Show HN: Conduct, open-source guardrails for LLM and MCP tool calls Conduct, an open-source runtime governance tool for AI agents, enforces a single policy across LLM and MCP tool calls before execution, with signed configuration and a SHA-256 hash-chained audit log. The project, available on GitHub, includes Conduct Guard (policy engine) and Conduct Router (LLM proxy), supporting providers like Anthropic, OpenAI, and Perplexity, and ships with 20+ compliance packs (OWASP, SOC 2, HIPAA, PCI DSS, EU AI Act) and 22 pre-built playbooks. Runtime governance for AI agents — one policy enforces across every LLM call, every shell tool, every teammate's AI session. Two product surfaces, one repo, one policy: Conduct Guard — the policy engine. Decides block / warn / audit / inject for every AI action before it executes, backed by signed configuration and a hash-chained audit log. Conduct Router — the LLM proxy. Point any provider SDK Anthropic, OpenAI, Perplexity at Router and every request runs through Guard on the way to the upstream provider. Runtime firewalls like Straiker https://www.straiker.ai/ and Lakera https://www.lakera.ai/ tell you what an agent did . Guard controls what an agent can do — with cryptographic proof. | Runtime firewalls | Conduct Guard | | |---|---|---| | Timing | After the action | Before the action | | Config integrity | Trust the pack | Workspace-signed | | Audit | Log stream | SHA-256 hash chain | | Coverage | LLM calls only | LLM and shell / MCP | | Failure mode | Fail-open soft | Fail-closed by default | The three-pillar moat: Signed configuration — every workspace signs its active policy set. Every Guard check verifies the signature before enforcing. A tampered pack — pushed by anyone, at any layer — is rejected before it can decide anything. Hash-chained audit — every decision appends to a SHA-256 chain rooted at workspace genesis. Any missing or altered entry breaks the chain and is caught on one-click verification. Evidence you can hand to an auditor. Policy-first, not detection-first — rules decide before the action executes, with structured reasons. Not anomaly detection after the fact. New here? Start with Discovery mode : read-only visibility into every AI action your team takes for 14 days. No policy to author, nothing to install upstream, no cost. When you're ready to enforce, promote a rule from what Discovery already saw. git clone https://github.com/sseshachala/conductai cd conductai docker compose up - API on http://localhost:8000 Guard + Router live at /guard/ and /proxy/ - Canvas UI on http://localhost:3000 - Redis worker + Postgres come up in the same stack Point any provider SDK at Router: curl https://api.conductai.ai/proxy/anthropic/v1/messages \ -H "Authorization: Bearer cond agt ..." \ -H "Content-Type: application/json" \ -d '{"model":"claude-sonnet-4-6","max tokens":1024,"messages": {"role":"user","content":"Hello"} }' Or wrap your CLI hooks with Guard: pip install conduct-cli conduct login conduct sync installs hook + MCP, pulls policies Now every Claude Code, Cursor, Copilot, ChatGPT, or Codex session on that machine is governed by the same active packs. | Component | Path | |---|---| Guard runtime | apps/api/app/modules/guard/ | Router proxy | apps/api/app/modules/guard/routers/proxy.py | Compliance packs | apps/api/app/modules/guard/skill packs/ | Canvas UI | apps/web/ | Playbook DSL loader | apps/api/app/dsl/ | Playbook library | apps/api/playbooks/ 22 pre-built | CLI | packages/conduct-cli/ | 20+ compliance packs ship out of the box: OWASP, SOC 2 CC7.3, HIPAA §164.312, PCI DSS 4.0, EU AI Act Art. 15/16, NIST AI RMF, ISO 42001, and framework-specific packs for Python, Node, and Terraform. 22 pre-built playbooks: Issue → PR, code review, incident response, prod deploy gate, CI/CD triage, security scanner triage, Slack digest, and more. Each is one YAML file; edit-and-run. Developer / agent Guard control plane ───────────────── ─────────────────── Claude Code ──┐ ┌── Canvas UI Next.js Cursor ──┤ CLI hook ────► ├── FastAPI + policy engine Copilot ──┤ cond cli ├── Postgres state, audit Codex ──┘ ├── Redis workers, queues ┌──── MCP ────► └── Hash chain SHA-256 Any SDK ────┤ Anthropic, └── Router ────► Upstream provider Anthropic, OpenAI, /proxy/ OpenAI, Perplexity, ... Perplexity Guard checks fire at three chokepoints: CLI hook — every Claude Code / Cursor / Copilot / Codex tool call. MCP layer — every MCP tool invocation. Router — every LLM call by any SDK. One policy, three enforcement surfaces. Self-host with docker compose — the command above. Runs everything locally. Self-host on Kubernetes — deployment templates ship in issue 1149 https://github.com/sseshachala/conductai/issues/1149 . Hosted — conductai.ai https://conductai.ai . Free tier includes Discovery; paid tiers unlock enforcement + Router + hash-chain verification API. SECURITY.md /sseshachala/conductai/blob/main/SECURITY.md — vulnerability reporting policy, scope, coordinated disclosure, and safe harbor. Threat model /sseshachala/conductai/blob/main/docs/threat-model.md — system context, trust boundaries, attacker goals, mitigations, and residual risks. Policy decision contract /sseshachala/conductai/blob/main/docs/policy-decision-contract.md — guard check decision semantics and fail-mode behavior. Audit log verification /sseshachala/conductai/blob/main/docs/audit-log-verification.md — independent prev hash / entry hash chain verification procedure and example script. API versioning /sseshachala/conductai/blob/main/docs/api-versioning.md — proxy/MCP compatibility, deprecation windows, and OpenAPI publication guidance. Apache License 2.0 — the entire repository, including the CLI, Guard, Router, Agent Booster, playbooks, and packs. - Free for commercial and non-commercial use, modification, and redistribution. - Includes an explicit patent grant from all contributors Apache 2.0 §3 . - Trademark rights are not granted; see NOTICE /sseshachala/conductai/blob/main/NOTICE — "Conduct", "Conduct AI", and "Conduct Guard" remain trademarks of Conduct AI. - Redistribution must preserve the LICENSE and NOTICE files. The hosted control plane at conductai.ai https://conductai.ai canvas UI, team RBAC, marketplace, managed Guard is a commercial offering built on top of this repository. For enterprise support, indemnification, or licensing questions, email hello@conductai.ai . We accept bug reports, docs fixes, new playbooks, new packs, tests, and code. Read CONTRIBUTING.md /sseshachala/conductai/blob/main/CONTRIBUTING.md first. - Everyone participating agrees to the Code of Conduct /sseshachala/conductai/blob/main/CODE OF CONDUCT.md . - Security vulnerabilities: don't open a public issue. See SECURITY.md /sseshachala/conductai/blob/main/SECURITY.md . - Anything else: GitHub Discussions https://github.com/sseshachala/conductai/discussions or SUPPORT.md /sseshachala/conductai/blob/main/SUPPORT.md . Product: conductai.ai https://conductai.ai Guard landing: conductai.ai/guard https://conductai.ai/guard Router landing: conductai.ai/router https://conductai.ai/router Docs: conductai.ai/docs https://conductai.ai/docs Discussions: github.com/sseshachala/conductai/discussions https://github.com/sseshachala/conductai/discussions Changelog: CHANGELOG.md /sseshachala/conductai/blob/main/CHANGELOG.md + Releases https://github.com/sseshachala/conductai/releases Book a demo: cal.com/sudhi-seshachala-pks7pd https://cal.com/sudhi-seshachala-pks7pd ⭐ If Conduct saves your team time, star it — it helps other teams find it.