knox
Sign in Get started
AI GOVERNANCE MEMBRANE

The governance layer your AI works through.

Knox Membrane sits between your AI agents and your real systems. Every action crosses it: scope set by you, claims checked against records, risky acts stopped at the gate, everything recorded.

Get started → Sign in
Works with Claude today. Built to govern any AI.
K
N
O
X
CLAUDE GPT XAI GROK GEMINI LLAMA MISTRAL QWEN DEEPSEEK CLAUDE GPT XAI GROK GEMINI LLAMA MISTRAL QWEN DEEPSEEK CLAUDE GPT XAI GROK GEMINI LLAMA MISTRAL QWEN DEEPSEEK CLAUDE GPT XAI GROK GEMINI LLAMA MISTRAL QWEN DEEPSEEK
GROK GEMINI LLAMA MISTRAL QWEN DEEPSEEK CLAUDE GPT XAI GROK GEMINI LLAMA MISTRAL QWEN DEEPSEEK CLAUDE GPT XAI GROK GEMINI LLAMA MISTRAL QWEN DEEPSEEK CLAUDE GPT XAI GROK GEMINI LLAMA MISTRAL QWEN DEEPSEEK CLAUDE GPT XAI
GEMINI LLAMA MISTRAL QWEN DEEPSEEK CLAUDE GPT XAI GROK GEMINI LLAMA MISTRAL QWEN DEEPSEEK CLAUDE GPT XAI GROK GEMINI LLAMA MISTRAL QWEN DEEPSEEK CLAUDE GPT XAI GROK GEMINI LLAMA MISTRAL QWEN DEEPSEEK CLAUDE GPT XAI GROK
QWEN DEEPSEEK CLAUDE GPT XAI GROK GEMINI LLAMA MISTRAL QWEN DEEPSEEK CLAUDE GPT XAI GROK GEMINI LLAMA MISTRAL QWEN DEEPSEEK CLAUDE GPT XAI GROK GEMINI LLAMA MISTRAL QWEN DEEPSEEK CLAUDE GPT XAI GROK GEMINI LLAMA MISTRAL
CLAUDE GPT XAI GROK GEMINI LLAMA MISTRAL QWEN DEEPSEEK CLAUDE GPT XAI GROK GEMINI LLAMA MISTRAL QWEN DEEPSEEK CLAUDE GPT XAI GROK GEMINI LLAMA MISTRAL QWEN DEEPSEEK CLAUDE GPT XAI GROK GEMINI LLAMA MISTRAL QWEN DEEPSEEK
AI GOVERNANCE MEMBRANE
01 / THE PROBLEM

Your agents already act on real code, data and operations. Mostly unsupervised.

They drift from the task, answer from memory instead of records, and can take irreversible steps before anyone looks. Knox does not replace your AI. It is the layer your AI works through, and its gates refuse rather than warn.

02 / WHAT KNOX IS

Four parts, one crossing.

How it works →
01

Membrane and gates

You set the scope before work starts. Gates the agent cannot route around stop unauthorised acts.

02

Verified memory

Git as the source of truth, a database index and semantic recall. Answers come from records, not guesses.

03

Governed tools

A versioned set of instruments, checked before they ship and on every change.

04

The record

Every act is logged with who did it, so work can be audited and replicated.

THE ONE RULE

Knox must be the agent's only way in.

A gate only protects the path through it. Give your AI a second route — its own GitHub or database connector, a shell, a direct login — and it can walk around the membrane, unseen. Setting up Knox includes removing those other connections.

Your AI KNOX Repo · Database · Computers
✓One door. Every act checked and recorded.
Your AI DIRECT Repo · Database · Computers
✕A second door. Acts here are neither checked nor recorded.
03 / HOW YOU USE KNOX

From inside the AI you already use.

An MCP connector

Connect Knox to Claude in the browser or the desktop app. Your AI’s actions go through the membrane instead of straight to your systems.

AVAILABLE · CLAUDE

Hosted, or your own PC

The agent works in Knox’s hosted workspace, or on a separate PC you designate as its sandbox. Knox’s runner only dials out.

YOU CHOOSE THE LEVEL

Your business systems, read-only

Link systems you already run with access set by you. Sage desktop on your own server, read by ODBC: the agent reports, it cannot change a ledger.

IN USE AT AN ESTATE COMPANY

Knox runs on itself.

Internal operating figures, Knox Alpha, 5 Oct 2026. Not customer results.
81,293 recorded agent actions
958 governed sessions
138,379 stamps
5,405 checked claims

Put your AI behind the membrane.

Install Knox on GitHub, connect your Supabase, add your team. Your data stays in your own accounts.

Get started → Sign in