IT'S TIME TO SHIP.

Do you know where your agent is?

Agent Curfew continuously records your agents' movements — without asking the agent to report itself. See what each agent touched, which tools it used, where it worked, and whether it crossed a boundary.

The agent doesn't check in. Agent Curfew already knows.

OBSERVED MOVEMENT · LIVE 3 agents · 0 unaccounted windows
21:41:02
mcp.tool_call · fs.write
src/parser.rs
claude · sess 8f1a
sealed
21:41:04
mcp.tool_call · shell.exec
cargo test
claude · sess 8f1a
sealed
21:43:17
boundary.crossed · credential
AWS_PROD_KEY
codex · sess 4c2e
held
21:43:20
approval.requested · APS
press to authorize
gl-drive-0001
pending

Agents move faster than logs can explain.

They read files.
Write code.
Call tools.
Use credentials.
Change production.

When something goes wrong, teams are left reconstructing the story from scattered logs — often using records created by the same agent they are trying to investigate.

Agent Curfew creates an independent record of the agent's movements as they happen.

SIGNALS

Observe the movement. Not the explanation.

Agent Curfew records activity at the boundaries agents move through:

01MCP tools called
02Files accessed or changed
03Commands executed
04Systems contacted
05Credentials requested
06Workspaces entered
07Permissions exercised
08Sessions started and stopped
09Last verified activity
→ The agent does not decide what gets recorded.
→ It does not need to remember to check in.
→ It cannot explain away a movement that was independently observed.

Know where every agent has been.

For each agent, Agent Curfew answers:

Where is it working?/repo/parser
What is it doing?shell.exec
Which tools has it used?7 of 9 approved
What did it touch?142 objects
When was it last active?21:43:20Z
Did it leave its assigned boundary?once · 21:43
Does its recorded work still exist?2 / 2 match
Can the activity record be verified?seal valid
VERDICT

No reconstructed story.

A movement record that does not require belief.

Confidence: High — 1,204 observed movements across 3 agents.
ARCHITECTURE

Built around MCP. Independent of the agent.

Agent Curfew observes the MCP boundary between agents and tools. When an agent calls a tool, accesses a resource, or attempts an action, Curfew records the movement automatically.

AGENT
Claude · Codex · custom
calls out
CURFEW GATE
Tees, then forwards
observes · seals · alerts
TOOLS
Files · shell · APIs · secrets
unchanged
→ The agent does not call Agent Curfew.
→ Agent Curfew sees the agent call everything else.

Set the boundary.

Define where an agent is allowed to operate:

Approved tools Permitted directories Authorized systems Available credentials Session windows Required approval points Restricted actions
INSIDE THE BOUNDARY

The agent works.

Silent. Nothing to approve, nothing to read. The record accrues underneath.

OUTSIDE IT

Curfew records the crossing and alerts you.

The crossing is evidence whether or not you act on it.

Quiet when everything is normal.

Agent Curfew watches continuously and speaks when something matters:

An agent stops producing observable activityWARNING
An unauthorized tool is attemptedCRITICAL
A protected file changesWARNING
A credential boundary is crossedCRITICAL
Activity continues outside its approved windowWARNING
The observed record develops a gapWARNING
Preserved work no longer matches its verified copyCRITICAL

You decide what happens next:

Notify Require approval Pause access End the session
APS · REV 3 3-PORT THUMB-SIZED STATUS · CUSTODY · APPROVAL
MEET APS

The GPS for agents.

Agent Curfew records where your agent moves. APS proves where its work went.

A thumb-sized physical flight recorder. It preserves verified copies of protected work, safeguards a non-exportable identity key, and requires a physical button press for sensitive approvals.

GREENProtected copies match
YELLOWVerification or approval is pending
REDSomething disagrees
WHITEConnecting

Software can request permission.

Only you can press the button.

Explore APS
END TO END

From movement to custody.

01An agent uses a tool, changes a file, or enters a system.
02Agent Curfew observes the movement independently.
03The resulting work is captured and sealed.
04Verified copies are routed to separate storage.
05APS physically confirms sensitive actions.
06You are alerted when the agent — or its work — leaves the expected state.
The agent keeps working.
The record keeps watching.
PRICING

Start recording.

Early access. Three builds of the APS recorder — from a portable witness to a system that watches a whole fleet of agents.

WHICH ONE IS YOURS
APS MINI $149
One person, moving between machines.
A portable hardware witness — secure signing, a physical approval button and a small verified custody vault.
APS $249
One desk, always recording.
A desktop custody router — records agent activity continuously, seals its work and verifies every stored copy.
APS PRO $479
Many agents at once.
A high-performance local system — fleet monitoring, expanded verified storage and fleet-wide TICS scoring.

Checkout is handled by Stripe. Questions before you buy — support@ghostlogic.tech.

IT'S TIME TO SHIP.

Do you know where your agent is?

You shouldn't have to ask the agent.