PyxGrant / Pilot

A 30-day Evidence Pilot. Observe only.

One team, their laptops and CI runners, and the MCP servers they use. Thirty days in observe mode: PyxGrant decides every routed call, records what it would have refused or held, and lets the call through. You leave with a signed pack a security owner can hand to their boss. Nothing is enforced. We do not publish a price.

The first yes

Thirty days, one deliverable, no enforcement.

This step does not need a written agreement or a security review of the build. Those belong to phase two, if you want to enforce.

WHO

One engineering team

Developers running Cursor, Claude Code, or CI agents with MCP tools, and the security owner who will read the pack.

HOW LONG

30 days

Install in the first days, observe for the rest of the month, then export the pack. Observe mode can run longer; thirty days is the window we treat as a finished first step.

IN

What it covers

  • Finding the team's agents and MCP servers
  • The MCP proxy on the servers you choose
  • The Claude Code and Cursor hook for built-in shell and file tools
  • Observe findings, stats, and the signed audit log
OUT

What it leaves out

  • Refusals and holds. Observe mode protects nothing.
  • The operator console as a required deliverable
  • Host-wide file and syscall monitoring. Your EDR keeps it.
  • Kernel-level enforcement, and a published price
What you take to your boss

A signed evidence pack, not a slide deck from us.

The pack is produced on your machines. An auditor verifies it with your public key, without help from us. That is also the document you can hand an insurer if they ask what the agents did.

01

Coverage

Which of the team's agents and MCP servers were found and routed, and which still run outside PyxGrant. pyxgrant processes

02

What it would have stopped

Every call it would have refused or held, recorded as an observe: finding, with a count of the ones that look like wrong refusals. pyxgrant stats

03

Time per call

What the gateway adds on your hardware, at the median and the slow tail. We do not quote a number from ours. pyxgrant perf

04

The signed pack

pyxgrant report writes the findings, the coverage, and the receipts. pyxgrant audit checks the hash chain. Your public key verifies the pack without our binary in the room.

Setup

Install, route, watch.

PyxGrant decides every routed call exactly as it would, records what it would have refused or held, and lets the call through. Redaction still applies.

  1. Install and check.Put the binary on each machine, write a starting policy, and confirm the host is ready. pyxgrant policy init pyxgrant selftest
  2. Find what's running.List the coding agents on each machine, every MCP server they load, ungoverned local model ports, and any plaintext secrets in their configs. pyxgrant agents scan pyxgrant discover
  3. Route the tools.Rewrite each MCP client config so its servers run behind PyxGrant, moving tokens into the OS vault, and install the hook for built-in tools. pyxgrant wrap -config .cursor/mcp.json -vault
  4. Observe for 30 days.Set "enforcement": "observe" in the policy. Nothing is refused or held. Each call it would have stopped is recorded as an observe: finding.
  5. Export the pack.Write the report and verify the chain on your machines. pyxgrant report pyxgrant audit

The quickstart has the exact commands →

Phase two

Enforce, if the pack is enough to say yes.

The current heavier plan — written scope, a security review of the build, least-privilege policy, and the console — starts here. It is not required to begin the Evidence Pilot.

  1. Review the pack together.Every observe finding that shouldn't have fired is counted and fixed with a policy change before anything is refused.
  2. Agree the enforce scope in writing.Who is covered, success criteria, a named contact on each side for refusals that block work, and support terms. A security review against this build, including pyxgrant boundaries.
  3. Tune, then enforce.Propose a least-privilege policy from what the team actually used, check it against the recorded calls, then switch to enforce. pyxgrant policy learn pyxgrant replay -candidate new.json
  4. Operate.Held calls, signed approvals, freeze, and pyxgrant console for the security owner. Enforce mode fails closed. A held call that nobody answers is refused after ten minutes.

Limits to plan around

  • Observe mode protects nothing. It is a trial. Calls it would refuse still go through, so run it where that is acceptable.
  • Only routed actions are seen. An agent without the hook, or a server left out of the config, is not. pyxgrant reconcile names calls that went around it, if you supply the provider's audit export.
  • Detection has edges. Data protection is pattern-based, and prompt injection is not solved.
  • No published price. We do not list a number on this site. Ask when you request the pilot.

Before phase two

  • A security review against this build, including pyxgrant boundaries, the product's own list of what it doesn't do
  • The enforce scope, success criteria, and support terms agreed in writing
  • A named contact on each side for refusals that block work

What each path covers →

Request the 30-day Evidence Pilot.

Tell us which agents and MCP servers the team uses. We'll reply with install steps for observe mode, not a contract.