The AI Agent Firewall

Your AI agent can code.
Enclivo controls where it can go.

Put a network security boundary around your AI coding agents. Keep your code and LLM infrastructure on-premise while controlling exactly what the agent can access.

VS Code control · CLI agent support · On-premise LLMs · Default-deny networking
Developer
VS

VS Code or CLI

Developers control the agent using VS Code or a supported command-line workflow.

→
Workload
AI

AI Coding Agent

The agent reads code, runs commands and performs development tasks. Enclivo controls its network access.

→
Network boundary
⬡
Enclivo Agent network firewall DEFAULT DENY
The IDE controls the agent. Enclivo controls the agent's network perimeter.
Don't replace your agent.   Put a security boundary around it.

Control the agent. Not the IDE.

Enclivo does not try to secure VS Code or every extension running inside it. Instead, Enclivo sits around the AI coding agent and controls its network access.

01 — Developer interface Use the Enclivo VS Code extension to control and interact with your agent from the IDE.
02 — Agent Your coding agent performs its normal work: reading files, editing code and running commands.
03 — Enclivo boundary Enclivo determines which network destinations the agent is allowed to reach.
04 — Your infrastructure The agent can access approved internal services such as your private LLM, Git server and package mirror.

Keep using the agents your developers already know.

Enclivo is a security layer, not another coding agent. Use its VS Code extension to control an agent, or run supported CLI-based agents behind the same network boundary.

✓ Supports existing agent workflows
VS
Enclivo VS Code Extension Control an AI coding agent directly from VS Code.
>_
CLI Agents Run compatible command-line agents with Enclivo controlling their network access.
AI
Private LLM Servers Point the agent at an LLM running inside your own infrastructure.
+
Existing development environment Keep your repositories, terminals and internal developer services where they already are.

Your developers stay in their IDE.

The Enclivo extension provides a convenient control surface for the agent. It does not replace VS Code or attempt to firewall unrelated VS Code extensions.

VS Code
EXPLORER
▾ my-project
 ▸ src
 ▸ tests
  package.json
app.ts
1 async function deploy() {
2   const config =
3     await loadConfig();
4
5   return deployApp(config);
6 }
AI Coding Agent
I'll update the deployment configuration and run the relevant tests.
✓ Network access controlled by Enclivo

Your LLM can be private.
Your agent can still get out.

Running an LLM on-premise does not automatically prevent an AI coding agent from accessing the internet. Agents can read files, execute commands, install packages, call APIs and interact with external services.

×
Unrestricted internet access An agent can reach external services unless access is explicitly controlled.
×
Package and tool downloads Agent workflows can trigger network access through package managers and developer tools.
×
Third-party services APIs and external integrations can create additional paths outside your security boundary.
×
Trusting the agent itself Security shouldn't depend on an agent deciding what it should or shouldn't access.

Treat your AI agent like an untrusted workload.

Move network security outside the agent itself. Administrators define what the agent can access.

⊘

Default deny

Block outbound network access by default. The agent gets no implicit path to the internet.

✓

Explicit allowlists

Permit only approved domains, IP ranges, internal services and endpoints.

◈

Internal by default

Connect the agent to your private LLM, Git infrastructure, package mirrors and APIs.

⌁

Agent-specific policies

Apply different network policies to different agents, projects, teams or environments.

≡

Visibility

See which destinations agents attempt to reach and which requests are blocked.

□

Air-gapped capable

When zero external connectivity is required, operate entirely within your network.

Your network.
Your rules.

Security teams define the perimeter. Developers keep using their preferred agents while Enclivo enforces the network policy underneath them.

enclivo.policy
# Agent network policy

agent:
  name: coding-agent

network:
  default: deny

  allow:
    - llm.internal.company
    - git.internal.company
    - registry.internal.company

  internet:
    enabled: false

# The agent can work.
# The agent cannot roam.

Don't ask the agent to behave securely.

Put the control outside the model and outside the agent. Enclivo provides a network boundary that remains in force regardless of what the agent attempts to access.

✓
Agent-focused boundary Control the network access of the coding agent, independently of the IDE used to control it.
✓
Private LLM infrastructure Connect to models running inside your own environment.
✓
Restricted outbound access Control which destinations the agent can reach.
✓
No cloud dependency Deploy the security boundary inside your infrastructure.

From controlled networks to fully isolated environments.

Choose how much network access your agents receive. The same development workflow can operate under different security policies.

CONTROLLED

Controlled internet

Allow selected external services while blocking everything else.

ON-PREMISE

Internal only

Connect agents exclusively to your internal models, repositories and services.

AIR-GAPPED

Zero external access

Operate entirely inside an isolated network with no internet connectivity.

Keep your AI agents.
Control where they can go.

Enclivo is built for organizations that want agentic software development without giving coding agents unrestricted access to confidential code, internal systems or the public internet.

Talk to us