FAQ
Is it free?
Yes. Apache-2.0, no account, no usage limits.
Does it send my data anywhere?
No. The software makes no network calls and has no telemetry. Receipts go only where you configure. See the privacy page.
Is it a sandbox?
No. It is an application-level boundary. Use it together with OS and cloud controls. See what it does not do.
Does it work with my model or framework?
It is vendor-neutral: it wraps functions and tools, whatever calls them. There are adapters for MCP servers and OpenAI-style function tools, and a plugin for Cursor and Codex.
What if the governance code itself crashes?
The action does not happen (FAIL_CLOSED). Internal errors are treated like any other failure.
Is it slow?
Each decision runs a handful of in-process checks. The only waits are on providers you supply, each under a timeout (2 seconds by default), and a timeout is a refusal, not a delay with a happy ending.
Can I make it fail open for development?
There is deliberately no "default allow". For development, write a permissive policy rule, and keep it out of production configs. The default setting only accepts DENY or FAIL_CLOSED.
How do I know it works?
The behaviours are tested: each of twenty invariants has executable tests, the decision engine has full branch coverage, and senscheck test runs 21 failure scenarios against the engine. The simulator shows real results.
Can it guarantee my agent is safe?
No. It guarantees that actions routed through it follow the rules described here. It cannot guard paths that skip it.
Where do I report a vulnerability?
security@teknoledg.com. See the security policy.