RUNESTONE LABS
Tools for trustworthy
AI agents.
We build the layer between AI agents and the real world — the place policy gets enforced, risky actions get approved, and every tool call gets audited. Open source. Self-hosted by default.
What we build
Gatekeeper
Policy enforcement, approval gates, and audit trails for AI agent tool calls. Every shell command, file write, and HTTP request goes through a decision: allow, approve, or deny.
npm i @runestone-labs/gatekeeper-client
More, coming.
We're building additional tools on top of Gatekeeper. Get in touch if you want early visibility.
Why Runestone
Local-first.
Your policy, your approvals, your audit log — on your hardware. No SaaS proxy, no vendor lock-in.
Honest threat models.
We document what we do and don't protect against. You won't find "AI safety" handwaving here.
Apache-2.0.
Real OSS. Read the source. Fork it. Run it yourself. No "open core" bait-and-switch.
Investors
Backing infrastructure for trustworthy agents.
If you invest in developer tools, AI infrastructure, or security — and you want to see the roadmap, traction, and thesis — reach out. Founder-direct replies.