Conduct Launches Open-Source Governance Framework for LLM and MCP Tool Executions
The project brings cryptographic permissions and unified compliance packs to AI developer tools like Claude Code, Cursor, and Copilot.

A new open-source runtime security project called Conduct has launched to provide engineering teams with centralized policy enforcement for AI agents and Model Context Protocol (MCP) tool calls. First detailed in a project release on Hacker News, the platform establishes uniform security rules across shell utilities, language model API calls, and local developer sessions.
Unlike traditional monitoring tools and runtime firewalls that log agent activities after execution, Conduct incorporates a Guard component that uses cryptographic proofs to constrain what an AI agent can execute. The system acts as a proactive control layer rather than a passive audit log, restricting agent actions across individual developer machines and shared team environments.
The framework integrates across major developer platforms and coding assistants, governing sessions within Claude Code, Cursor, GitHub Copilot, ChatGPT, and Codex. By standardizing execution parameters, the tool allows security teams to enforce identical compliance rules across disparate coding tools used throughout an organization.
To ease deployment, Conduct includes a 14-day zero-cost "Discovery mode" that grants read-only visibility into team-wide AI actions. The feature requires no upstream software installation or pre-written rules, allowing security administrators to observe real-world agent behaviors before converting those actions into active enforcement policies.
Out of the box, the repository provides more than 20 pre-configured compliance packages tailored to international regulatory standards and technical frameworks. Supported benchmarks include SOC 2 CC7.3, HIPAA §164.312, PCI DSS 4.0, Articles 15 and 16 of the EU AI Act, the NIST AI Risk Management Framework, and ISO 42001, alongside language-specific security sets for Python, Node.js, and Terraform.
The project also features 22 pre-packaged YAML playbooks designed to automate routine developer and operational tasks. Included playbooks cover issue-to-pull-request conversions, automated code reviews, incident response protocols, production deployment gates, CI/CD triage, security scanner management, and automated Slack digests.
The complete core repository—comprising the command-line interface, Guard execution engine, Router, Agent Booster, playbooks, and compliance modules—is distributed under the open-source Apache License 2.0. The project maintainers are actively accepting community contributions for additional playbooks, bug fixes, documentation updates, and compliance packs.
Alongside its open-source foundation, commercial operations are managed through conductai.ai, which offers a hosted enterprise control plane. The commercial layer introduces a visual canvas user interface, team-level role-based access controls (RBAC), an extension marketplace, managed Guard infrastructure, and dedicated enterprise support options.
Sources
Written by
The Company Wire
Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.



