Working software · Demonstrations on request

Agents powerful enough to matter. Governed enough to trust.

Moonwalker supervises AI agents while they work. You decide what each agent is allowed to touch. Any agent you already use, in any harness you want, anywhere a server can exist. Bring your own AI, your own storage, your own systems: Moonwalker is the plumbing and the logbook, and what flows through them is yours. Built for government and enterprise.

Works with the agents you already use
Claude Code Claude.ai Codex CLI ChatGPT Any MCP client
The product

This is what a governed action looks like.

Two real records from a Moonwalker session. One action the policy allowed, one it refused. Both were written the same way.

● Allowed · recorded
action
web_fetch
target
https://moonwalkercorp.com
capability
read
scope
single target
reversible
trivially
credentials
none touched
risk
0 · green
friction
audit only
audit id
5fd643f9-35b9-4227-b55b-053d1a6dafa9
Routine actions flow. The score and the record are written whether or not anyone is watching.
● Refused · recorded
action
read
target
C:\Payroll\2026\direct-deposit.csv
policy
path is denied by security policy
result
nothing returned to the agent
recorded
the request, the rule, the refusal
A payroll file the agent was never given. The refusal is part of the record, so the attempt is visible afterward.

Allowed or refused, read or write, every call is recorded the same way. Whether a step outside its permissions is refused, flagged, or only logged is a setting you control.

How it works

Nothing to migrate. Nothing leaves.

01 / Runs where you are

One process wherever the agent works

A desktop, a phone, a laptop, inside your app, in your cloud, on a disconnected network, in a robot. Anywhere a server can exist. No kernel module. No rewrite of the agent. It sits between the agent and the machine.

02 / Plugs into the agents you have

The open tool protocol they already speak

Your agents connect to Moonwalker and get files, shell, browser, desktop, scheduled jobs, and worker agents through it. Bring your own model. We attach none of our own.

03 / Writes to storage you chose

The record lands on your side, never ours

Write-once storage you picked. Opening it takes a person you designated, and the opening is itself recorded. We see none of it.

What sets it apart

Ask any vendor four questions.

Plenty of tools now stop an agent before it acts. Enforcement is table stakes. Custody is not.

Where does the evidence live?

On your infrastructure. Never on ours. There is no Moonwalker cloud for it to reach.

Who holds the key?

You. The record sits on storage you chose. We run no cloud and hold no database, so there is nothing on our side to hand over, sell, or be compelled to produce.

Does it survive an agent that lies, on a machine you do not trust?

Yes. Policy is checked at the surface where the action executes, not at a gateway the agent can route around.

Is the vendor's own model attached?

No. We sell no model, so we never grade the mind we govern.

Why the record matters

A logbook you can write a policy against.

A normal audit log is testimony, and nobody can insure testimony. Carriers underwriting agentic AI cannot price a behavioral loss, the kind where the agent did the wrong thing while correctly authenticated, because no record exists to price it from. This one does.

01 / Every action is priced

A risk read before it runs, kept

What kind of action, whether it can be undone, whether it reaches outside, whether it touches credentials. Read at the surface before it runs, written into the record, never guessed after the fact.

02 / Numbers that know their limits

Insufficient data is an answer

The scoring engine is actuarial math, not a language model. It reports not enough evidence rather than manufacture a number, so every figure it gives carries the conditions it is entitled to exist under.

03 / The score travels, the record stays

Insurable without handing over the data

The score is computed where the evidence lives, on your infrastructure. The score can go to an underwriter. The record it came from never has to. Priced risk is what makes AI usage insurable.

What Moonwalker governs

One authority plane for the messy places agents actually work.

Governance that stops at the model boundary governs nothing. Moonwalker sits where autonomous work becomes real: local machines, project vaults, browser sessions, worker agents, scheduled jobs, and the evidence they leave behind.

Local workspace

Files, shells, browsers, and desktop

Read and write access, shell execution, code workers, and browser sessions, each bound to an explicit scope, a backup posture, and policy the customer owns. Governed database access runs on the same contract, scope and evidence over the query, with the data never leaving your systems.

Agent operations

Workers, packets, jobs, and closeouts

Long-running autonomous work becomes reviewable: a task packet, a bounded dispatch, a required artifact, run history, review, and a closeout that says what actually happened.

Human authority

Risk friction where it matters

Routine actions flow without ceremony. Consequential, credential-bearing, outward-facing, or hard-to-reverse actions meet warning, attestation, approval, or a hard stop.

Evidence layer

A flight recorder for autonomous action

Because instructions, task context, and available evidence all cross the control plane, the record preserves what the agent was told and what it knew at the moment it acted, context that otherwise vanishes the instant the action completes.

Security

Built for the bar you’ll be held to.

Tamper-evident by design. Hash-chained entries, signed checkpoints, and anchors to a witness outside the machine, so no gap is ever quiet.

Crypto posture

SHA-384 chain digests and AES-256-GCM at rest, both on the CNSA 2.0 list, with no MD5, BLAKE, or legacy ciphers anywhere in the sealed path. Signatures are ECDSA P-384, and the signature lane is swappable, so the CNSA 2.0 signature algorithms are a module change rather than a format migration. Where FIPS 140-3 is required, the signing seam points at a validated module the host already carries.

Who it is for

Teams already running agents who found their controls describe agent activity rather than constrain it.

Regulated enterprises, government, and high-assurance operators. The question we sell against is simple.

When one of your agents does something you did not intend, what do you have, and who else can read it, alter it, or be compelled to produce it?
Where this is going

The rules are already written. We built for all of them.

Every serious regime now asks the same thing of an AI agent. Log what it did, keep the log, let a human step in, and be able to show it afterward. None of them say who should hold that record. We do.

Europe

EU AI Act

Automatic event logging, layered human oversight, and a retention floor for high-risk systems. The record stays on your infrastructure, so the governance layer adds no cross-border transfer of its own.

United States

OMB M-25-21 and M-25-22, NIST AI RMF, DoD traceable and governable

Continuous monitoring of high-impact AI for federal agencies, and logging and traceability named as core controls in every voluntary framework.

Asia Pacific and beyond

Singapore, South Korea, ISO 42001

Unique agent identities, a log of every agent action, human override, and a person's right to demand human re-processing of an automated decision. None of it is enforceable without a record of what was automated.

Get in touch

If governed autonomy is a problem you have, let's talk.

If you are getting ready for where AI governance is going, let's have a conversation. We built for the whole world's rules before most of them were enforced. This is where everything is headed, and we've got your back.