Panguard AI icon

Panguard AI

Reclamar

Panguard AI is an open-source security platform for AI agents that scans skills and MCP servers before they run and protects agent actions at runtime.

Panguard AI

Open-source security for AI agents

Panguard AI is an open-source security platform for AI agents. Its core job is to scan skills and MCP servers before they run, then protect agent actions at runtime using the ATR rulebook, which the site positions as an agent-era counterpart to shared detection standards such as CVE and Sigma.

The product is aimed at developers and regulated teams that need practical controls and evidence, not just alerts. The site says the community edition is MIT-licensed, self-hosted, zero-telemetry, and free forever, while paid plans add signed compliance evidence reporting, enterprise deployment options, and support for on-prem, VPC, and airgapped environments.

Key capabilities

Pre-execution skill and MCP scanning

Scans AI agent skills and MCP servers before the agent loads them, using ATR rules to detect prompt injection, tool poisoning, malicious MCP content, and supply-chain threats.

Runtime guard behavior

Runs protections at runtime as agents act, so detections are not limited to a one-time preflight review.

Multiple security layers

Describes an optional deceive-and-respond layer in the pricing page, alongside protect and detect, for broader security workflows.

Evidence and compliance outputs

Produces signed, audit-ready evidence in PDF and JSON, with SHA-256 and Merkle-tree signing and framework mappings for compliance review.

Rule-based detection and updates

Uses an ATR rulebook that is local-first and deterministic, with rule updates distributed through the Threat Cloud and community rule contributions.

CLI-first deployment and operations

Provides command-line workflows such as scan, audit, guard, and status, with one-command installation and self-hosted operation.

Common use cases

  • Pre-deployment review of agent skills

    Before deploying a skill or MCP server, a developer can scan it for prompt injection, tool poisoning, or other rule-based threats and review the findings before the agent loads it.

  • Ongoing runtime protection

    Teams that want continuous protection can run the guard and status workflows to monitor agent activity after rollout instead of relying only on one-time audits.

  • Audit and compliance evidence

    Regulated organizations can use the signed PDF or JSON outputs, framework mappings, and evidence packs to support security reviews and compliance discussions.

  • Self-hosted deployment with local control

    Organizations that prefer local control can use the self-hosted community edition, which the site says runs offline and has zero telemetry.

  • Enterprise security operations

    Enterprise teams can use the on-prem, VPC, or airgap options and connect the platform to SSO and SIEM workflows for larger deployments.

Pros and Cons

Pros

  • Covers both pre-run scanning and runtime protection for AI agent workflows.
  • Provides signed, audit-ready evidence rather than only detection alerts.
  • Community edition is free, open source, MIT licensed, and self-hosted.
  • Supports command-line workflows and one-command installation.
  • Offers explicit enterprise deployment options such as on-prem, VPC, and airgap.

Cons

  • Some capabilities on the site are described at a platform level, so the public pages do not fully separate every feature into a standalone product workflow.
  • Enterprise pricing and some advanced deployment capabilities are sales-led, so teams that need those options will need to contact sales.

FAQ

What does Panguard AI do?

Panguard AI is built to scan AI agent skills and MCP servers before they run, then protect agent actions at runtime. The source also describes a free open-source community edition and a paid Enterprise add-on for teams that need signed compliance evidence reporting.

Is there a free version?

The pricing page says Community is available today at $0 forever, with MIT-licensed open-source access. Paid offerings include a $25K one-time Founding Pilot and sales-led Enterprise plans starting at $150K+ per year.

How is it set up and operated?

The site says you can install with one command and that the Community edition is self-hosted, zero telemetry, and runs offline. The pricing page also lists pga CLI commands for scan, audit, guard, and status.

What outputs does it generate?

The product pages say Panguard AI can scan skills and MCP servers, protect agent actions at runtime, and emit signed, audit-ready evidence. The pricing and enterprise pages also describe PDF and JSON outputs, SHA-256 and Merkle-tree signing, and compliance mapping.

Is it meant for teams and regulated environments?

The pricing page says Enterprise & up includes on-prem, airgap, SSO, and SIEM support, while the enterprise specification adds SAML SSO, SCIM, SIEM webhook, and audit-log export. Community is self-hosted and runs on-device.

Quick Facts

Category
AI agent security
Source domain
panguard.ai
License
MIT / open source for Community
Deployment
Self-hosted; enterprise options include on-prem, VPC, and airgap
Primary users
Developers, AI vendors, regulated teams, and enterprises
Command-line workflow
scan, audit, guard, status