Let AI build.
CodeMarine
stands guard.

Secure what AI writes. Verify what AI brings in. Control what AI does.

CodeMarine is the independent security control plane around Claude, Codex, Cursor and the rest of your development stack. Deterministic checks protect the continuous path. Frontier models investigate the hard cases.

Local-first checksCross-providerExplicit coverage
Current product UI Local demo workspace
CodeMarine desktop Summary view for the checkout-service demo workspace
Captured from CodeMarine desktop with local demo data.
One independent layer across
ClaudeCodexCursorWindsurfGrokDevinCI
How CodeMarine fits

Frontier intelligence, with an independent safety layer.

Claude, Codex, Cursor and other frontier tools do the creative work. CodeMarine watches the shared result, checks what enters the workspace and applies deterministic policy wherever a supported control point exists.

1
FRONTIER TOOLS

Build and reason

Models write code, use tools and investigate the repository with deep context.

ClaudeCodexCursorOthers
3
FRONTIER TOOLS

Investigate and fix

Approved models receive focused evidence, reason about hard cases and propose a patch.

FindingCall pathPolicyRevision
4
CODEMARINE · VALIDATION

Verify and remember

Rescan the change, enforce policy and turn verified discoveries into durable regression control.

RescanPolicyEvidence
Continuous feedback loop

Models bring intelligence. CodeMarine makes the result repeatable, visible and enforceable.

One policy across every tool

One policy around every tool your team adopts.

Provider controls still matter. CodeMarine adds a shared layer around the codebase, software supply chain and supported agent actions. The policy remains when the model changes.

01

Deterministic decisionsThe same revision, rules and policy produce the same result.

02

Continuous coverageProtection keeps running after one agent session ends.

03

Visible limitsEvery surface is marked by its actual mechanism and health.

Your AI development stack

ClaudeCoding agent

CodexCoding agent

CursorAI editor

WindsurfAI editor

GrokFrontier model

DevinHosted agent

Independent control across every tool
CodeMarine

Continuously watches the shared workspace and applies one deterministic security policy.

CodeIntegritySupplyProvenanceActionsRuntime policyEvidenceAudit trail
{ }WorkspaceToolsCIInfrastructure
Runtime Protection Current product UI · demo workspace
CodeMarine Runtime Protection view showing Claude Code and Cursor coverage
Captured from CodeMarine desktop with local demo data.
Runtime protection

Give AI autonomy. Keep control of the blast radius.

Broad permission prompts often become background noise. CodeMarine is designed around a narrower question: is this specific action a known catastrophe?

Files and GitRecursive deletion, protected paths and destructive history changes
Data systemsDatabase drops, truncation and broad destructive mutations
InfrastructureCloud deletion, Kubernetes removal and IaC destruction
CredentialsSensitive-source collection and shell-visible exfiltration paths

Preventive claims apply only to supported pre-execution paths. Live host canaries and proof-backed Guarded status are planned. Native tools and remote actions remain outside coverage until a separate control path exists.

Read the Runtime Safety architecture
What agents bring in

Trust is added one package and tool at a time.

Agents extend the system while they work. CodeMarine inspects the dependencies, MCP servers, skills and instructions entering that trust boundary.

  • Package identitySlopsquatting, typosquatting and known-malicious package signals
  • Install behaviorManifest, lockfile, source and install-time execution review
  • Agent extensionsMCP descriptions, plugins, skills, rules and persistent instructions
  • Instruction integrityPrompt injection and agent memory or identity-file tampering
See the full trust boundary
Sarge stopping a malicious software bug before it enters the system
Dependency review Illustrative product view
package.jsonMODIFIED BY CURSOR
12"dependencies": {13"fastify": "^5.2.0" KNOWN14"auth-flow-utils": "^1.0.4" VERIFY15}
PROVENANCE SIGNALPackage requires review

The name is plausible but expected ownership and source are not established.

Registry UnconfirmedInstall script InspectLockfile Changed
Built for frontier models

Models investigate. CodeMarine stays in control.

CodeMarine does not try to replace frontier reasoning with a longer pattern list. It uses deterministic security for routine coverage and reserves semantic investigation for cases that deserve it.

01

Detect locally

Continuous deterministic checks find known risks without a model call.

02

Package context

Graph paths, evidence and revision data focus the investigation.

03

Investigate

An approved frontier model reasons about ambiguous or novel risk.

04

Validate

CodeMarine rescans the patch and checks policy before acceptance.

05

Retain the lesson

A verified discovery can become a deterministic regression control.

FRONTIER MODELSReason about new and context-dependent risk.
+
CODEMARINECheck continuously and enforce on proven paths.
See the governed model workflow
Coverage you can inspect

No blanket green shield.

Code scanning does not prove runtime containment. An installed hook does not prove the host invoked it. CodeMarine’s target status model separates coverage from operational health.

Guarded will require a supported blocking mechanism, matching revisions and a current live-host proof. Until that system ships, preventive hook surfaces remain Setup needed.

Read the coverage contract

Code and configuration scanningDeterministic workspace path

Current

Supply-chain and agent artifact scanningDependencies, MCP, rules and skills

Current

Supported local action adaptersSetup and proof limitations apply

Beta

Live proof and Protection CenterProof registry and product UI

Planned
Sarge standing watch in a CodeMarine command center
Meet Sarge

You choose the AI. CodeMarine watches what follows.

Claude, Codex, Cursor and the rest can all touch the same codebase. CodeMarine keeps one independent watch over the code they change, the software they bring in and the supported actions they try to take.

Code changesChecked continuously, regardless of which agent or person made them.
New trustPackages, MCP servers, skills and instructions examined as they enter the workspace.
High-impact actionsEvaluated on supported control paths with the real coverage state kept visible.
The hard questions to ask any AI security layer
Straight answers

The questions a security buyer should ask.

Is CodeMarine a replacement for Claude Security or Codex?

No. Frontier tools are strong semantic investigators. CodeMarine provides continuous deterministic checks, software supply-chain controls and one cross-provider evidence layer. The strongest design uses both: frontier models investigate while CodeMarine keeps the routine path repeatable and governed.

Why not rely on each provider’s permission prompts?

Native permissions and sandboxes are important. They are also scoped to one provider and one execution environment. Broad prompts can interrupt normal work, which encourages people to relax them. CodeMarine is designed to add a narrow independent layer around high-confidence risks while preserving one policy across providers.

Can CodeMarine stop an agent from destroying a server?

Only when the operation passes through a supported pre-execution path. Local shell hooks can cover some actions. Native APIs, hosted agents and remote tools need a governed gateway, scoped credentials or downstream policy. CodeMarine reports the gap instead of claiming universal interception.

Does every scan call a model?

No. The continuous path is local-first and deterministic. Optional model investigation is reserved for cases that need semantic reasoning. This keeps routine protection predictable and token-efficient.

What does deterministic protection actually mean?

The same code revision, ruleset and policy should produce the same security decision. That gives CI gates, audit evidence, suppressions and regression controls a stable answer. A frontier model can still investigate the hard case, but it does not become the sole policy authority.

Does CodeMarine work across Claude, Codex, Cursor and other tools?

CodeMarine watches the shared workspace independently of the authoring tool. Provider-specific prevention still depends on the hooks and execution surfaces each tool exposes. That lets one policy cover the common result while the product reports differences in preventive coverage honestly.

Browse the full product and security FAQ
Early access

Give AI room to work. Keep a hand on authority.

CodeMarine is building the independent security layer for teams using more than one frontier development tool.

Sarge, the CodeMarine guardian