Protect

# Let agents work. *Keep production, secrets and main safe.*

Protect checks every tool call before your terminal runs it. A blocked call never runs, and the model is told why.

[Start free](https://context-mode.com/docs/quick-start)[Read the docs](https://context-mode.com/docs/protect)

How it works

## Checked *before it runs.*

1. 01**The agent asks for a call** Shell, file, fetch or tool server.
2. 02**Protect reads what it does** Through sudo, sh -c, xargs and 130 other wrappers.
3. 03**Allowed or blocked** A blocked call never reaches the shell.

Proof

## How tool-call rules *compare.*

|  | Context Mode | Built-in permissions | General LLM gateways |
| --- | --- | --- | --- |
| Decides by | What a call does, through sudo, sh -c and 130 wrappers | Rules per client | Tool name and arguments |
| Covers | Every agent and machine on the account | One client, one machine | Apps you route through it |
| Org policy members cannot loosen | Yes, on Team | No | Varies |
| Set up | One command | Per client | Your own infrastructure |

Read 2026-09-29 and 2026-09-30. [Method and sources →](https://context-mode.com/docs/landscape)

Features

## Start in a minute.

**Core protections**

Stop losses you can't undo, like wiping your home folder.

**Secrets**

Keep .env files away from the model.

**Sites**

Allow or block hosts, nested URLs included.

**Monitor first**

Record matches before you block them.

**Presets**

Three presets and four extra packs.

**Keep your sandbox**

Protect reads the call, not the program. Use both.

Team and Enterprise

## One policy *for the whole org.*

**Members cannot loosen it**

On Team, the org sets the rules once. Every member's agents follow them, on every machine.

*Read environment files**Block · locked* *Push to protected branches**Block · locked* *Change cloud resources**Monitor*

**One log**

What agents tried and which rule answered. Export as CSV or JSON Lines.

**Your deployment**

Our cloud, a dedicated instance, or your own Cloudflare account.

[Talk to us](mailto:sales@context-mode.com)[See plans](https://context-mode.com/pricing)

## Write the rules *once.*

*npx @context-mode/cli* connects your agents. 1,000 requests free, no card.

[Start free →](https://context-mode.com/docs/quick-start)[Read the docs →](https://context-mode.com/docs/protect)
