Desktop app
Runs on your machine. Nothing leaves it: policies, ledger and keys stay local.
EDR for AI agents · Invite-only beta
Simam checks every tool call your AI agents and MCP servers make against identity, policy, budget and human approval before it runs, then seals it into a tamper-evident evidence ledger. Local-first or in the cloud.
Demo replay
rm -rf /Simam stopped it before it ran, and kept the receipt.
$ agent.run("clean up the repo")
→ git.status allowed
→ fs.list ./ allowed
→ shell.exec "rm -rf / --no-preserve-root"
policy destructive_shell · BLOCKED
ledger #4812 sealed · sha256 9f3a…c21e · prev 71bd…04e2
→ github.push --force awaiting approval
How it works
Every agent carries its own key. Unknown callers never reach a tool.
Rules on tools, arguments and destinations: allow, hold for approval, or block.
Per-agent spend limits stop runaway loops before the invoice does.
Risky actions wait for a human. One click approves or denies.
Each decision is hash-chained into a ledger you can verify, not just read.
The console
Deploy your way
Runs on your machine. Nothing leaves it: policies, ledger and keys stay local.
One console for your team, with roles and approvals. Now in invite-only beta.
Join the invite-only beta. We approve new accounts by hand.
Join the betaAligned with OWASP LLM Top 10 · OWASP Agentic Security · MITRE ATLAS