Give AI agents the access they need, not unrestricted access to your enterprise.
Anpu Labs designs and deploys the runtime your agents operate in: isolated sandboxes, default-deny policy, brokered credentials, enterprise identity, and security telemetry your SOC can read. Built on NVIDIA OpenShell, inside your own cloud.
Runs underneath Claude Code, Codex, MCP servers, LangGraph, and custom agents.
Once an agent can execute code, call APIs, read repositories, query databases, invoke MCP tools, or use cloud credentials, prompt guardrails stop being a security control. They are a suggestion to a program that chooses its own next step.
Most teams can build the demo. Pilots stall when the agent needs real access and a review board asks who approved it.
Can the agent perform the task?
Should this agent take this action, against this resource, with this credential, from this environment, right now?
Anpu builds the layer that answers that question, and logs the answer.
Anpu designs the layer between autonomous agents and the systems they touch. NVIDIA OpenShell enforces it at runtime. Your identity provider, secrets platform, and SIEM stay the source of truth.
Runs on Kubernetes, containers, or VMs in your AWS, Azure, or GCP accounts.
Agents receive capabilities, not blanket access. Each sandbox starts with no outbound access, and every grant is written down, reviewed, and versioned like code.
Which destinations and API operations the agent can reach. Everything else is refused at egress.
Which directories the agent can read or write. Workspaces are separated per agent and per team.
Which binaries and system calls can run. The agent runs unprivileged, with kernel-level confinement.
Which secrets can be used, for which destination, by which agent. Keys are injected at the gateway, never handed over.
Useful autonomy without administrator access. Every decision is logged with the destination, the binary, and the reason.
Agents run in hardened, isolated sandboxes instead of on laptops or shared build servers. A compromised session stays contained.
Per-agent policies that name each system, operation, and path the agent may use. Nothing is inherited from the person who launched it.
Secrets stay in Vault or your cloud secret manager. The runtime adds them only to requests bound for approved endpoints.
Approved MCP servers and tools per workspace, so connecting a new server does not quietly widen what every agent can do.
Route sensitive workloads to NVIDIA NIM or self-hosted models inside your boundary, and the rest to providers you have approved.
Allow and deny decisions, credential use, and tool calls forwarded to your SIEM, with dashboards and alerts your SOC owns.
Every pilot ends with an adversarial run. We confirm the agent completes its real workflow, then try to make it do everything its policy forbids.
You get the results, the policies, and the logs that prove each one.
| Attempt | Expected | Result |
|---|---|---|
| Open a pull request on an approved repository | Allowed | Passed |
| Read a repository outside the workspace | Denied | Passed |
| Send data to an unapproved domain | Denied | Passed |
| Read a credential not attached to the agent | Denied | Passed |
| Call a prohibited MCP tool | Denied | Passed |
| Write outside the sandbox working directory | Denied | Passed |
| Escalate privileges inside the sandbox | Denied | Passed |
| Modify cloud IAM | Denied | Passed |
Run Claude Code, Codex, and other coding agents against real repositories without giving them your engineers' full access.
Let agents triage incidents and take narrow remediation steps without holding administrator access to production.
A shared runtime, policy catalog, and audit trail for agents across teams, designed to support your FedRAMP, HIPAA, and examiner requirements.
OpenShell is NVIDIA's open-source runtime for autonomous agents. It sits underneath harnesses like Claude Code and Codex and enforces sandboxing, policy-controlled egress, and credential handling while the agent runs.
It is an early-stage project, and we say so. We de-risk it the way we de-risk anything new: a staged pilot, explicit success criteria, and hardening before broad rollout.
The same model as every Anpu engagement, scoped to agents. The measure of a finished project is that you stop needing us.
We inventory your agents, the systems and credentials they touch, and the controls already in place.
You keep the output whether or not we continue.
One high-value agent moves into the controlled runtime with real integrations, then goes through adversarial validation.
Then we expand to more agents and teams, or step back. Either way, your engineers own it.
We integrate with what you have approved. Nothing on this list needs replacing.
IAM decides which identities can reach which services. An agent decides for itself which commands, APIs, and tools to use next. Secure agent infrastructure adds controls around that execution: what the agent can run, reach, and read, and which credentials it can use, at the moment it acts.
No. Vault or your cloud secret manager stays the source of truth. We connect it to the runtime so agents use credentials without ever holding them.
Yes. Everything runs in your AWS, Azure, or GCP accounts or your Kubernetes clusters, under your controls.
No. OpenShell works with the model providers you have approved. NVIDIA NIM is an option when you want private inference inside your boundary.
It is an early-stage open-source project. Staged pilots, explicit success criteria, and hardening come before any broad rollout.
No single tool does. We design the runtime to support your existing compliance controls and package the evidence your assessors ask for.
Fixed scope. You get an agent capability map, a threat model, and a security gap list, whether or not you build with us.