Your security policy, enforced at runtime.

We give you control over the traffic between your agents and the resources they are accessing so nothing risky runs without your approval.

Anything that connects
Agents and automation
Editors and assistants
People, and the tools they use
runtime control planepgwire15432 → 5432
On the wireQuery · 148B
 
Handed on 
 
Anything that answers
Databases
Warehouses & streams
Clouds & infrastructure

How we interrogate every action

Deterministic policy first.
Then agent-powered analysis.

Every action is checked twice. The first check is deterministic: the rules you wrote, evaluated in order, returning the same answer every time. The second is an agent that reads the statement itself and judges what it is trying to do, and what it would touch if it ran.

Pass

The action runs. Nothing is added to the path and nothing waits on a person.

Block

It never reaches the resource. The client reads the reason you wrote, as a real protocol error rather than a dropped connection.

Route to a human

The action holds for one-off approval, with the exact statement attached.

A static rule cannot judge intent. A person cannot review at machine speed. The second layer covers what neither one can: it reads every statement as fast as the client sends it, and catches the risk no rule was written for.

Where it sits

In the connection itself, one hop before the resource.

A sidecar runs next to your resource, not in place of it. Every statement a client sends goes through it first. Every response comes back through it. It reads both in flight, before either side sees the other.

We call it a sidecar because it attaches to one resource and travels with it.

Everything it enforces comes from one config file.

The client connects to127.0.0.1:15432the sidecar
The sidecar connects to127.0.0.1:5432your real resource

What you change

You point the client somewhere else.
That is the whole integration.

Changes

The address your client points at543215432

Stays the same

  • Your application code
  • Your credentials
  • Your network routes
  • Your agent’s prompt

Nothing on the other end can tell the difference. No SDK, no agent-side config, no cooperation from the thing being controlled, which is the point. A control the client can opt out of is not a control.

Protocols

Protocol agnostic, by design.

We parse the protocol, not the client. Whatever the connection speaks, the same policy runs on it. No code changes, no new credentials, no rerouting, and nothing bolted to one driver or one vendor.

We build on wire protocols on purpose. Models change every few months. Frameworks change faster. Postgres is not going anywhere. A control that sits in the connection outlives every layer above it.

Read the code, then run it.

Anything that reads every query to your data should be code you can read too. Free and open source under MIT. One command to install. One file to configure.

Ask AI how hoop.dev sits between an agent and your data sources