Your AI agent can code.
Enclivo controls where it can go.
Put a network security boundary around your AI coding agents. Keep your code and LLM infrastructure on-premise while controlling exactly what the agent can access.
VS Code or CLI
Developers control the agent using VS Code or a supported command-line workflow.
AI Coding Agent
The agent reads code, runs commands and performs development tasks. Enclivo controls its network access.
Control the agent. Not the IDE.
Enclivo does not try to secure VS Code or every extension running inside it. Instead, Enclivo sits around the AI coding agent and controls its network access.
Keep using the agents your developers already know.
Enclivo is a security layer, not another coding agent. Use its VS Code extension to control an agent, or run supported CLI-based agents behind the same network boundary.
Your developers stay in their IDE.
The Enclivo extension provides a convenient control surface for the agent. It does not replace VS Code or attempt to firewall unrelated VS Code extensions.
1 async function deploy() { 2 const config = 3 await loadConfig(); 4 5 return deployApp(config); 6 }
Your LLM can be private.
Your agent can still get out.
Running an LLM on-premise does not automatically prevent an AI coding agent from accessing the internet. Agents can read files, execute commands, install packages, call APIs and interact with external services.
Treat your AI agent like an untrusted workload.
Move network security outside the agent itself. Administrators define what the agent can access.
Default deny
Block outbound network access by default. The agent gets no implicit path to the internet.
Explicit allowlists
Permit only approved domains, IP ranges, internal services and endpoints.
Internal by default
Connect the agent to your private LLM, Git infrastructure, package mirrors and APIs.
Agent-specific policies
Apply different network policies to different agents, projects, teams or environments.
Visibility
See which destinations agents attempt to reach and which requests are blocked.
Air-gapped capable
When zero external connectivity is required, operate entirely within your network.
Your network.
Your rules.
Security teams define the perimeter. Developers keep using their preferred agents while Enclivo enforces the network policy underneath them.
# Agent network policy agent: name: coding-agent network: default: deny allow: - llm.internal.company - git.internal.company - registry.internal.company internet: enabled: false # The agent can work. # The agent cannot roam.
Don't ask the agent to behave securely.
Put the control outside the model and outside the agent. Enclivo provides a network boundary that remains in force regardless of what the agent attempts to access.
From controlled networks to fully isolated environments.
Choose how much network access your agents receive. The same development workflow can operate under different security policies.
Controlled internet
Allow selected external services while blocking everything else.
Internal only
Connect agents exclusively to your internal models, repositories and services.
Zero external access
Operate entirely inside an isolated network with no internet connectivity.
Keep your AI agents.
Control where they can go.
Enclivo is built for organizations that want agentic software development without giving coding agents unrestricted access to confidential code, internal systems or the public internet.
Talk to us