For individuals

Your assistant has your passwords.
Give it a lock.

The AI you use every day stopped being a chatbot a while ago. The moment it browses, sends mail, moves files or runs a command, it is acting — with your accounts, on your machine. enclawed decides what it is allowed to do, by rule.

The chatbot talks

You ask it to draft an email. It answers, you decide what to do. If it gets something wrong, you lost two minutes.

The agent does

Same program, but you gave it the keys: inbox, files, browser, terminal. It does not offer you the email. It sends it.

enclawed stands in between

Every action is checked against a list of what you allowed. On the list, it happens. Not on the list, it does not. There is nothing to talk around.

Why a list beats a smarter AI. The usual answer is to watch the AI with more AI. That lowers how often things go wrong; it cannot rule anything out. A rule has no error rate: the action either matches what you permitted, or it does not.

What you get

  • The open core, free to inspect. enclawed’s core is open source. You do not have to take our word for how it decides — you can read it.
  • A record you can check. Every action, allowed or refused, lands in a log built so that altering it after the fact is visible.
  • The Enclaweder, when you want the lock outside the computer. A device the size of a credit card on a USB-C port. The permissions live in it, not on the machine — so someone who gets into the machine still does not reach them.
Measured, not asserted. Across 1,600 messages routed through real services — real attacks mixed with ordinary requests — the unhardened runtime stopped none. enclawed stopped all of them, with zero false alarms on legitimate traffic. The test harness and the per-sample data are public.

See the measurements · See the device · Read the open core

Get on the list

The Enclaweder ships once its certification is granted. Tell us what you run and we’ll tell you what it takes to secure it.

Talk to us