Runwall
Zero-trust · AI agent governancePython · TypeScript · OPA/Rego · MCP · FastAPI
Active development
AI infrastructure · Security
What it does
Built a zero-trust proxy that sits between LLM agents and MCP tool servers, enforcing policy on every tool call instead of trusting the model with direct access — no code changes required to the agent or the tools it calls.
Implemented an OPA/Rego policy engine combined with taint tracking and LLM-based semantic risk scoring, so requests are evaluated for intent and data flow, not just static permissions — with human-in-the-loop approval workflows for high-risk actions.
Hardened through four rounds of adversarial security audits, improving the platform's security posture from 2.1/10 to 9.1/10. Selected for the Claude for Startups program, the Zendesk Startup Program, and the Sarvam AI Startup Program. Live at runwall.in.
