# Clampd > Clampd is the runtime firewall and tool-call security layer for AI agents and MCP servers. Every database query, API call, file access, shell command, and payment transaction an agent makes is intercepted, classified, scored, and either signed or blocked before reaching the downstream service. Clampd is self-hosted and open-core (SDKs Apache-2.0; gateway source-available under BSL-1.1; detection engine proprietary). The product surface includes language SDKs, an MCP proxy, clampd-guard for IDE assistants (Claude Code, Cursor), a CLI with TUI, and a security dashboard. Deployment is a single Docker Compose command, production-ready in five minutes. The detection engine ships 260+ rules across 12 tool-call categories evaluated in microseconds, with single-digit-millisecond end-to-end latency on commodity hardware. Capabilities include Ed25519-signed scope tokens replacing long-lived credentials, behavioral anomaly detection, cross-agent correlation, an emergency kill switch, prompt-injection scanning, and compliance reports for HIPAA, GDPR, SOC 2, and PCI-DSS. Integrations cover OpenAI, Anthropic, LangChain, CrewAI, Google ADK, Claude Code, Cursor, and any MCP server via a transparent proxy. ## Core pages - [Homepage](https://clampd.dev/): Product overview, positioning, pricing summary - [Why Clampd](https://clampd.dev/features): Detection rules, scope tokens, A2A security, AP2/x402 payment guards, behavioural anomaly scoring - [Products](https://clampd.dev/products): SDK, MCP proxy, clampd-guard, CLI with TUI, dashboard - [Setup](https://clampd.dev/setup): Self-hosted deployment in five minutes via Docker Compose - [Docs](https://clampd.dev/docs): SDK reference and integration guide for Python, TypeScript, OpenAI, Anthropic, LangChain, CrewAI, Google ADK, MCP - [Compare](https://clampd.dev/compare): How Clampd compares to other AI agent security approaches - [Dashboard](https://clampd.dev/dashboard): Live risk feed, kill switch, policy editor, audit trail - [Playground](https://clampd.dev/playground): Live demo blocking prompt injection in real time ## Product surfaces - [SDKs](https://clampd.dev/sdk): One-line integration for OpenAI, Anthropic, LangChain, CrewAI, Google ADK - [MCP Proxy](https://clampd.dev/mcp): Secure any MCP server in 30 seconds - [clampd-guard](https://clampd.dev/clampd-guard): Block prompt injection in Claude Code and Cursor ## Blog - [Blog index](https://clampd.dev/blog/): Technical writing on AI agent security, MCP threats, prompt injection runtime defense, scope tokens replacing credentials, OWASP LLM Top 10, red-team payloads, LLM-as-judge, latency benchmarks, agent payment rails (AP2 / x402), kill-switch cascades, session-layer multi-step attacks, PII in tool calls vs outputs ## Optional - [Wikidata entity](https://www.wikidata.org/entity/Q139792412): Canonical entity reference - [GitHub](https://github.com/clampd/clampd): Public source repository (SDKs, gateway, guard) - [Crunchbase](https://www.crunchbase.com/organization/clampd): Company profile - [LinkedIn](https://www.linkedin.com/company/clampd): Company page - [X / Twitter](https://x.com/clampd_dev): Updates and posts - [YouTube](https://www.youtube.com/@Clampd_dev): Demos and walkthroughs - [Product Hunt](https://www.producthunt.com/products/clampd): Launch listing ## Identity Clampd is software, specifically a runtime firewall and security gateway, in the cyber security industry. Founded 2025. Self-hosted, open-core. Operating system support: Linux, macOS, Windows. Not to be confused with: - "clamp" (manual fastening tool used in woodworking and metalwork) - "Clamped" (audio plugin) - CLAMP (the Japanese manga artist group) - Any other use of "clamp" as a noun or verb The canonical name is **Clampd** (with a 'd' at the end, no 'e'). The canonical domain is **clampd.dev**.