Context Fence

Stop your AI agent from leaking your secrets.

Why this exists

Your agent doesn't ask — it just reads.

An agent will open the file you never wanted it to touch. We put a local check in that gap — every call validated before it runs, at schema speed.

On July 18, a coding agent read a .env file it was never asked to open. The keys left the machine. AI agents often hold real secrets, like keys and passwords. Nobody sees what they do with them. You find out later, if at all. Most teams just trust the agent. The fence checks first. Most teams just trust the agent. The fence checks first.

// capabilities

What Context Fence
protects

What your agent sends out, checked on your machine. No cloud in the path.

local yaml·<10ms·sqlite·zero egress
01

Secrets

Strips keys and tokens from what agents read. If it looks like a secret, it does not pass.

02

MCP tools

Checks every MCP tool call before it runs. Plain rules decide in under 10ms.

03

Hidden instructions

Flags tricks hidden in tool output. The agent never acts on them.

04

The log

A record of every decision. Each row names the rule that fired.

05

Prompts and files

Checks what is sent to AI models and what agents read and write.

06

Browsers, coding agents, and other tools

Wider coverage for how agents work today.

// case studies

Where it is being tested

Four patterns where the fence proves its value, from solo dev to agency fleet. These are examples, not customer stories.

4 patternsSolo → FleetLive proof
agency-mcp

agency mcp

Agency running client MCP servers

the problem

One team of agents touches client repos all day. One wrong read can send a client's secrets out.

what the fence did

Each client gets its own rule file. A no for one client stays a no.

zero agent changes
solo-claude

solo claude

Solo dev shipping with Claude Code agents

the problem

One dev, one laptop, and keys that must stay in env vars. The agent can read any file.

what the fence did

Risky calls are denied by default. Bad pushes, stray writes, and env reads are stopped.

tripped in hour onedefault-deny
mcp-gateway

mcp gateway

Gateway fronting every MCP endpoint they expose

the problem

A gateway opens private files to outside tools. One gap reads like an open door.

what the fence did

Each tool gets a short allow list. Other calls are denied first.

per-session allowlistsdenied before tools run
repl-auth

repl auth

A REPL that could reach the vault

the problem

A coding helper could reach the secret vault. The first test tried to read the keys.

what the fence did

Out of scope commands are refused. The vault path never reaches the model.

session-scoped commandsvault never reached

bench notes · july 2026

Simple pricing. Pay per machine, not per seat.

A node is one machine that runs Context Fence. Unlimited rules on every plan.

Free

$
forever · local core
1 node · local only7-day audit retention
Full local protection for MCP tools
Unlimited rules
1 machine (local only)
7 day log history
Works on Mac, Windows, and Linux
Start for free

Starter

$$22
per month · billed annually
3 nodes30-day audit retention
Everything in Free
Unlimited rules
3 machines included
30 day log history
Cloud backup of your settings
Get Starter

Enterprise

Contact us
annual · custom
Unlimited nodes180-day+ audit retention
Everything in Teams
Unlimited rules and machines
180+ day log history
Single sign on and roles
Rule version history
Contact us

Nodes, not seats. Monthly or annual billing — prices converted to your currency live. privacy policy.

// faq

Questions a security engineer actually asks

No. All checks run on your computer. Nothing is sent anywhere to be checked.
Under 10ms per check. It uses plain rules, not an AI judge. You will not feel it.
Keys and tokens. Unsafe file reads like .env files. Risky tool calls and hidden tricks in tool output. More coverage is coming in v2.1.
Old DLP tools and cloud gateways send your traffic to their servers to inspect it. We check everything on your machine. Nothing is sent anywhere.
Yes, the local proxy is free. Paid plans add more machines, longer log history, and team features. The hosted control plane is not built yet.
Soon. It widens Context Fence from MCP tools to full protection for AI agents. Join the newsletter to hear when it ships.