Skip to content
AppClap
Pipelock is unclaimed —
P

Pipelock

Open-source agent firewall for MCP and AI agent egress·pipelab.org

Visit

Pipelock is an open-source agent firewall that mediates MCP, HTTP, and WebSocket traffic between AI agents and the internet, including local stdio MCP servers. It runs an 11-layer scanning pipeline covering data-loss prevention, prompt-injection detection, tool-poisoning defense, and SSRF/cloud-metadata blocking. It ships as a single Go binary under 30MB with a process sandbox and adaptive kill switch, and can emit signed Ed25519 evidence and compliance-mapped reports (OWASP, NIST AI RMF, EU AI Act, HIPAA, SOC 2) for mediated actions.

What it's for

Protect AI coding agents (Claude Code, Cursor, VS Code, JetBrains) from credential leaksWrap local stdio MCP servers with the same scanner pipeline as network upstreamsDetect and block prompt injection and tool poisoning across HTTP, WebSocket, and MCP trafficGenerate signed, offline-verifiable evidence of enforcement decisionsRun security assessments against MCP deployments and produce compliance reportsCoordinate multiple named agent security profiles under one admin boundaryEnterprise fleet governance with centralized signed policy distribution and remote kill

Features 17

  • 11-layer scanner pipeline
  • 32-pattern prompt-injection detection with 6-pass normalization
  • 65 DLP patterns for credential and PII detection
  • Adaptive enforcement with escalation levels and auto-recovery
  • Compliance evidence mapped to OWASP, NIST AI RMF, EU AI Act, HIPAA, and SOC 2
  • Fleet governance via Pipelock Conductor (Enterprise)
  • Hot-reloadable signed rule bundles
  • Kill switch with 6 independent trigger sources (CLI, dashboard, API, Telegram)
  • MCP protocol scanning (tools/list, tools/call arguments, tool responses)
  • Offline receipt verification (Go, TypeScript, Rust, Python verifiers)
  • Operator dashboard/console with Prometheus metrics
  • Process sandbox (Landlock + seccomp on Linux, sandbox-exec on macOS)
  • Session binding and chain detection
  • Signed Ed25519 decision receipts and audit reports (HTML, JSON, SARIF)
  • SSRF, private-IP, and cloud-metadata blocking
  • Stdio MCP server wrapping with tool poisoning and rug-pull detection
  • TLS interception and cross-request detection

At a glance

free tierfree trialopen sourceself-hostableAPI
TypeCLI tool
DeploymentSelf-hosted
PlatformsLinux, macOS
Fordevelopers running AI coding agents, startups and small teams, solo builders coordinating multiple agent profiles, enterprise security and compliance teams
CompanyPipeLab · 2024

Integrations

Claude CodeCursorVS CodeJetBrainsTelegramPrometheusPolar

Complianceself-reported

OWASP MCP Top 10OWASP Agentic Top 10MITRE ATLASEU AI ActNIST AI RMFHIPAASOC 2

Pricing

Prices are stated in USD. The site emphasizes flat-rate pricing with no seats or per-agent metering. Enterprise pricing offers three on-ramps: a $5,000/60-day evaluation, a $15,000 year-one Design Partner track (limited to 3), and a $25,000/year flat annual contract.

CommunityFree

No credit card required; forever free.

Full security engine, one default security profile

Founding Pro$49/mo

Founding-member price locked for life for the first 50 customers; standard price is $99/mo. No seats, no per-agent pricing.

Unlimited named security profiles under one admin boundary

Assess License$83.25/mo · billed annually

Adds to the free Assess summary (grade, section scores, top findings, pass/fail verdict). Run pipelock assess against a deployment.

One-year license

Enterprise EvaluateQuote

Credited toward year one if signed within 30 days of the eval ending; includes a signed Fleet Receipt Report regardless.

60-day evaluation

Enterprise Design Partner$1250/mo · billed annually

Direct input on Conductor, Fleet Receipt Reports, and evidence workflows; renews at $25,000/year unless otherwise agreed.

Limited to 3 design partners

Enterprise Annual$2083.33/mo · billed annually

No seats, no per-agent meter, no quote maze.

Flat contract regardless of agent count

Save 17% when billed annually instead of monthly.

Last checked 28 days ago·