Let AI build.
CodeMarine
stands guard.

Secure what AI writes. Verify what AI brings in. Control what AI does.

CodeMarine is the independent security control plane around Claude, Codex, Cursor and the rest of your development stack. Deterministic checks protect the continuous path. Frontier models investigate the hard cases.

CodeMarine desktop Summary view for the checkout-service demo workspace

One security layer across every AI tool your team uses.

Choose the best model for the job. CodeMarine keeps watching the code, supply chain and supported actions when the provider changes.

One independent policy Code integrity · Supply-chain trust · Runtime decisions · Security evidence Compare every integration

Frontier intelligence, with an independent safety layer.

Claude, Codex, Cursor and other frontier tools do the creative work. CodeMarine watches the shared result, checks what enters the workspace and applies deterministic policy wherever a supported control point exists.

01FRONTIER INTELLIGENCE

Build, reason and investigate.

Claude, Codex, Cursor and other frontier tools bring deep context, novel vulnerability discovery and contextual remediation.

  • BuildWrite code and operate tools
  • InvestigateReason about ambiguous or novel risk
  • FixPropose a patch with repository context
Focused evidence Proposed fixes
CODEMARINE CONTROL

Watch, verify and enforce.

CodeMarine stays on the continuous path with deterministic checks, cross-provider policy and evidence that survives the model session.

  • Secure the codeScan every resulting change
  • Verify new trustCheck packages, MCP, skills and rules
  • Control actionsEvaluate supported high-impact operations
  1. 1

    AI createsCode, tools and hypotheses

  2. 2

    CodeMarine checksCode, supply chain and supported actions

  3. 3

    AI investigatesFocused evidence for the hard cases

  4. 4

    CodeMarine validatesRescan, policy and durable evidence

Frontier intelligence. Deterministic control.

The model does the reasoning. CodeMarine keeps the result continuous, repeatable and governed.

One policy around every tool your team adopts.

Provider controls still matter. CodeMarine adds a shared layer around the codebase, software supply chain and supported agent actions. The policy remains when the model changes.

01

Deterministic decisionsThe same revision, rules and policy produce the same result.

02

Continuous coverageProtection keeps running after one agent session ends.

03

Visible limitsEvery surface is marked by its actual mechanism and health.

Your AI development stack

ClaudeCoding agent

CodexCoding agent

CursorAI editor

WindsurfAI editor

GrokFrontier model

DevinHosted agent

Independent control across every tool
CodeMarine

Continuously watches the shared workspace and applies one deterministic security policy.

CodeIntegritySupplyProvenanceActionsRuntime policyEvidenceAudit trail
{ }WorkspaceToolsCIInfrastructure

Let AI move fast without letting one bad command wreck everything.

Developers allow shell access because the agent needs it. CodeMarine checks the exact command before it runs on supported paths.

Read the Runtime Safety architecture
CodeMarine Runtime Protection view showing Claude Code and Cursor coverage
Protect your machine and codeCatch commands that can wipe folders, overwrite protected files or destroy Git history.
Protect production dataCheck database drops, truncation and broad deletes that can erase records.
Protect infrastructureCheck attempts to remove cloud resources, Kubernetes environments or Terraform-managed systems.
Protect credentialsDetect shell-visible attempts to collect secrets and send them somewhere else.
Where the guardrail works

Supported local hooks can stop an action before execution. Unconnected browsers, native APIs and remote services need another control path and are marked Not covered.

Trust is added one package and tool at a time.

Agents extend the system while they work. CodeMarine inspects the dependencies, MCP servers, skills and instructions entering that trust boundary.

  • Package identitySlopsquatting, typosquatting and known-malicious package signals
  • Install behaviorManifest, lockfile, source and install-time execution review
  • Agent extensionsMCP descriptions, plugins, skills, rules and persistent instructions
  • Instruction integrityPrompt injection and agent memory or identity-file tampering
See the full trust boundary
Sarge stopping a malicious software bug before it enters the system
Dependency review
package.jsonMODIFIED BY CURSOR
12"dependencies": {13"fastify": "^5.2.0" KNOWN14"auth-flow-utils": "^1.0.4" VERIFY15}
PROVENANCE SIGNALPackage requires review

The name is plausible but expected ownership and source are not established.

Registry UnconfirmedInstall script InspectLockfile Changed

Models investigate. CodeMarine stays in control.

CodeMarine does not try to replace frontier reasoning with a longer pattern list. It uses deterministic security for routine coverage and reserves semantic investigation for cases that deserve it.

01

Detect locally

Continuous deterministic checks find known risks without a model call.

02

Package context

Graph paths, evidence and revision data focus the investigation.

03

Investigate

An approved frontier model reasons about ambiguous or novel risk.

04

Validate

CodeMarine rescans the patch and checks policy before acceptance.

05

Retain the lesson

A verified discovery can become a deterministic regression control.

FRONTIER MODELSReason about new and context-dependent risk.
+
CODEMARINECheck continuously and enforce on proven paths.
See the governed model workflow

No blanket green shield.

Code scanning does not prove runtime containment. An installed hook does not prove the host invoked it. CodeMarine’s target status model separates coverage from operational health.

No supported blocking path and current host proof means no Guarded status.

Read the coverage contract

Code and configuration scanningDeterministic workspace path

Current

Supply-chain and agent artifact scanningDependencies, MCP, rules and skills

Current

Supported local action adaptersSetup and proof limitations apply

Beta

Live proof and Protection CenterProof registry and product UI

Planned
Sarge standing watch in a CodeMarine command center

You choose the AI. CodeMarine watches what follows.

Claude, Codex, Cursor and the rest can all touch the same codebase. CodeMarine keeps one independent watch over the code they change, the software they bring in and the supported actions they try to take.

Code changesChecked continuously, regardless of which agent or person made them.
New trustPackages, MCP servers, skills and instructions examined as they enter the workspace.
High-impact actionsEvaluated on supported control paths with the real coverage state kept visible.
The hard questions to ask any AI security layer

The questions a security buyer should ask.

Is CodeMarine a replacement for Claude Security or Codex?

No. Frontier tools are strong semantic investigators. CodeMarine provides continuous deterministic checks, software supply-chain controls and one cross-provider evidence layer. The strongest design uses both: frontier models investigate while CodeMarine keeps the routine path repeatable and governed.

Why not rely on each provider’s permission prompts?

Native permissions and sandboxes are important. They are also scoped to one provider and one execution environment. Broad prompts can interrupt normal work, which encourages people to relax them. CodeMarine is designed to add a narrow independent layer around high-confidence risks while preserving one policy across providers.

Can CodeMarine stop an agent from destroying a server?

Only when the operation passes through a supported pre-execution path. Local shell hooks can cover some actions. Native APIs, hosted agents and remote tools need a governed gateway, scoped credentials or downstream policy. CodeMarine reports the gap instead of claiming universal interception.

Does every scan call a model?

No. The continuous path is local-first and deterministic. Optional model investigation is reserved for cases that need semantic reasoning. This keeps routine protection predictable and token-efficient.

What does deterministic protection actually mean?

The same code revision, ruleset and policy should produce the same security decision. That gives CI gates, audit evidence, suppressions and regression controls a stable answer. A frontier model can still investigate the hard case, but it does not become the sole policy authority.

Does CodeMarine work across Claude, Codex, Cursor and other tools?

CodeMarine watches the shared workspace independently of the authoring tool. Provider-specific prevention still depends on the hooks and execution surfaces each tool exposes. That lets one policy cover the common result while the product reports differences in preventive coverage honestly.

Browse the full product and security FAQ

Give AI room to work. Keep a hand on authority.

CodeMarine is building the independent security layer for teams using more than one frontier development tool.

Sarge, the CodeMarine guardian