All products
AgentWall logo
BetaDeveloper Security

AgentWall

A safer way to run AI coding agents.

Running AI agents on a computer or server? AgentWall helps you catch risky supported actions before they can delete files, expose sensitive data, or disrupt work.

Ubuntu 24.04 (amd64) · macOS Apple Silicon · Windows 11 x64 · Public beta

AgentWall — Decision log

Live
  • rm -rf ~/projects/data

    Blocked
  • git push --force origin main

    waiting for your review…

    Ask
  • npm run test

    Allowed

decisions stay on your machine

Public beta downloads

Put a checkpoint in front of your AI agents.

Download the published beta for Ubuntu, Apple Silicon macOS, or Windows 11 x64. Platform maturity and verification differ; review the notes before installing.

Public beta: what to know

  • Download the published package, then verify it before you install.
  • You see what AgentWall plans to change before you turn it on.
  • Codex and Claude Code support is still being tested, so do not rely on AgentWall for every action.

Apple Silicon macOS has a published beta download. Its signed files are publicly verifiable, but it remains a prototype while live agent evidence is completed.

Windows 11 x64 has an intentionally unsigned public beta installer. Its SHA-256 manifest verifies the downloaded bytes, not the publisher identity, and installation does not activate AgentWall automatically.

Download

Ubuntu, Apple Silicon macOS, and Windows 11 x64.

All three are published beta artifacts. Windows is an unsigned preview, and macOS and Windows integrations remain prototype-labeled while their evidence is incomplete.

Ubuntu 24.04

amd64

AgentWall 0.4.0-beta.1 Debian package for 64-bit Intel and AMD systems.

Install after downloading

sudo apt install ./agentwall_0.4.0-beta.1_amd64.deb

Minisign public key: RWQpDxCtUWCeUzwsHBDWUck9FihPyjwhpR91+e0eQDyGbI0BBDpQZzhQ

macOS 13+ · Apple Silicon

Apple Silicon

AgentWall 0.4.0-beta.4 DMG for Apple Silicon Macs. The download is published and verifiable; it is not a supported whole-machine security product.

Before you install

Claude Code and Codex are still being tested. AgentWall may not see every action, and it does not protect activity outside its installed agent connections.

Windows 11 · x64 preview

x64 preview

AgentWall 0.4.0-beta.6 current-user setup executable for 64-bit Windows 11. It is intentionally unsigned and is not a publisher-authenticated installer.

Before you run it

Compare the setup file with SHA256SUMS. The checksum detects changed bytes but does not prove publisher identity. Installation does not activate AgentWall, there is no automatic update, and Codex and Claude Code remain prototype integrations.

Current scope and evidence are published in the public capability matrix. AgentWall has no automatic update channel today.

Enterprise

Give your team a safer way to use AI agents.

AgentWall Enterprise is planned for teams that need simple, shared rules and a clearer view of how supported AI agents are used. It is not available yet.

Talk to Us

Tell us about your fleet, agents, and requirements. We respond by email to discuss early access, availability, and enterprise pilots.

Contact Us

Or email us directly at support@omnetsystems.com.

Central policies

Set simple rules for the supported AI agents your team uses.

Fleet visibility

See which devices and supported agents are connected and need attention.

Clear activity history

Review important approvals and blocked actions when your team needs answers.

Simple team setup

Help IT set up supported devices and share the same rules across a team.

The right people in control

Let the right people manage team settings and review important activity.

Fit with your security tools

Connect useful information to the security and compliance tools you already use.

Designed for managers and builders

Give teams room to move quickly while making the biggest risks easier to understand and control.

Privacy

Clear control over agent activity.

  • Your AgentWall settings, rules, and activity history stay on your computer by default.
  • Personal mode does not upload what your agent does. The desktop app may send an anonymous app-open count with no installation ID, commands, file paths, rules, or activity history.
  • The activity viewer runs only on your computer.
  • Cloud dashboards and team-wide reporting are not part of the personal product today.

Capability matrix

What AgentWall can help with today.

AgentWall only sees actions that a supported agent sends through its installed connection. The details below show the current limits.

IntegrationLabelOSEvidence note

Claude Code

AgentWall can check selected Claude Code actions when its connection is installed and working.

Ask/Block · Prototype

In testing: it can pause or stop some actions, but it is not ready to promise complete coverage.

Ubuntu 24.04 amd64Still being tested. Do not rely on it to catch every Claude Code action.

Codex

AgentWall can check selected Codex actions when its connection is installed and working.

Ask/Block · Prototype

In testing: it can pause or stop some actions, but it is not ready to promise complete coverage.

Ubuntu 24.04 amd64Still being tested. Do not rely on it to catch every Codex action.

Canonical artifact: public-capability-matrix.json. Claude Code remains ask-block-prototype until support-promotion gates are fully evidenced.

Limits

What AgentWall does not do.

  • Whole-machine protection or all-agent coverage
  • Tamper-proof local audit or absolute enforcement
  • Complete prompt-injection prevention
  • Automatic updates or claims beyond the separately verified signed release artifacts
  • Enterprise fleet dashboard in the personal product
  • DLP, EDR, Slack, or Teams enforcement in the day-one product

Common bypasses

Ways AgentWall can be bypassed.

  • Shell, git, or editor use outside wired Claude Code or Codex sessions
  • Agent tools outside the installed hook matcher
  • Removing or editing hooks manually
  • Personal-mode fail-open behavior when policy or approval infrastructure is unavailable
01

Ask before risky actions

AgentWall can pause a supported agent before it runs a risky command, changes files, or uses a selected tool.

02

Keep decisions visible

See what AgentWall checked and what it allowed, so your team can understand what an agent was trying to do.

03

Make safer calls quickly

When AgentWall needs you, it explains the request clearly so you can approve it or stop it.

04

Know when it needs attention

AgentWall tells you when its supported connections are not working properly, instead of pretending you are protected.

AgentWall beta

Put a checkpoint in front of your agents.

Download the free beta for Ubuntu, macOS, or Windows — or talk to us about your team.