Default-deny execution gate for AI agents, APIs, and distributed systems. Policies, drift detection, hard invariants, post-quantum signed permits.Written in Rust. Says no unless policy says yes.
-
Updated
May 4, 2026 - Rust
Default-deny execution gate for AI agents, APIs, and distributed systems. Policies, drift detection, hard invariants, post-quantum signed permits.Written in Rust. Says no unless policy says yes.
The official "kavach" skill repository
Settlement-rail enforcement for DORA-compliant payment infrastructure. Companion to hsm + gatekeeper.
Default-deny policy gateway for LLM/agent tool calls. Rate limiting, path validation, argument filtering, audit logging.
Security-first AI artifact registry — digest-based storage, policy-gated promotion, signed provenance, and reproducible trust metadata for local models, adapters, and tokenizers
Add a description, image, and links to the default-deny topic page so that developers can more easily learn about it.
To associate your repository with the default-deny topic, visit your repo's landing page and select "manage topics."