Each one is a plugin to a coding agent, and each runs a deterministic check — no model call at check time. Start where your problem is: the code an agent writes, what an agent is allowed to do, or the outcome you are designing toward.
Six tools in one lifecycle around one deterministic gate — they run in order, and each hands the next an artifact rather than a claim — and a seventh that draws what any of them produced.
The same substrate pointed at a different question: not “is this call acceptable?” but “can this session ever reach a situation it must never be in?” The argument, the tools and the reading in one place →
.claude settings and MCP config and determines whether your policy allows a path from untrusted input to credential or source egress.
polyflowrun agent workflowsOperate
A workflow engine for AI agents. Admits a workflow only if it model-checks, then runs it durably and hands the agent one work order at a time.
polycrewcrew a runOperate
Several agents — and the people among them — on one polyflow run at the same time: a shared broker, orders one of them can claim, no order done twice, and a journal that says who did what.
polysecmandate + red linesVerify
Treats a leak as a reachable state rather than a clever prompt, and checks the guardrail on every path before it ships.
polymanenforce policyOperate
Sits between an agent and its tools, tracks what the session has touched, and refuses the call that would complete the leak — before it runs.
Our digital-twin design platform is a separate line of work, and it is not something you install. It runs as a hosted platform in soft launch, by invitation. See what it does →