Skip to content

Deploy AI agents with the control you intend.

Loaf compiles your intent into per-task, enforced guardrails: egress policy, sandbox constraints, and evidence that they held. Not a policy document an agent can reason its way around. A boundary it runs inside of.

Intent

review-pr #482, repo: loaf/site

  • scope: read pr diff, comment
  • egress: github.com only
  • fs: repo checkout, read-only

Enforced

  • connect api.github.comALLOW
  • connect pastebin.exampleDENY
  • write /repo/.git/hooksDENY
  • read /repo/src/**ALLOW

Illustrative example, not a live product view.

Without Loaf, with Loaf

The same four controls, made concrete. Full detail on the trust page.

Guardrails
Without: An agent is told what not to do, and decides for itself how closely to follow that.
With Loaf: Your intent compiles into an explicit policy before the agent starts. It can't loosen it mid-task.
Egress policy
Without: An agent can reach anywhere the network allows, unless someone remembers to block it.
With Loaf: Network access is default-deny. Only the destinations a task was granted are reachable.
Sandbox constraints
Without: A single compromised step can touch anything the process has access to.
With Loaf: Each run is scoped to its own boundary: filesystem, process, and resource limits, nothing more.
Evidence they held
Without: Whether the guardrail held is something you have to take on faith.
With Loaf: Every run leaves a record you can check: which controls were active, and that they weren't bypassed.

Built to be verified, not just trusted

Read how each control is enforced today, and where we are honest about what is still a work in progress.

Read the trust page