Runtime protection
Evaluate tool calls and agent actions as they happen. Alert, request approval, or block based on policy.
- Claude Code and Codex hooks
- Agent frameworks and gateways
- IDE and proxy integrations
Signals Corps Runtime
Agent security for IT & security teams
Signals Corps Runtime applies one security policy across Claude Code, Codex, other coding tools, and delivery pipelines—then brings every triggered rule into one operational view.
Three ways to run
Apply consistent security rules at the point of action, before an integration is trusted, and whenever code changes. Signals Corps Runtime turns those checks into a policy your team can operate centrally.
Evaluate tool calls and agent actions as they happen. Alert, request approval, or block based on policy.
Inspect agent instructions and integrations before they enter your environment or reach a developer.
Check pull requests and releases automatically, with findings delivered where engineering already works.
Coding-tool coverage
Signals Corps Runtime adapts one policy to the control points each coding tool exposes—from native hooks to MCP, extensions, and gateways.
Integration depth matters. Hooks and gateways can evaluate actions automatically. MCP makes Runtime available inside compatible tools, but automatic enforcement depends on the controls that tool exposes.
Centralise triggered rules, matched evidence, enforcement decisions, and ownership without forcing every team into a new workflow.
From signal to decision
Show developers exactly what was stopped and give security teams the same structured evidence in their central workflow.
The developer sees the matched rule, the decision, and a safe next step without leaving their coding session.
Engineering gets evidence at the changed line; security gets a consistent finding and audit trail.
Operational by design
Meet developers in their existing tools and workflows instead of introducing another security checkpoint.
Begin in alert-only mode, understand normal behaviour, then introduce approvals or blocks where risk justifies it.
Evaluate locally for fast feedback and send structured findings to the central platform for investigation.
Give security teams the rule, evidence, identity, integration, and outcome needed to understand what happened.
Browser preview
Drop in a SKILL.md or MCP configuration. This lightweight demonstration runs supported detection patterns entirely in your browser and shows exactly which rules matched.
Content is processed on-device and never uploaded.
Every finding shows the ATR rule, severity, matched content, and a link to the rule definition.
Pipeline enforcement
Add the official ATR Action to your repository. Every change can be checked automatically, with findings sent to GitHub’s Security tab as SARIF.