Skip to content

The datasheet for every AI agent

Summary

HOL Guard is a local-first runtime security layer from Hashgraph Online DAO that sits between AI coding agents and the machine, evaluating shell, file, MCP, package and skill actions against policy before they execute. An optional Guard Cloud adds shared policy and evidence for teams.

From
Freethen $4.99 monthly · $4.17 billed annually
Free tier
YesFree forever on one machine: local protection and local protection modules only. The rendered plan table marks every cloud row unavailable on Free — cloud-connected devices, approval and receipt sync, retention, storage, digests, advisories, alerts, policy versioning and shared policy. No account or credit card is needed for local use.
Visit HOL Guard CompareFind alternatives

What it does

Reviews code
PartlyThe sibling plugin-scanner reviews repositories and gates pull requests on security grounds — prompt-injection markers, dangerous shell commands, secret leaks — rather than reviewing a diff for correctness like a code reviewer would.Scans bundled skills for prompt injection markers, zero-width characters, dangerous shell commands, and secret leaks.hol.org/guard
Done-for-you service
NoYou install and run the software yourself; the enterprise path adds a bounded deployment review with a named owner, not a team that builds or operates agents on your behalf.Install Guard Local on the selected machines and observe policy decisions before actions run.hol.org/guard/enterprises

How much it does unattended

Runs autonomously
PartlyPolicy decides unattended for allow, observe and block outcomes, but the product's whole purpose is to insert a human at the ask step, and three adapters are documented as failing open on hook crashes.On supported integrations, Guard evaluates covered shell, file, MCP, skill, and package actions against your active policy before execution. Policy…hol.org/guard/features
Agent permissions
YesThis is the core of the product: every supported action routes to block, review, warn or allow, with project and team overrides layered in a defined precedence order.Route each supported action to block, review, warn, or allow. Trace the policy path from launch to decision, then layer project and team overrides…hol.org/guard/features

Which models it runs on

Claude
YesClaude Code is a first-class harness with its own install command, hook integration and the strongest deferred-approval path; Guard guards Anthropic's agent rather than calling Claude models itself.The install page has guides for Codex, Claude Code, Cursor, Gemini CLI, OpenCode, Hermes, OpenClaw, GitHub Copilot CLI, Antigravity, Kimi, Grok, Pi /…hol.org/guard/install
GPT
YesOpenAI's Codex is a supported harness with native approvals, and GitHub Copilot CLI is covered partially; the vendor names agent harnesses, never model families, because Guard performs no inference.Guard supports 13 harnesses including Codex, Claude Code, OpenCode, Copilot, Cursor, Gemini, Hermes, OpenClaw, Antigravity, Kimi, Grok, Pi, and ZCode.hol.org/guard/enterprises
Model choice
YesOne policy layer covers thirteen harnesses, so the choice of agent and model stays entirely yours and Guard enforces the same decision surface whichever you adopt.One policy layer governs 13 supported AI coding agents, so the same decision surface applies no matter which harness the team adopts.hol.org/guard/enterprises

Not established: Open models

Where you use it

In your editor
PartlyCursor and Antigravity are covered through hooks, but the vendor's own non-coverage table records that Cursor terminal commands outside an agent session escape Guard and that VS Code extension-host MCP interception is not claimed.Built-in terminal commands outside an agent session can bypass Guard.hol.org/guard/security/non-coverage
On the command line
YesThe terminal is the original surface: a one-line installer, hol-guard init and doctor commands, and wrappers around CLI harnesses; a desktop app was added as the primary path.Download Guard Desktop for Mac, Windows, or Linux from this page, then open the app. The command line remains available as a secondary path.hol.org/guard/install
In your pipeline
PartlyRuntime Guard is a local daemon and does not act on pull requests; CI gating comes from the separate plugin-scanner and its published GitHub Action, which fails a PR on severity or trust score.Use plugin-scanner verify in CI, or the published ai-plugin-scanner action, to gate PRs before release.hol.org/guard
In a browser
PartlyA hosted Guard Cloud command center with dashboards and evidence exists, but the plan table marks cloud-connected devices unavailable on Free, so putting a machine into that console starts at Solo.Solo adds recent personal Cloud memory across two devices. Pro adds longer history, instant alerts, and full evidence. Team adds shared policy and…hol.org/guard/pricing

Whose machine it runs on

Self-hosted
YesEnforcement is designed to live on your own machine and works air-gapped; only the optional shared control plane is hosted, and Enterprise offers an on-premises Guard Cloud.Yes. Guard Local operates fully offline with no cloud dependency. Guard Cloud is an optional add-on for teams that want dashboards and shared policy.hol.org/guard/enterprises
Open source
PartlyThe local runtime that does the blocking is Apache-2.0 and inspectable on GitHub, while Guard Cloud — sync, shared policy, dashboards — is a separately scoped closed service.HOL Guard's core Guard Local runtime is open source under Apache-2.0. It can be installed, inspected, and used without a paid plan or cloud account,…hol.org/guard

What it costs to run

How it meters
YesBilling is per person and per seat on flat monthly tiers, with plan value expressed as connected devices, retention days and storage rather than actions checked or commands blocked.Pro adds synced approval history, alerts, and cloud storage for one person. Team adds shared policy, owner queues, investigation routing, and audit…hol.org/guard/pricing
Free tier
YesA standing free tier gives the local runtime, approval prompts and a local audit log across every supported agent, with no card and no cloud account required.The free plan includes the local Guard runtime, real-time approval prompts, local audit log, and support for all supported AI agents. No credit card…hol.org/guard/pricing
API access
PartlyThe only Guard endpoint in HOL's discovery contract is the OAuth-scoped MCP route, read-only over workspace and receipt scopes; outbound webhooks and SIEM export exist, but no general Guard REST API is documented.Sends an authenticated JSON-RPC 2.0 MCP request to the HOL Guard Cloud workspace server using the OAuth grant scopes.hol.org/openapi.json
MCP server
YesGuard Cloud publishes its own Streamable HTTP MCP server with OAuth metadata, so another agent can query a connected workspace and its receipts under read scopes.The public Registry MCP endpoint is available at https://hol.org/.well-known/mcp, while the HOL Guard Cloud MCP endpoint uses Streamable HTTP at…hol.org
Bring your own key
PartlyEnforcement already runs on hardware you own, and Enterprise can place the shared control plane inside your own network boundary; no bring-your-own model key applies because Guard calls no model.Keep the shared control plane inside the network and operating boundary your team chooses.hol.org/guard/enterprises

Buying it for a team

A company can buy it
YesA per-seat Team plan is self-serve at a published price, and an Enterprise track with volume pricing and dedicated support sits above it behind contact sales.Federation, log pipeline export, and curated feeds tailored to your stack. Volume pricing and dedicated support included.hol.org/guard/pricing
Seat model
YesTeam is priced per seat per month with no published minimum or maximum seat count; the ceiling that does exist is on cloud-connected devices rather than people.Team$30/seat/mohol.org/guard/pricing
Pooled budget
PartlyTeam storage is a workspace pool that grows per seat, and policy and approval queues are shared, but no pooled credit or action balance across seats is published anywhere.25 GB + 5 GB/seathol.org/guard/pricing
Admin controls
YesOrganisation policy on the Team plan is explicitly one that a local device cannot weaken, and a shared pack carries per-harness defaults, allowed and blocked publishers, domains and artifacts.Organization module policy local devices cannot weakenhol.org/guard
Audit log
YesEvery decision writes a receipt locally, free of charge and offline; Cloud plans add searchable decision history, and exports carry redacted context with an integrity digest.Every decision leaves a redacted, reviewable record — so security can audit what happened without source or secret material leaving the machine.hol.org/guard/enterprises
Single sign-on
PartlySAML federation is real but sits outside the self-serve tiers: the trust packet routes SSO, SAML and SCIM requests to Enterprise billing assistance, and no price is published for it.SSO, SAML, SCIM, SIEM routing, custom retention, and custom feeds should route to Enterprise billing assistance without blocking local self-serve…hol.org/guard/security/trust

What happens to your code

Opt out of training
PartlyLocal use never uploads source or secrets at all, and cloud sync stores redacted decision summaries, but the privacy policy claims a broad right to use customer content to improve the service and publishes no model-training statement or opt-out.We use HOL Guard customer content to provide, secure, troubleshoot, support, and improve HOL Guard and related services, and to comply with law and…hol.org/points/legal/privacy
Data residency
PartlyNothing has to leave the machine, which sidesteps the question for local use, but anything synced is processed in the United States with no region choice offered short of the Enterprise on-premises option.If you are located outside the United States and choose to provide information to us, please note that we transfer the data, including Personal Data,…hol.org/points/legal/privacy
Getting out
YesDecision trails export as CSV and JSON, account data downloads as JSON from privacy settings, and downgrading keeps local functionality with the audit log preserved on disk; credit expiry is not published.Blocked actions arrive with redacted request context, a recommended action, and linked evidence. Review one or many, then export the decision trail…hol.org/guard/features
Certifications
PartlyGDPR and CCPA handling is documented in detail with lawful bases, retention periods and self-serve rights, but no SOC 2 or ISO 27001 attestation is claimed on the pricing, enterprise or security trust pages.If you are a resident of the European Union (EU) and European Economic Area (EEA), you have certain data protection rights covered by the GDPRhol.org/points/legal/privacy

28 sourced claims on this page. Checked 2026-09-07. How we check.

Sources and updates

Updates1

  • Capabilities · Commercial terms · Free tier · Price

Advertise here

Reach buyers mid-decision. Reach builders choosing their next agent. Promote your brand with a display placement or bring your listing into focus with Featured.

Explore owner options →Advertise on this page →

The digestFree

Which agents actually ship.

What we re-checked, what got added, and one number from the index. Tuesdays.

110 agents trackedOne-click unsubscribe