
kontext-cli
Secure agents in seconds with permissions enforced at runtime.

Secure agents in seconds with permissions enforced at runtime.

Workload identity platform that attests running services, issues SPIFFE IDs/SVIDs, and enables mTLS and JWT authentication for Kubernetes,…

JumpServer is an open-source Privileged Access Management (PAM) platform that provides DevOps and IT teams with on-demand and secure access to SSH,…

This application gives Mac users in enterprise environments control over the administration of their machines by elevating their access level to…

A tool for secrets management, encryption as a service, and privileged access management

A lightweight, cryptography-powered, open-source toolkit built to enforce Zero Trust security for infrastructure, applications, and data in the…

TrustedRouter.com repo for secure LLM proxying

Ed25519 signed receipts + Cedar policies for AI agents. Finance mandate gate (Legate), proof packs, 3 IETF Internet-Drafts. npx protect-mcp

cMCP: Confidential MCP Gateway. Hardware-attested policy enforcement for MCP tool calls.

PacketFence is a fully supported, trusted, Free and Open Source network access control (NAC) solution. Boasting an impressive feature set including a…

Infisical is the open-source platform for secrets, certificates, and privileged access management.

Zero-trust networking platform that makes services invisible with cryptographic identity, policy-based access, and end-to-end encryption. Replaces…

strongSwan - IPsec-based VPN

Execution-Layer Security (ELS) for AI agents — policy-enforced shell with audit.

Code signing and transparency for containers and binaries

Sandboxed runtime for autonomous AI agents with declarative YAML policies enforcing filesystem, network, and process constraints, plus endpoint-bound…

The Symfony PHP framework

Sandbox and MCP proxy that blocks AI coding agents from reading SSH keys, AWS credentials, and .env files, with deny-by-default policy and…