Build and reason
Models write code, use tools and investigate the repository with deep context.
Secure what AI writes. Verify what AI brings in. Control what AI does.
CodeMarine is the independent security control plane around Claude, Codex, Cursor and the rest of your development stack. Deterministic checks protect the continuous path. Frontier models investigate the hard cases.
Claude, Codex, Cursor and other frontier tools do the creative work. CodeMarine watches the shared result, checks what enters the workspace and applies deterministic policy wherever a supported control point exists.
Models write code, use tools and investigate the repository with deep context.
One local-first control plane checks the output no matter which tool created it.
Approved models receive focused evidence, reason about hard cases and propose a patch.
Rescan the change, enforce policy and turn verified discoveries into durable regression control.
Models bring intelligence. CodeMarine makes the result repeatable, visible and enforceable.
Provider controls still matter. CodeMarine adds a shared layer around the codebase, software supply chain and supported agent actions. The policy remains when the model changes.
Deterministic decisionsThe same revision, rules and policy produce the same result.
Continuous coverageProtection keeps running after one agent session ends.
Visible limitsEvery surface is marked by its actual mechanism and health.
Your AI development stack
ClaudeCoding agent
CodexCoding agent
CursorAI editor
WindsurfAI editor
GrokFrontier model
DevinHosted agent
Continuously watches the shared workspace and applies one deterministic security policy.
Broad permission prompts often become background noise. CodeMarine is designed around a narrower question: is this specific action a known catastrophe?
Preventive claims apply only to supported pre-execution paths. Live host canaries and proof-backed Guarded status are planned. Native tools and remote actions remain outside coverage until a separate control path exists.
Read the Runtime Safety architectureAgents extend the system while they work. CodeMarine inspects the dependencies, MCP servers, skills and instructions entering that trust boundary.
The name is plausible but expected ownership and source are not established.
CodeMarine does not try to replace frontier reasoning with a longer pattern list. It uses deterministic security for routine coverage and reserves semantic investigation for cases that deserve it.
Continuous deterministic checks find known risks without a model call.
Graph paths, evidence and revision data focus the investigation.
An approved frontier model reasons about ambiguous or novel risk.
CodeMarine rescans the patch and checks policy before acceptance.
A verified discovery can become a deterministic regression control.
Code scanning does not prove runtime containment. An installed hook does not prove the host invoked it. CodeMarine’s target status model separates coverage from operational health.
Guarded will require a supported blocking mechanism, matching revisions and a current live-host proof. Until that system ships, preventive hook surfaces remain Setup needed.
Read the coverage contractCode and configuration scanningDeterministic workspace path
CurrentSupply-chain and agent artifact scanningDependencies, MCP, rules and skills
CurrentSupported local action adaptersSetup and proof limitations apply
BetaLive proof and Protection CenterProof registry and product UI
Planned
Claude, Codex, Cursor and the rest can all touch the same codebase. CodeMarine keeps one independent watch over the code they change, the software they bring in and the supported actions they try to take.
No. Frontier tools are strong semantic investigators. CodeMarine provides continuous deterministic checks, software supply-chain controls and one cross-provider evidence layer. The strongest design uses both: frontier models investigate while CodeMarine keeps the routine path repeatable and governed.
Native permissions and sandboxes are important. They are also scoped to one provider and one execution environment. Broad prompts can interrupt normal work, which encourages people to relax them. CodeMarine is designed to add a narrow independent layer around high-confidence risks while preserving one policy across providers.
Only when the operation passes through a supported pre-execution path. Local shell hooks can cover some actions. Native APIs, hosted agents and remote tools need a governed gateway, scoped credentials or downstream policy. CodeMarine reports the gap instead of claiming universal interception.
No. The continuous path is local-first and deterministic. Optional model investigation is reserved for cases that need semantic reasoning. This keeps routine protection predictable and token-efficient.
The same code revision, ruleset and policy should produce the same security decision. That gives CI gates, audit evidence, suppressions and regression controls a stable answer. A frontier model can still investigate the hard case, but it does not become the sole policy authority.
CodeMarine watches the shared workspace independently of the authoring tool. Provider-specific prevention still depends on the hooks and execution surfaces each tool exposes. That lets one policy cover the common result while the product reports differences in preventive coverage honestly.
CodeMarine is building the independent security layer for teams using more than one frontier development tool.