Your AI agent has access to your Stripe keyGitHub
Inherence is the safety layer for AI agents on your machine.
five minutes. free.
Six categories of catastrophic action. Each one is blocked at the proxy, signed in your dashboard, and tunable from a YAML file. Defaults are tight; you decide what to loosen.
Block transfers above thresholds you set.
Block reads of .env, AWS, SSH, keychains.
Block password resets, MFA changes.
Block bulk deletes, destructive commands.
Block calls to cloud metadata, infra.
Block file reads combined with external sends.
The proxy sits in front of every tool call. Each call is classified, evaluated against the six catastrophe rules, and either forwarded to your upstream MCP server or blocked before it ever reaches the wire. Every decision is signed.
The proxy is open source · the policy gate runs on our servers · receipts you can verify yourself
An agent tries to issue a $4,500 refund after reading a prompt-injected support email. Inherence blocks it. The user reviews and approves a legitimate refund instead.
Apache 2.0. Audit every line. The proxy that runs on your machine is the same code on GitHub — reproducible builds, signed releases.
Read on GitHub →02 — ReceiptsEvery decision is signed. Verifiable offline against our public key. You don't have to trust our dashboard — you can re-check the math.
Verification docs →03 — Free tierNo credit card. No trial period. The proxy and the dashboard are free for solo developers — forever. Paid tiers are for teams and orgs.
Sign up →The proxy gates every MCP server that runs locally. Gmail — the first hosted SaaS connector — is live in beta. GitHub, Drive, Slack, and Notion are next: OAuth through Inherence, every tool call through your policy gate before it reaches the SaaS API.
The Apache 2.0 proxy at pip install inherence-proxy sits in front of every MCP server your agent uses — filesystem, GitHub, Stripe, shell. Gmail joins as the first hosted connector: five read-only tools, all gated through the six rules.
Same six rules. Same dashboard. Same signed receipts. Built; awaiting OAuth verification with each provider.