Your AI agent just ran git push --force.
CodeTrust stopped it before it executed.
AI governance enforcement platform. 2,928 rules, 9 enforcement layers, 39 MCP tools. Blocks destructive commands, catches hallucinated packages, tracks which AI model wrote every line — before damage happens.
What no other tool does
SonarQube checks quality. Snyk checks CVEs. Nobody checks what the AI agent itself is doing.
Real-Time Agent Interception
BASH_ENV guard + PreToolUse hooks block destructive commands before execution. git push, rm -rf, heredoc — all caught before damage.
AI Attribution
Per-line model tracking. GPT-5.3, Claude Opus 4.6, Gemini 3, Codex 5.3 — know which AI wrote which line. Shadow AI flagged.
Hallucination Detection
Live verification against PyPI, npm, crates.io, Go Proxy, Maven, NuGet, RubyGems, and Packagist. Hallucinated packages blocked instantly.
AI Policy Engine
Model allowlist/blocklist. Max AI ratio per commit. Attribution requirements. The CTO decides, CodeTrust enforces.
Commit & Repo Guards
Pre-commit hook scans 2,928 rules. BLOCK = rejected. Governance files protected — agents cannot change their own rules.
9 Enforcement Layers
BASH_ENV, PreToolUse hooks, MCP Gateway, pre-commit, GitHub Action, advisory files, governance config, allow-list audit, compliance frameworks. All verified by codetrust doctor.
Governance active in 30 seconds
Free tier: 25 scans/day. Detection only. No credit card.
Sign up with GitHub