diff --git a/SEO.md b/SEO.md index 752c61d..9503bff 100644 --- a/SEO.md +++ b/SEO.md @@ -148,7 +148,7 @@ not needed; the assistants that do read `llms.txt` get Mintlify's. | Page | Search intent | |---|---| -| `index` | Execution safety for AI agents · control AI agents running in your platform · works with agents you can and can't modify · any AI agent whatsapp slack claude code cursor codex chatgpt | +| `index` | stop wrong, restricted, or malicious AI agent actions · control AI agents running in your platform · works with agents you can and can't modify · any AI agent whatsapp slack claude code cursor codex chatgpt | | `execution-boundary` | what stops an agent action · AI agent execution boundary · how an agent execution boundary is adopted | | `risk-check` | AI agent execution risk assessment | | `protect-my-agent` | AI agent execution boundary, connection coverage and ctrlrun Pro/Enterprise governance for businesses | diff --git a/docs.json b/docs.json index 44a17a4..8ca9d9f 100644 --- a/docs.json +++ b/docs.json @@ -13,7 +13,7 @@ "href": "/" }, "favicon": "/images/favicon.svg", - "description": "Execution safety for AI agents. Control consequential actions before they affect real systems.", + "description": "CTRLRun stops AI agents from taking wrong, restricted, or malicious actions in your workflows. Every action is checked against your rules before it runs.", "navbar": { "links": [ { @@ -26,7 +26,7 @@ }, { "href": "/#pro-and-enterprise", - "label": "Pro and Enterprise" + "label": "Free, Pro, Enterprise" }, { "href": "https://github.com/CTRLRun/ctrlrun", diff --git a/docs/ROADMAP.md b/docs/ROADMAP.md index 2656e58..40664e7 100644 --- a/docs/ROADMAP.md +++ b/docs/ROADMAP.md @@ -304,7 +304,7 @@ Do not build: a consequence taxonomy — a budget names a metric, not a class · Exit: `ctrlrun.guarantees/v5` — G22 a budget exhausted by ambiguity refuses the next reserve until reconciled, and releases on `FAILED`, under the v0.6 multi-process standard against Postgres · G23 a scope provider that raises leaves nothing reserved and nothing executed · G24 a task-bound grant is refused on a task it does not name, by name — each with a positive control, each `N/A` with a reason on a grant that carries no budget, no scope, or no task. -**This is the gate for the homepage.** The H1 stays *Execution safety for AI agents* until v0.9 exits. After it, *action governance* is true in code, and only then does the category line move up. +**This is the gate for the category line, and it used to be the gate for the H1.** Recorded 2026-09-12: the H1 moved ahead of v0.9, to *CTRLRun stops AI agents from taking wrong, restricted, or malicious actions in your workflows*, because it states what the shipped kernel does today and claims nothing about authority. *Action governance* still waits: after v0.9 it is true in code, and only then does the category line move up. Standards: none new. diff --git a/index.mdx b/index.mdx index d81c631..378d7f9 100644 --- a/index.mdx +++ b/index.mdx @@ -1,10 +1,10 @@ --- -title: "Execution safety for AI agents" +title: "Stop wrong, restricted, or malicious AI agent actions" sidebarTitle: "CTRLRun" -description: "Execution safety for any AI agent you have: WhatsApp, Slack and Teams bots, Claude Code, Cursor, Codex, ChatGPT. Approval bound to the exact action." +description: "Every AI agent action is checked against your rules before it runs. Allowed ones go through, sensitive ones wait for a person, forbidden ones are blocked." mode: "custom" -"og:title": "CTRLRun: execution safety for AI agents" -"twitter:title": "CTRLRun: execution safety for AI agents" +"og:title": "CTRLRun: stop wrong, restricted, or malicious agent actions" +"twitter:title": "CTRLRun: stop wrong, restricted, or malicious agent actions" canonical: "https://ctrlrun.dev/" "og:url": "https://ctrlrun.dev/" --- @@ -18,15 +18,13 @@ import { CommercialTiers } from "/snippets/commercial-tiers.jsx";

THE AGENT IS PROBABILISTIC. THE ACTION IS NOT.

-

Execution safety
for AI agents.

-

Control the AI agents running in your platform. Any domain. Your rules.

-

AI action governance, not AI agent governance.
A model decides differently every run. The action it is about to take is fixed, and can be checked before it happens.

+

CTRLRun stops AI agents from taking wrong, restricted, or malicious actions in your workflows.

+

Every action is checked against your rules before it runs. Allowed actions go through. Sensitive ones wait for a person. Forbidden ones are blocked.

- Read the docs + Protect my agent GitHub

Open source · one line, any action{'@ctrlrun.protect("your.action")'}

-

Already running agents in production? Protect my agent →

ONE EXAMPLE / THE MODEL HALLUCINATES AN AMOUNT

@@ -71,12 +69,10 @@ import { CommercialTiers } from "/snippets/commercial-tiers.jsx";
-

THE SAME BOUNDARY, RUN FOR YOU

-

Open source is the boundary. Pro and Enterprise are how it is run.

-

Every tier enforces the same rules on the same actions. What changes is who runs the control plane around them, and how far the controls are shaped to your deployment.

+

FREE, PRO, ENTERPRISE

+

Free and open source: the boundary. Pro: the boundary, run for you. Enterprise: the boundary, shaped to you.

-

Running it yourself stays a first-class route: the core is Apache-2.0 and nothing here is required to use it. The Pro dashboard is in development. Start with the open-source core →

Let agents act.
Keep the consequences yours to decide.
Docs →GitHub ↗Contact ↗
diff --git a/protect-my-agent.mdx b/protect-my-agent.mdx index 2e22fe6..9ae2f8c 100644 --- a/protect-my-agent.mdx +++ b/protect-my-agent.mdx @@ -35,6 +35,6 @@ import { ArchitectureReview } from "/snippets/architecture-review.jsx"; -
Execution-safety review: where it starts

A paid architecture review of tool boundaries, approval flows, duplicate execution, uncertain outcomes and action records. You leave with an execution-control map and a prioritized plan: what can run automatically, what needs a person, and what must stop until the outcome is known.

Production Integration Sprint: the boundary into your stack

Hands-on integration, policy design, approval workflows, persistence, retry handling, reconciliation and production testing. Rollout is per workflow: pick one, agree the rules and who approves what, run it in observe mode to see what would have been blocked, then turn enforcement on.

ctrlrun Pro: governance from one dashboard

Connect your agents and workflows, manage policies, investigate activity and understand operational risk from one place, built on the same open-source foundation you can run yourself. In development. Join the waiting list ↗

ctrlrun Enterprise: governance shaped to your deployment

Everything in Pro, with our engineers to design, integrate and maintain the additional controls your business needs: custom policies, the integrations your stack requires, deployment options and the insights you ask for. This is what the review above starts.

Ongoing Production Support

A recurring engagement for new actions, policy changes, upgrades, incident analysis and rollout reviews.

-

Building it yourself? Start integrating with CTRLRun OSS →

+
Execution-safety review: where it starts

A paid architecture review of tool boundaries, approval flows, duplicate execution, uncertain outcomes and action records. You leave with an execution-control map and a prioritized plan: what can run automatically, what needs a person, and what must stop until the outcome is known.

Production Integration Sprint: the boundary into your stack

Hands-on integration, policy design, approval workflows, persistence, retry handling, reconciliation and production testing. Rollout is per workflow: pick one, agree the rules and who approves what, run it in observe mode to see what would have been blocked, then turn enforcement on.

ctrlrun Pro: integrate, analyze, protect. One dashboard

Connect your agents and workflows and see what each connection covers. Search every action, decision and outcome across your agents. Manage policies and approvals from one place, test a rule in observe mode, then turn enforcement on. Built on the open-source foundation, run by us. In development. Request early access ↗

ctrlrun Enterprise: the same product, shaped to your company

Everything in Pro, with CTRLRun engineers who design, integrate and maintain the controls your business needs: custom policies and approval chains, connectors to your internal systems, your deployment options, the reports you ask for. Scoped to your requirements, delivered with your team. This is what the review above starts.

Ongoing Production Support

A recurring engagement for new actions, policy changes, upgrades, incident analysis and rollout reviews.

+

Building it yourself? ctrlrun Open Source is free. Install it →

diff --git a/snippets/commercial-tiers.jsx b/snippets/commercial-tiers.jsx index 007a5b8..4ffbc6a 100644 --- a/snippets/commercial-tiers.jsx +++ b/snippets/commercial-tiers.jsx @@ -1,4 +1,5 @@ -// The two commercial tiers, each with the form its button asks for. The comparison table +// The three tiers. Open Source is a link to the quickstart and asks for nothing; the two +// commercial tiers each carry the form their button asks for. The comparison table // that used to sit under them is gone; the one row a reader acted on -- who does the work -- // is now a line on each card. Pro takes a place on the // waiting list, so it asks for as little as a place requires; Enterprise is the start of a @@ -17,12 +18,23 @@ export const CommercialTiers = () => { const ENDPOINT = 'https://ctrlrun-review-form.vercel.app/api/interest'; const TIERS = [ + { + intent: 'open-source', + name: 'ctrlrun Open Source', + status: 'FREE · OPEN SOURCE', + promise: 'Free. Run it yourself.', + body: 'The boundary itself, at no cost. No account, no card, no call with us. Every rule that decides is code you can read, and every action leaves a receipt you keep. Free to use and free to change, under the Apache-2.0 licence.', + who: 'Your team, on your machines.', + cta: 'Install it', + href: '/docs/get-started/quickstart', + event: 'open_source_install_clicked' + }, { intent: 'pro-waitlist', name: 'ctrlrun Pro', status: 'IN DEVELOPMENT', - promise: 'Centralized governance for your AI agents.', - body: 'Connect your agents and workflows, manage policies, investigate activity, and understand operational risk from one dashboard. Built on ctrlrun’s open-source foundation.', + promise: 'Integrate, analyze, protect. One dashboard.', + body: 'Connect your agents and workflows and see what each connection covers. Search every action, decision and outcome across your agents. Manage policies and approvals from one place, test a rule in observe mode, then turn enforcement on. Built on the open-source foundation, run by us.', who: 'Your team, on our dashboard.', cta: 'Request early access', field: 'agents', @@ -38,8 +50,8 @@ export const CommercialTiers = () => { intent: 'enterprise-contact', name: 'ctrlrun Enterprise', status: 'ENGAGEMENTS OPEN', - promise: 'AI governance tailored to your deployment.', - body: 'Everything in Pro, with ctrlrun engineers to design, integrate, and maintain the additional controls your business needs. Custom policies, integrations, deployment options, and insights, scoped to your requirements.', + promise: 'The same product, shaped to your company.', + body: 'Everything in Pro, with CTRLRun engineers who design, integrate and maintain the controls your business needs: custom policies and approval chains, connectors to your internal systems, your deployment options, the reports you ask for. Scoped to your requirements, delivered with your team.', who: 'Our engineers, with your team.', cta: 'Discuss your deployment', field: 'message', @@ -101,11 +113,14 @@ export const CommercialTiers = () => {

{tier.promise}

{tier.body}

Who does the work {tier.who}

+ {tier.href && ( + {tier.cta} + )} {sentIntent === tier.intent &&

{tier.done}

} - {sentIntent !== tier.intent && open !== tier.intent && ( + {!tier.href && sentIntent !== tier.intent && open !== tier.intent && ( )} - {sentIntent !== tier.intent && open === tier.intent && ( + {!tier.href && sentIntent !== tier.intent && open === tier.intent && (
send(event, tier)}>
diff --git a/snippets/home-slides.jsx b/snippets/home-slides.jsx index 2550863..2ec67f4 100644 --- a/snippets/home-slides.jsx +++ b/snippets/home-slides.jsx @@ -7,7 +7,7 @@ export const HomeSlides = () => { const SLIDES = [ { id: 'overview', label: 'Overview' }, { id: 'how-it-works', label: 'How it works' }, - { id: 'pro-and-enterprise', label: 'Pro and Enterprise' }, + { id: 'pro-and-enterprise', label: 'Free, Pro, Enterprise' }, ]; const LAST = SLIDES.length - 1; const [active, setActive] = useState(0); diff --git a/style.css b/style.css index 9bfb520..37f262c 100644 --- a/style.css +++ b/style.css @@ -16,7 +16,7 @@ .cr-site .cr-eyebrow,.cr-site .cr-step { font-size:10px; font-family:ui-monospace,SFMono-Regular,Consolas,monospace; font-weight:600; letter-spacing:.12em; line-height:1.6; color:var(--cr-muted); } .cr-site .cr-eyebrow { margin-bottom:20px; } .cr-dot { color:var(--cr-accent); } -.cr-lede .cr-mark { color:var(--cr-accent); font-weight:600; } +.cr-lede .cr-mark,.cr-site h1 .cr-mark { color:var(--cr-accent); font-weight:600; } .cr-hero { padding:80px 0 52px; max-width:830px; } .cr-hero h1 { margin-bottom:25px; } .cr-site .cr-lede { margin-top:24px; font-size:21px; color:var(--cr-ink); letter-spacing:-.015em; } @@ -262,8 +262,8 @@ body:has(.cr-site) { --topbar-tabs-height:0px; } .cr-home .cr-button,.cr-try-page .cr-button,.cr-home .cr-text-link,.cr-try-page .cr-text-link { font-size:14px; } .cr-home .cr-home-hero { display:grid; grid-template-columns:1fr 1.1fr; gap:72px; align-items:start; padding:64px 0 84px; } .cr-home-pitch { padding-top:30px; } -.cr-home h1 { font-size:clamp(40px,4.7vw,60px); line-height:1.08; } -.cr-home .cr-lede { font-size:22px; line-height:1.55; max-width:430px; } +.cr-home h1 { font-size:clamp(34px,3.3vw,46px); line-height:1.12; } +.cr-home .cr-lede { font-size:18px; line-height:1.6; max-width:480px; } .cr-home .cr-actions { gap:18px 24px; margin:36px 0 0; } .cr-site .cr-hero-aside { margin-top:30px; font-size:14px; line-height:1.6; color:var(--cr-muted); } .cr-hero-aside a { color:var(--cr-accent); font-weight:550; text-decoration:underline; text-underline-offset:4px; text-decoration-thickness:1px; } @@ -320,7 +320,7 @@ body:has(.cr-subpage) #search-bar-entry-mobile,body:has(.cr-subpage) #assistant- @media (max-width:800px) { .cr-home .cr-home-hero { grid-template-columns:1fr; padding:44px 0 60px; gap:40px; } .cr-home .cr-section { padding:72px 0; } - .cr-home h1 { font-size:clamp(38px,7vw,56px); } + .cr-home h1 { font-size:clamp(30px,6vw,40px); } .cr-home .cr-section-heading { align-items:flex-start; flex-direction:column; } } @media (max-width:600px) { @@ -430,7 +430,7 @@ body:has(.cr-subpage) #search-bar-entry-mobile,body:has(.cr-subpage) #assistant- .cr-site .cr-commercial-head h3 { font-size:23px; letter-spacing:-.02em; margin:0 0 10px; } .cr-site .cr-commercial-head p { margin:0; font-size:14.5px; line-height:1.7; color:var(--cr-muted); } .cr-site .cr-commercial-head h2 + p { margin-top:14px; } -.cr-tiers { display:grid; grid-template-columns:repeat(2,minmax(0,1fr)); gap:24px; } +.cr-tiers { display:grid; grid-template-columns:repeat(3,minmax(0,1fr)); gap:24px; } .cr-tier { display:flex; flex-direction:column; align-items:flex-start; gap:10px; padding:24px; border:1px solid var(--cr-line); border-radius:6px; background:var(--cr-paper); min-width:0; } .cr-tier .cr-step { color:var(--cr-accent); } .cr-site .cr-tier h3 { font-size:21px; letter-spacing:-.02em; margin:0; } @@ -438,7 +438,7 @@ body:has(.cr-subpage) #search-bar-entry-mobile,body:has(.cr-subpage) #assistant- .cr-site .cr-tier-body { margin:0; font-size:14px; line-height:1.7; color:var(--cr-muted); } .cr-site .cr-tier-who { display:flex; flex-wrap:wrap; gap:4px 10px; margin:2px 0 0; font-size:13.5px; color:var(--cr-ink); } .cr-tier-who span { font:600 10px/2 ui-monospace,SFMono-Regular,Consolas,monospace; letter-spacing:.1em; text-transform:uppercase; color:var(--cr-muted); } -.cr-tier .cr-button { margin-top:6px; } +.cr-tier > .cr-button { margin-top:auto; } .cr-tier-open { border-color:var(--cr-accent); } .cr-tier-form { width:100%; margin-top:6px; } .cr-tier-form fieldset { display:flex; flex-direction:column; gap:12px; border:0; margin:0; padding:0; } @@ -447,7 +447,7 @@ body:has(.cr-subpage) #search-bar-entry-mobile,body:has(.cr-subpage) #assistant- .cr-site .cr-tier-done { margin:6px 0 0; padding:14px 16px; border:1px solid var(--cr-accent); border-radius:5px; font-size:14px; line-height:1.65; color:var(--cr-ink); background:var(--cr-panel); } .cr-site .cr-commercial > .cr-caption { margin-top:18px; } .cr-commercial .cr-caption a { text-decoration:underline; text-underline-offset:3px; } -@media (max-width:800px) { +@media (max-width:1000px) { .cr-tiers { grid-template-columns:1fr; } } .cr-site .cr-surfaces { list-style:none; padding:0; margin:34px 0 0; display:flex; flex-direction:column; gap:20px; } @@ -470,7 +470,7 @@ body:has(.cr-subpage) #search-bar-entry-mobile,body:has(.cr-subpage) #assistant- } @media (max-width:600px) { .cr-home .cr-home-hero { padding:36px 0 52px; gap:34px; } - .cr-home .cr-lede { font-size:19px; } + .cr-home .cr-lede { font-size:17px; } .cr-how-intro { margin-bottom:32px; } } @@ -493,8 +493,8 @@ body:has(.cr-subpage) #search-bar-entry-mobile,body:has(.cr-subpage) #assistant- align-items:center; } .cr-home .cr-home-pitch { padding-top:0; } -.cr-home h1 { font-size:clamp(42px,4.6vw,64px); } -.cr-home .cr-lede { max-width:480px; margin-top:30px; } +.cr-home h1 { font-size:clamp(34px,3.3vw,46px); } +.cr-home .cr-lede { max-width:520px; margin-top:24px; } .cr-home .cr-hero-context { margin-top:24px; max-width:460px; font-size:15px; line-height:1.75; } .cr-home .cr-actions { margin-top:36px; } .cr-site .cr-hero-oneline { display:flex; flex-wrap:wrap; align-items:center; gap:8px 14px; margin-top:26px; font-size:12px; line-height:1.6; } @@ -508,8 +508,8 @@ body:has(.cr-subpage) #search-bar-entry-mobile,body:has(.cr-subpage) #assistant- /* Agents you can and can't modify: one compact band across both hero columns, so it is read with the pitch and the first slide still fits a 720px-tall screen. */ .cr-home > .cr-home-hero { row-gap:28px; } -.cr-site .cr-any-agent { grid-column:1 / -1; display:grid; grid-template-columns:auto minmax(0,1fr) auto; align-items:center; gap:10px 28px; padding:14px 22px; border:1px solid var(--cr-accent); border-radius:6px; background:var(--cr-panel); box-shadow:inset 4px 0 0 var(--cr-accent); text-decoration:none; transition:background .15s; } -.cr-site .cr-any-agent:hover { background:var(--cr-paper); } +.cr-site .cr-any-agent { grid-column:1 / -1; display:grid; grid-template-columns:auto minmax(0,1fr) auto; align-items:center; gap:10px 28px; padding:14px 22px; border:1px solid var(--cr-line); border-radius:6px; background:var(--cr-paper); text-decoration:none; transition:border-color .15s; } +.cr-site .cr-any-agent:hover { border-color:var(--cr-accent); } .cr-site .cr-any-agent h2 { margin:0; font-size:clamp(17px,1.45vw,20px); line-height:1.25; letter-spacing:-.015em; white-space:nowrap; } .cr-site .cr-any-agent p { margin:0; font-size:14px; line-height:1.5; } .cr-any-agent p b { color:var(--cr-ink); font-weight:600; } @@ -572,7 +572,7 @@ body:has(.cr-subpage) #search-bar-entry-mobile,body:has(.cr-subpage) #assistant- .cr-home > .cr-home-hero,.cr-home > .cr-section { min-height:0; padding-block:64px; } .cr-home > .cr-home-hero { grid-template-columns:1fr; gap:44px; } .cr-home .cr-home-pitch { max-width:580px; } - .cr-home h1 { font-size:clamp(40px,7vw,56px); } + .cr-home h1 { font-size:clamp(30px,6vw,40px); } .cr-home .cr-section-heading { align-items:flex-start; gap:16px; } .cr-home .cr-integration { grid-template-columns:1fr; gap:40px; } .cr-home .cr-planned-work { grid-template-columns:1fr; gap:16px; }