ironcurtain
View on GitHubA secure* runtime for autonomous AI agents. Policy from plain-English constitutions. (*https://ironcurtain.dev)
IronCurtain is a TypeScript runtime that keeps autonomous AI agents untrusted: it compiles a plain-English constitution into a deterministic policy, then enforces allow/deny/escalate on every MCP tool call inside a V8 or Docker sandbox. Also runs multi-agent workflows with human gates.
Use Cases
Run autonomous coding agents inside a sandboxed container without ambient authorityCompile plain-English security constitutions into deterministic tool-call policiesMediate MCP tool calls with allow/deny/escalate decisionsDefend against prompt injection and multi-turn agent driftOrchestrate multi-agent vulnerability discovery and design-and-code workflowsAdd human-in-the-loop approval for risky git, file, or network actionsRoute LLM API calls through a TLS-terminating allowlist proxySchedule agents as daemon/cron jobs with browser-based escalation handling
Built With
- Language
- TypeScript
- Frameworks
- MCP · isolated-vm · Docker · Apple Container · Vercel AI SDK · Node.js · WSL2 · libFuzzer · AFL++
Tags
agent-security · sandboxing · policy-engine · mcp · prompt-injection · constitution · v8-isolate · docker · multi-agent · workflow-orchestration · human-in-the-loop · zero-trust · tool-calling · escalation · typescript · cli