

A real MCP client, Boundary proxy process and real upstream MCP process have been exercised end-to-end.

Before-upstream enforcement

Allowed operations reached the upstream server. Blocked and approval-gated operations were withheld before the corresponding upstream side effect.

Predictive intervention

In controlled testing, Boundary gated a currently safe action when modeled sensitive external disclosure became reachable downstream.

Clean-room reproduction

The controlled workflow was reproduced internally from a fresh checkout and virtual environment.

CURRENT INTERNAL REGRESSION
208 passing tests

A development-quality signal, not a claim of universal correctness or independent validation.

External Validation

Challenge Boundary on a workflow we did not design.

We're recruiting external technical evaluators to reproduce the controlled workflow and then test Boundary against an independently selected MCP or agent workflow.

✓ Private repository access
✓ Frozen reproduction protocol
✓ Independent challenge phase
✓ No production commitment required

Boundary is currently experimental and not production-ready.