
Policy engine and EDR for AI agent fleets and developer workstations. Monitors tool calls, file access, network flows, and process execution with Ed25519-signed audit trails and fail-closed enforcement.
EDR for the age of the swarm.
Fail closed. Sign the truth.
Status: pre-1.0 beta. Public APIs are stable; defaults may still tighten before 1.0.
Clawdstrike is a policy engine, an EDR, and a signed audit chain in one binary. An AI agent's tool_call sits in the same event taxonomy as a kernel-level file_access, process_exec, network_flow, dylib_load, or launch_persistence. One policy engine evaluates them. One Ed25519-signed causal graph records them. Defaults fail closed.
The same engine ships as a Rust crate, a TypeScript SDK, a Python package, a Go module, a CLI, a desktop EDR agent (macOS Endpoint Security + Network Extension; Linux Tetragon + Hubble), and an enterprise control plane.
Quick Start · Guards · Policies · Formal Verification · Enterprise · Design
Install via your preferred package manager:
brew install backbay-labs/tap/clawdstrike # macOS, Linux
npm install @clawdstrike/sdk # TypeScript
pip install clawdstrike # Python
cargo add clawdstrike # Rust
go get github.com/backbay-labs/clawdstrike-go
Scaffold a project and start the daemon:
clawdstrike init --keygen
# writes policy.yaml, config.toml, keys/clawdstrike.key{,.pub}
clawdstrike daemon start && clawdstrike daemon status
# Status: healthy | Version: 0.2.7 | Uptime: 2s
Three denials, each signed:
$ clawdstrike check --action-type file --ruleset strict ~/.ssh/id_rsa
BLOCKED [Critical]: Access to forbidden path: ~/.ssh/id_rsa
$ clawdstrike check --action-type egress --ruleset strict api.openai.com:443
BLOCKED [Error]: Egress to api.openai.com blocked by policy
$ clawdstrike check --action-type mcp --ruleset strict shell_exec
BLOCKED [Error]: Tool 'shell_exec' is blocked by policy
Verify the policy itself compiles and is internally consistent:
$ clawdstrike verify --policy strict
Consistency: PASS (47 formulas, 0 conflicts)
Completeness: PASS (4/4 action types covered)
Inheritance: PASS (0 weakened prohibitions)
Run a real agent under enforcement:
clawdstrike run --policy clawdstrike:strict -- python my_agent.py
The agent runs normally. Every tool call hits the engine first. Denials raise a typed error in your SDK and emit a signed receipt.
For fleet deployments, install the Helm chart. hushd and the Spine signers are fail-closed and need keys at install time, so pre-create the Secrets and reference them from the chart:
NS=clawdstrike-system
kubectl create namespace "$NS"
kubectl -n "$NS" create secret generic clawdstrike-hushd-auth \
--from-literal=CLAWDSTRIKE_API_KEY="$(openssl rand -hex 32)" \
--from-literal=CLAWDSTRIKE_ADMIN_KEY="$(openssl rand -hex 32)" \
--from-literal=CLAWDSTRIKE_AUTH_PEPPER="$(openssl rand -hex 32)"
kubectl -n "$NS" create secret generic clawdstrike-spine \
--from-literal=SPINE_LOG_SEED_HEX="$(openssl rand -hex 32)" \
--from-literal=SPINE_WITNESS_SEED_HEX="$(openssl rand -hex 32)"
helm install clawdstrike \
oci://ghcr.io/backbay-labs/clawdstrike/helm/clawdstrike --version 0.2.0 \
--namespace "$NS" \
--set hushd.auth.existingSecret=clawdstrike-hushd-auth \
--set spine.secrets.existingSecret=clawdstrike-spine
That brings up hushd, the Spine checkpointer + witness, and bundled NATS JetStream. The Control API (enrollment, posture commands, signed completion bundles back) and the Tetragon/Hubble telemetry bridges are opt-in.
See the chart README for the full parameter set, and Enterprise enrollment for end-to-end agent onboarding.
flowchart LR
A[Agent / sensor] --> B[Canonical event]
B --> C[Policy engine + guard stack]
C -->|allow| D[Action runs]
C -->|deny| E[Blocked, fail-closed]
C --> F[Ed25519 receipt]
F --> G[Causal graph]
G -.->|enterprise| H[Spine audit chain]
SDK adapters and OS-level sensors feed the same canonical event into the policy engine. Adapters cover AI agent tool calls; kernel sensors (macOS Endpoint Security and Network Extension, Linux Tetragon and Hubble) cover file, process, network, dylib, and persistence events. The guard stack returns a verdict, the verdict ships with an Ed25519 receipt, and each receipt is content-hashed into a per-session causal graph that threads agent identity through downstream OS events.
When a decision crosses a response threshold the engine emits a signed effect: quarantine a file, restrict an egress destination, suspend a process tree, revoke a previously-issued approval. Effects are reversible where possible. Past observations stay on a disk-backed flight recorder, so a tightened policy can be simulated against last week's state before it ships. In enterprise mode the receipt chain ships over NATS to the Spine checkpointer; an independent witness co-signs each batch.
Logs are stories; proof is a signature.
Each guard is a composable check at the tool boundary. Returns a verdict with evidence. Fail-fast or aggregate; configured per-policy.