Quickstart
Create an API key, install an SDK, and authorize one export. Start here.
Vulnify decides what an AI agent is allowed to do before the action runs. The agent, or the code around it, describes the action. Vulnify returns ALLOW, REVIEW, or BLOCK in real time. A review waits for a person, for example in Slack. Every decision is appended to a hash-chained audit log.
Vulnify is a runtime authorization layer. It does not scan machines or source code for vulnerabilities. It governs what agents and automations can access and do.
The product is in early access. The web app is app.vulnify.io. The API is https://api.vulnify.io.
A check sends action metadata: the agent, the action, the resource, the destination, and how many records are affected. Vulnify is designed to store that metadata, not the contents of your records.
You can optionally send content so the server can scan it for sensitive data. Matches come back as findings. The content itself is not stored. See Risk engine.
| Decision | What it means |
|---|---|
ALLOW |
Run the action. |
REVIEW |
Do not run the action. A person has to approve it. |
BLOCK |
Do not run the action. |
In monitor mode the event is stored and not enforced. Follow finalDecision, which matches the recorded decision when there is no review. evaluatedDecision is what enforcement would have returned. If Vulnify cannot be reached, the SDKs fail closed by default and return BLOCK. A rejected request, including a body over 200 KB, throws instead.
ALLOW. This is the path the SDKs implement.ALLOW, and the agent never sees it.Quickstart
Create an API key, install an SDK, and authorize one export. Start here.
Decisions
ALLOW, REVIEW, BLOCK, monitor mode, and fail-closed. Read the model.
Node.js and Python
API reference
POST /v1/events and the gateway, authenticated with an API key. Open the reference.
Policies as code
Pull, test, and apply policies from YAML. Open the CLI guide.