The control plane for AI coding agents · Mac, Windows & Linux

Steer your agents
to safety.

Steerly runs Claude Code, Codex, Cursor, Copilot and Gemini side by side in one workspace - behind a firewall that classifies every command they propose before it runs. The leaked secret, the force-push, the 2 a.m. rm -rf: stopped on your machine, before it becomes your incident.

✓ 5-minute install ✓ From $16/seat/mo ✓ 100% local - your code never leaves
Allow 1,204 last 24h
Ask 38 held for review
Deny 7 blocked at source
Per verdict <1ms local, in-process

Replay of a recorded session · 5 agents · 3 repos

Steerly · control-plane · acme/api Live
Your agents
Claude Codeauth-reset
Codexpassword-reset
Cursorbilling-fixes
Copilotchart-fixes
Geminidocs-cleanup
Command
firewall
idle
Your machine
acme/api · main
.env.production
postgres · prod
deploy · vercel
09:41:02claudenpm test -- authallow
09:41:07codexcat .env.productiondeny
Works with Claude Code Codex Cursor Copilot Gemini CLI macOS · Windows · Linux
Act I / Workspace
Base

Every coding CLI, tiled in one workbench.

Run Claude Code, Codex, Gemini CLI and Cursor as real terminals - split and tile as many as you want, each its own agent, all sharing one repo. Prefer a chat pane? Flip to it. Either way it is the same session, the same history, the same firewall.

acme/api · main session 4f2a
Live
Agents
Four agents, one repo
claude auth-reset, 12 allowed
codex password-reset, 1 held for approval
cursor billing-fixes, 2 denied
gemini docs-cleanup, 9 allowed
4 agents 1 repo policy: 10 packs 1204 38 7
Act II / Firewall
Ultra Security

One command, all the way through.

Firewall · acme/api · session 4f2a 09:41:07
01 Intercept
02 Classify
03 Escalate
04 Remediate
Session trace 02
09:41:07cat .env.productioncodex · deny
01 · Intercept
codex › cat .env.production

The command never reaches your shell. Steerly holds it at the boundary - on your machine, before execution - and reads it against the policy set for this repo. Nothing has run yet.

02 · Classify
Command
cat .env.production
Rule
secrets.read.production
Pack
built-in · secrets (10 packs active)
Verdict
deny

Three-way classification on every shell command and tool call. Reads, tests and lints fly through as allow. Deps, migrations and deploys stop and ask. Secret reads and history rewrites are denied outright.

03 · Escalate
claudeclear
codex3 denies
cursor1 held
copilotclear
Anomaly · egress volume 14× session baseline

One deny is an event. Three in ninety seconds, followed by an outbound POST, is a pattern. The Security Room surfaces it across every repo and every agent at once - the slow-burn exfiltration a single blocked command would never reveal.

04 · Remediate
00 Detected · Stripe key committed in a91f0 82
01 Rotate the exposed key -18
02 Scrub it from history -26
03 Open a clean PR + reviewer brief -16
04 Re-scan through the same brief -13
PR risk 82 → 9 cleared to merge ≤ 30

A deny is the start, not the end. Every step is a proposed change you review, never a silent edit, and the loop only closes when the score is back in the green. Evidence is appended to the audit log.

Deterministic

10 built-in policy packs, ~100 rules, under a millisecond per verdict. deny > ask > allow, every time, with no model in the loop.

Policy as code

Override any rule per project or per environment in a YAML pack, reviewed in a pull request like the rest of your stack.

DLP built in

A 50-pattern detector blocks secret reads before they ever enter agent context, not after they land in a log.

Act III / Room
Ultra Security

The whole fleet, in one room.

A live cross-session ops view: open approvals, blocked commands, high-risk sessions and DLP hits across every repo. Switch pages, clear an approval, watch the counts move.

Security Room · acme 5 active sessions · last 24h
3 approvals awaiting a human, 7 commands blocked in the last 24h, 2 high-risk sessions and 4 DLP hits across every repo.

Clearing an approval here is the same action the app performs: the queue shortens and the count moves with it.

Anomaly
Ultra Security

Catch the run that doesn't look like the others.

Steerly learns the shape of normal agent behaviour per session: command cadence, file scope, network egress. Then it flags the runs that drift. The kind of slow-burn exfiltration a single allow/deny rule would miss.

Egress volume · codex · last 60 min Baseline 1.0x
Outbound spike on codex · 14x baseline to an un-allowlisted host in 90 seconds · session paused, egress held pending review
Behavioural baselines

Per-agent, per-session models of egress volume, command mix and touched-file scope. Normal is learned, not configured.

Held, not just logged

A flagged session pauses its risky surface, egress and writes, until you clear it. An alert nobody reads is not a control.

Routed to the Room

Anomalies open as a triage item with the full timeline attached, in the same queue as approvals and blocks.

Spec
What you get

Ten packs live on first run.

No agent rewrites, no waiting on AppSec, nothing to configure before it starts working. Steerly wraps the agent CLIs you already have installed.

Command firewall · acme/api 0.00 ms
$ pending
matched: waiting for input
Built-in deny rules 7 rules · priority < 0
builtin:rm-rf-rootdenydestructive recursive delete of root, home, or wildcard
builtin:git-force-pushdenyforced git history rewrite to remote
builtin:cat-env-filedenyreads a secret-bearing .env file
builtin:curl-pipe-shelldenypipes remote content to a shell
builtin:fork-bombdenyfork bomb pattern
builtin:dd-to-devicedenywrites raw bytes to a device file
builtin:sudo-rm-rfdenyelevated recursive delete
Audit trail 3 entries

These are the shipped built-ins, evaluated the way the product evaluates them: priority order, first match wins, default-allow when nothing matches. It runs in this page, so nothing you type leaves the browser.

Per verdict <1ms deterministic, on device
Policy packs 10 ~100 rules
DLP patterns 50 scanned inline
Code egress 0 source never stored
Pricing
One price per seat

Every agent included.

No per-agent add-ons, no usage meters. Annual saves ~2 months - and every plan carries a 7-day money-back guarantee, so the risk is ours, not yours.

Compare every feature →

Base
$16
/ seat / mo · annual
  • Multi-agent workspace
  • Persistent terminals
  • File editor + explorer
  • Unlimited sessions
Get Base
Pro Popular
$40
/ seat / mo · annual
  • Everything in Base
  • PR risk briefs · 0-100
  • Auto-remediation loop
  • GitHub App + status checks
Get Pro
Ultra Security
$80
/ seat / mo · annual
  • Everything in Pro
  • Command firewall
  • Policy engine · 10 packs
  • Security Room · cross-session triage
  • Anomaly detection · memory graph
Get Ultra Security
Enterprise
Talk
custom terms
  • SSO / SAML · SCIM provisioning
  • Self-hosted & air-gapped options
  • MCP gateway · per-agent identity
  • SIEM export · SOC 2 / ISO evidence
  • Dedicated CSM
Contact us
FAQ

Questions, answered.

Is there a free trial?

Better - a 7-day money-back guarantee on every plan. Install Steerly, run it on your real work for a week, and if it is not for you we refund it.

Does my code leave my machine?

No. Classification runs in-process, locally. Steerly stores no model API keys and never uploads your repository.

Do I have to rewrite how my agents run?

No. Steerly wraps the agent CLIs you already have installed. Your prompts, your sessions and your shell habits stay exactly as they are.

What happens when the firewall gets it wrong?

Every verdict is inspectable and every rule is editable. An ask is one keystroke from approved, and policy exceptions are scoped per repo with an audit trail.

Steer them to safety.

Five minutes to install. Ten policy packs live on first run. Your agents keep their speed - they just stop being able to hurt you.