Content-free, open-core security for AI agents — Claude Code, Codex, Copilot CLI — right at the developer's endpoint. Most AI-security tools tokenize or proxy your prompts, files, and outputs off the machine to inspect them. MoorAI is content-free by construction: every check runs locally against one-way hashes, so prompt, file, and output content never leaves the device — unless an admin explicitly enables a capture tier. And because the agent is open source (AGPL-3.0), a CISO can audit that claim, not just trust it. The same on-device engine still guards everyday AI use across your team — the developer endpoint is where it goes deepest.
One local check, on the device, before a prompt ever reaches the AI — then only content-free signals flow to the console.
The same on-device engine, scoped to whoever's using it. In every case the checking happens locally — nothing leaves the machine, and no one reads what was typed.
Every claim as a straight yes or no.
A sample of what MoorAI recognizes — a 40+ threat matrix plus content rules, across everything the agent touches: what's typed, what it reads, what it passes to a tool, and what it says back. Each badge shows a representative response; you decide what every category actually does per policy: coach, alert, block, or require a signed justification.
claude -p CLI guard masks flagged spans before printing.Before anything an employee types reaches an AI tool, MoorAI checks it right there on the computer — against the rules you set. And it doesn't stop at the prompt: the same local engine checks the files an agent reads into its context, the arguments it passes to MCP tools, and the answers it sends back. Anything sensitive gets flagged or stopped, and what your people actually write never leaves the machine.
.env full of live keys is caught before that content ever lands in the model's context. Full enforcement on Claude Code via its PreToolUse hooks; Codex and Copilot CLI are detection-only, since they expose no equivalent deny hook.mcp__* tool call for secrets and PII before the call runs, and blocks per policy. The MCP surface is where agents quietly hand data to third-party servers — this is the check on that path.claude -p CLI guard masks flagged secret spans before they're printed — so a key the agent echoes out of a config file doesn't land in a terminal log or a pasted transcript.system: directive, buried in a file the agent will read later, is exactly the kind of delayed hijack this catches.components[] shape for GRC, audits, and third-party risk reviews.Most AI-security tools review prompts in a cloud, a gateway, or a vendor's own service — content leaves the endpoint to be inspected. MoorAI reviews prompts on the device, so content never leaves the machine, and it wraps the AI agents you already run. See the honest, architecture-level head-to-heads — including where each alternative is genuinely stronger.
The AI-integrated development pipeline starts on the developer's machine — that's where prompts are written, files are read into context, and MCP tools are called. MoorAI is the first control point on that pipeline, upstream of the CI, SCA, and code-scanning tools that only see risk once code is already committed. Govern AI use where it actually happens, not after the fact.
MoorAI maps its threat model and content-free telemetry to the AI-security frameworks your auditors ask about — and rolls it into a board-ready readiness report and an on-device AIBOM for the EU AI Act. So “how do you govern AI use?” has an evidenced answer, drawn from redacted signals — never a window into what anyone typed.
MoorAI rolls its content-free telemetry into a single board-level report: a composite trust score, shadow-AI exposure, endpoint posture, framework control-mapping, and a data-lineage-by-agent trail — all built from redacted signals, never prompt content. Evidence of how your organization governs AI, without a window into what anyone typed.
See the full layout — composite score, framework-mapping summary, and a data-lineage-by-agent table — rendered with example data.
Start here: you almost certainly have unmanaged Claude Code, Cursor, and Copilot installs running on developer machines right now — and zero visibility into what they read, send, or exfiltrate. That's the first job. MoorAI inventories every AI agent, app, account, MCP server, and browser extension on each device — from redacted, content-free signals — then lets you govern it: which agents and MCP servers are approved, and what each is allowed to do. Shadow AI stops being a blind spot, and unsanctioned agents stop being an open exfiltration path.
MoorAI reviews each prompt where it's typed, decides what to do, and reports only redacted metadata upstream.
MoorAI is governance without surveillance. Prompts and conversations are reviewed on the device and never leave the machine; security teams receive only redacted, content-free signals — a category, a risk level, and a one-way hash. It's a guardrail for how your organization uses AI, not a window into what people type.
“Content-free” is only worth something if you can verify it. Anyone can print the words on a page. Here's what actually backs the claim — and, honestly, what's still on the roadmap.
moorai-redteam) — run the adversarial suite against your own active policy and confirm it acts on each attack class, on your own machine. Claims about what it catches are checkable, not asserted.A local agent that reviews prompts where they're written, and a separate console for the fleet.
Open core: the enforcing agent is free and fully functional forever — you never pay to protect an endpoint. The management console is free for up to 200 users; beyond that, contact us for pricing.
The management console is free for up to 200 users; contact us for pricing beyond that. The community agent stays free and open source regardless.
Yes — it supports your obligations, without claiming to certify them. The EU AI Act expects organizations to know how AI is used, keep records, and apply human oversight. MoorAI produces content-free usage records — a category, a risk level, and a one-way hash per event — plus a control-mapping to the frameworks auditors reference (NIST AI RMF, ISO/IEC 42001, OWASP LLM Top 10, MITRE ATLAS). Its coach / alert / block / require-justification flow is human-oversight enforcement at the point of use. That gives you evidence and an audit trail that support and evidence EU AI Act obligations — MoorAI does not certify, guarantee, or by itself make you compliant, and it is not legal advice. It's control-mapping and records, not certification.
MoorAI lets your team use AI tools while keeping your company's information out of them. It runs on each computer, checks what an employee is about to send to an AI tool like ChatGPT, Claude, or Copilot, and warns or blocks before anything sensitive — source code, passwords, customer data — leaves the machine. Security teams get to see and control what's happening without ever reading what people type. The community version is free and open source.
It can. Depending on the tool and the plan, anything sent to an AI service may be stored, reviewed by humans, or used to train the model — which can surface it to other users as answers. Free and personal accounts are the biggest risk. That's exactly the gap MoorAI closes: it catches sensitive company material before it's sent, so it never reaches a service that could keep or leak it.
Three steps. First, the prompt is reviewed on the device — checked locally against policy, a 40+ threat matrix plus content rules — and the content never leaves the machine. Second, MoorAI coaches, alerts, or blocks, per policy, per tenant, per device. Third, a central web console shows posture, device inventory, alerts, and compliance, built from redacted metadata only.
Redacted, content-free signals — a category, a risk level, and a one-way hash — never the actual prompts or conversations. The console gives teams posture and compliance without exposing what anyone typed.
MoorAI is designed to sit in front of the AI agents teams already use, including Claude, Codex, and GitHub Copilot. Depth differs by agent, and it's worth being precise: on Claude Code, MoorAI hooks the agent's PreToolUse path, so it can actively block a file read or an MCP tool call that would pull secrets or PII into the model's context. Codex and Copilot CLI expose no equivalent deny hook, so on those the same checks run but are detection-only — you get the alert and the record, not the block. Prompt-stage review works across all of them.
Most guardrails only look at what a person types. But a coding agent reads files on its own — and a single .env can carry a dozen live credentials straight into the model's context without anyone typing a character. MoorAI hooks the agent's Read tool, plus conservative file-reading Bash, and inspects mcp__* tool-call arguments, so that content is checked before it becomes context. It runs on-device, reports content-free, and fails open — if the check can't run, work continues. This is governance, not a sandbox: it's built to stop mistakes and give you an accurate record, not to contain a determined attacker with local code execution.
No. Review happens on the device, and content never leaves the machine. That's the key difference from cloud DLP: MoorAI keeps the actual prompts and conversations local, and only redacted metadata is shared upstream.
The community agent runs standalone with local policy control and no account required — it's open source under AGPL-3.0, for macOS (Rust + a Tauri native host and webview detection core). Centralized fleet management — a multi-tenant console, SSO, and compliance reporting — is a separate, proprietary MoorAI management server.
The community agent is open source under AGPL-3.0 and runs standalone with no account required. The code is on GitHub. The centralized management server is a separate, proprietary product.
Coach, alert, or block — before the prompt reaches the agent.