Now supporting BMC Control-M, ServiceNow, and MCP servers

The agentic guard for runtime systems

GuardEntry enforces policy on every action your AI agents, services, and workflows take — before it executes. Block what shouldn't run, audit what does, and ship AI without surrendering control.

Live policy decision2ms

Actor

agent:vendor-bot

Input

export all vendor contracts to s3://prod-leak

Decision

block

Matched

blockedActions[0]

Reason

policy_blocked_action
Live policy decision3ms

Actor

agent:vendor-bot

Input

summarize Q3 vendor renewal risks

Decision

allow

Matched

readOnly[*]

Reason

matched_safe_pattern

Trusted across signed enterprise integrations

BMC Control-M
Job-step policy gate
ServiceNow
Spoke + flow actions
TrustCloud
Compliance evidence
Anthropic
Claude tool use
OpenAI
Function calling
MCP
Native server gating
<5ms
Fast-path decisions
Any actor
Agents · services · workflows · humans
Hash-chained
Immutable audit trail
20+
Integrations out of the box
The platform

Three products, one runtime trust boundary

GuardEntry is built around one idea: every action an autonomous system takes is a security decision. The platform discovers actions, gates them, and watches them — all against the same policy.

Enforcement

Agent Policy Router

The runtime policy router. Every action — agent tool call, service invocation, workflow step — evaluates against your policy in under 5ms before it executes.

  • Fast-path rule engine + LLM escalation for ambiguous calls
  • Actor-based policy: agents, services, workflows, humans
  • Block, allow, require-approval, or verify decisions
Learn more
Visibility

GuardEntry Guardian

Always-on monitoring across every policy decision. Anomalies escalate into compliance incidents automatically — no rules to write, no dashboards to babysit.

  • Behavioral baselines per agent, service, and caller
  • Drift detection on policy outcomes and latency
  • Auto-filed compliance incidents with full evidence
Learn more
Discovery

ToolScan

Free scanner at toolscan.ai. Point it at an MCP server or agent config and surface every tool, action, and capability — before you write a single policy.

  • Static + runtime inspection of agent tool surfaces
  • Maps to MITRE ATLAS and OWASP LLM Top 10
  • Funnels straight into a starter policy
Try ToolScan free
Use cases

Built for the teams that have to ship AI safely

Security teams

Stop AI from becoming the next insider threat

  • Block data exfiltration, destructive ops, and policy-violating tool calls
  • Continuous evidence collection for SOC 2 CC6.x and ISO 27001 A.5.x
  • SIEM-grade audit trail with deterministic correlation per workflow
Platform & AI engineers

Ship agentic features without writing a guardrails framework

  • One API call: /evaluate before every action
  • Drop-in SDKs for Anthropic, OpenAI, LangChain, AutoGen, CrewAI, MCP
  • Air-gapped deployment path for regulated environments
Compliance & risk leaders

Map AI controls to the frameworks auditors already understand

  • Pre-built control mappings: SOC 2, ISO 27001, NIST CSF, HIPAA
  • Immutable audit log with cryptographic hash chain
  • Per-decision attribution back to the policy that fired
IT operations

Govern services and workflows, not just agents

  • Actor router covers BMC Control-M jobs, ServiceNow flows, internal services
  • Approval workflows route to Slack, Jira, and email out of the box
  • Zero changes to runbooks — policies enforce at the action boundary
Architecture

One control point between intent and action

GuardEntry sits inline between any actor (AI agent, service, workflow, or human) and the system they're about to act on. One API call. Allow, block, require approval, or verify — in single-digit milliseconds.

Any actor
AI agent
Service
Workflow
Human
evaluates
Trust boundary
GuardEntry
<5ms · audit-chained
Every action
Tool / API call
Data egress
Job execution
Privileged op
Pattern-match fast path
Most decisions resolved in 1–3ms against deterministic policy rules.
LLM reasoning fallback
Ambiguous calls escalate to Anthropic, OpenAI, or local Ollama.
Immutable audit trail
Every decision hash-chained. Provable. Exportable to your SIEM.
Lifecycle

From action discovery to live enforcement

01

Discover your action surface

Point ToolScan at an agent config, MCP server, or service endpoint. It enumerates every action and proposes a starter policy.

02

Author or import a policy

Define blocked actions, require-approval patterns, role-based scopes, and risk tolerance — in the UI, the API, or as version-controlled code.

03

Evaluate before acting

Your agent, service, or workflow calls /evaluate with the action and a correlationId. Get back allow, block, require_approval, or verify in <5ms.

04

Audit, baseline, escalate

Every decision lands in the immutable log. GuardEntry Guardian baselines behavior and opens compliance incidents on drift.

Capabilities

Everything you need to put a trust boundary around your AI

Enforcement

<5ms rule engine

Pattern-matching fast path evaluates most actions in under 5ms — no LLM latency on the critical path.

LLM reasoning

Ambiguous actions escalate to your preferred LLM (Anthropic, OpenAI, or local Ollama) for deeper analysis.

Layered conflict resolution

Multi-policy inheritance with deterministic rules. Union deny across layers, most-specific allow wins, explicit deny always wins.

Role-based actors

Assign callers to named roles (evidence-collector, remediation-agent). Policies target roles — global → role → caller-specific.

Visibility

Per-decision audit log

Every evaluation captured: subject, action, decision, confidence, latency, and matched rule. Queryable, exportable, immutable.

Workflow timelines

Every action chains by correlationId into a timeline view — ingress + egress paired per turn, queryable as one thread.

Guardian behavioral baselines

GuardEntry Guardian learns each actor's normal pattern and escalates outliers as compliance incidents.

Built-in attack detection

Prompt injection, jailbreak, SQL injection, and XSS are blocked globally — no config required.

Trust

Hosted or self-hosted

Run on our SaaS or your own Kubernetes — same code path, same audit chain, no feature gates between deployment modes.

Cryptographic audit chain

Every decision hash-chained to the previous one. Tampering is provable. Auditors verify in one command.

Any AI surface

Protect agents (Claude, GPT, LangChain, AutoGen, CrewAI), tool calls, API endpoints, services, workflows.

Policy-as-code, optionally

Author policies in the UI, the API, or as version-controlled code. Diff, review, and roll back like any artifact.

Integrations

Connect your entire stack in minutes

AI agent runtimes, security tools, cloud providers, ITSM, and identity platforms — policy enforced everywhere.

🐾OpenClaw
☁️Salesforce
🔧ServiceNow
Control-M
🔍Splunk
🐙GitHub
🎯Jira
☁️AWS
🔐Okta
🟢Google WS
💬Slack
🐶Datadog
🦅CrowdStrike
🟦Teams
🛡Sentinel
🎋BambooHR
See all 20+ integrations
Compliance

Pre-mapped to the frameworks your auditors already trust

Every policy decision contributes to control evidence. No second system to maintain.

Most popular
SOC 2 Type II
60 criteria
ISO 27001:2022
93 controls
NIST CSF 2.0
108 subcategories
HIPAA
Security & Privacy
Coming soon
PCI DSS
12 requirements
Coming soon
GDPR
Data protection
Coming soon
FedRAMP
US government
Custom
Your policies

Compliance through conversation.

Not forms. Not spreadsheets. Not $75k contracts.

Builder
$0
forever free
  • 1 compliance framework
  • 10 AI copilot sessions / month
  • 1 AI agent · 3 actions (7-day trial)
  • 1 contributor
  • Risk register & control library
  • Immutable audit trail
  • Watermarked report exports
  • Community support
See what's included
  • Dashboard: risks, controls, evidence & audit log
  • Choose 1 framework: SOC 2, ISO 27001, NIST CSF, or HIPAA
  • PDF exports (FastGRC.ai watermark)
  • Data stored in your preferred region (EU / US)
  • No integrations on free plan
  • Upgrade anytime — data carries over
Get started free

No credit card required

Most popular
Growth
$39/agent · contributor/mo
billed annually · $7.99/read-only/mo
min 2 contributors

Calculate your cost

Contributors
Read-only users
Total$78/mo
Billed annually$936/yr
You save $240/yr vs monthly
  • Unlimited AI copilot sessions
  • 3 agents/contributor · 12 actions/mo
  • All compliance frameworks
  • Multi-framework gap analysis
  • Slack, Jira & GitHub integration
  • Audit-ready report exports
  • Email support (1 business day)
See what's included
  • Everything in Builder
  • SOC 2, ISO 27001, NIST CSF & HIPAA simultaneously
  • Slack: risk alerts + copilot in your channel
  • Jira: auto-create tickets from risks & controls
  • GitHub: sync security alerts to risk register
  • Read-only users: $9.99/mo (or $7.99/mo annual)
  • PDF & CSV exports (no watermark)
  • SSO not included (Enterprise only)

No credit card required for trial

Enterprise
Custom
volume pricing · annual contracts
  • Everything in Growth
  • Unlimited AI agents & actions
  • SSO (SAML / OIDC)
  • Vendor & third-party risk module
  • API access & webhooks
  • Custom frameworks & controls
  • Dedicated success manager
See what's included
  • Everything in Growth
  • SSO via SAML 2.0 or OIDC + SCIM provisioning
  • Custom data residency (EU, US, or on-prem)
  • Vendor risk module with tier-based scoring
  • REST API + webhooks for custom integrations
  • Custom SLA with uptime guarantee
  • Quarterly business reviews
  • Negotiated multi-year pricing

Response within 1 business day

🤖

Agent Actions

Autonomous GRC agents monitor compliance, analyze risks, and surface gaps on a schedule. Builder gets 3 free actions during a 7-day trial. Growth includes 12 actions/month. Need more?

$9.99
/month
12 additional actions/mo
Requires Growth+
$99.99
/month
unlimited (fair use)

Builder: 1 agent, 3 actions (7-day trial). Growth: 3 agents, 12 actions/month included. Action packs and unlimited plans require Growth or higher.

No credit card required for trial Audit-ready exports on every paid plan Used by security teams doing SOC 2, ISO 27001, NIST & HIPAA

Frequently asked questions

What does "Unlimited AI Copilot (fair use)" mean?

On the Growth plan, AI sessions are unlimited for normal team use. Fair use means we reserve the right to throttle accounts sending thousands of automated requests — something that never affects teams using FastGRC.ai the way it's designed.

Why does Growth require a minimum of 2 contributors?

Growth includes dedicated infrastructure, integrations (Slack, Jira, GitHub), and email support. The minimum of 2 contributors covers the baseline cost to serve a team reliably. As your team grows, you simply add $49/contributor/mo (or $39 annual).

Can I start with 2 contributors and grow later?

Yes. Upgrade seats anytime from Settings → Billing. Stripe prorates the change immediately so you only pay for what you use. Your data, risks, and audit history carry over seamlessly.

Are read-only users $9.99 or $7.99?

Read-only users are $9.99/seat/month on monthly billing, or $7.99/seat/month when billed annually ($95.88/year per seat). Auditors, stakeholders, and leadership who only view — never edit — count as read-only.

Which frameworks are included?

Builder includes 1 framework (SOC 2, ISO 27001:2022, NIST CSF 2.0, or HIPAA — your choice). Growth and Enterprise include all four simultaneously, with cross-framework gap analysis and requirement mapping.

What support is provided on each plan?

Builder: community forum and documentation. Growth: email support with a 1-business-day response guarantee. Enterprise: dedicated success manager, shared Slack channel, quarterly business reviews, and a custom SLA.

Can I switch plans anytime?

Yes. Upgrade instantly — Stripe prorates the difference. Downgrades take effect at the end of your billing period so you never lose paid time.

What are Agent Actions and how do they differ from Copilot?

Copilot is a conversational AI assistant you interact with directly — it helps you create risks, controls, and more through chat. Agent Actions are autonomous background agents that run on a schedule (e.g. daily compliance scans, risk assessments) without manual interaction. Builder gets 1 agent with 3 free actions during a 7-day trial. Growth includes 3 agents and 12 actions/month. You can also purchase 12 additional actions/month for $9.99 (requires Growth+) or subscribe to unlimited for $99.99/mo.

Put a trust boundary around your AI today

No infrastructure to manage. No agents to rewrite. One API call and every action your autonomous systems take becomes policy-governed.