AI SECURITY INFRASTRUCTUREVERSION 0.1.2 • LOCAL SIMULATION
AI Agent Firewall
Security infrastructure for AI agents, protecting requests before they reach tools, systems and sensitive actions.
AI Agent Firewall
A security layer that evaluates AI agent requests before they reach connected tools and systems.
01 — INSPECT
Evaluate incoming AI agent requests.
02 — ENFORCE
Apply security policies and risk-based decisions.
03 — DECIDE
Allow, review, or block requests.
SECURITY OPERATIONS WORKSPACE
SECURITY OVERVIEW
GLOBAL SECURITY ANALYTICS
SYSTEM STATUS
CASES SUMMARY
RECENT ACTIVITY
SECURITY CONTROL CENTER
SYSTEM STATUS: CHECKING...SECURITY ANALYTICS
TOTAL CHECKS
ALLOWED
REVIEW REQUIRED
BLOCKED
ERRORS
Decision Distribution
ALLOWED
REVIEW
BLOCKED
Try your first security check
Enter an AI-agent request. See how ZEQCY evaluates it. Nothing is actually executed in simulation mode.
SECURITY POLICY
POLICY VERSION
FINGERPRINT
CONSISTENCY
DRIFT STATUS
POLICY STATE
SECURITY INVESTIGATION CASES
| Case ID | Title | Status | Events | Created | Actions |
|---|
EVIDENCE PACKAGE OFFLINE VERIFICATION
COMPARE EVIDENCE PACKAGES
COMPARISON EVIDENCE REPORT
COMPARISON REPORT HISTORY
| Report ID | Timestamp | State | Added / Rem / Chg | Report Fingerprint |
|---|
OFFLINE COMPARISON HISTORY VERIFICATION
OFFLINE VERIFICATION RECEIPT
VERIFICATION RECEIPT HISTORY
| Receipt ID | Timestamp | Package Valid | Entry / Chain Int | Pkg FP / Rcpt FP |
|---|
OFFLINE RECEIPT HISTORY VERIFICATION
OFFLINE RECEIPT-HISTORY VERIFICATION RECEIPT
OFFLINE VERIFICATION RECEIPT HISTORY
| Receipt ID | Timestamp | Pkg State | Entry / Chain Int | Pkg FP |
|---|
OFFLINE VERIFICATION RECEIPT HISTORY EXPORT
OFFLINE RECEIPT HISTORY VERIFICATION HISTORY
| Verification ID | Timestamp | Pkg State | Entry / Chain Int | Export FP |
|---|
AGENT API CONNECTION
SECURITY EVENT EXPLORER
| TIME | REQUEST ID | AGENT | TOOL | DECISION | STATUS | DETAILS |
|---|---|---|---|---|---|---|
| NO EVENTS FOUND | ||||||
How ZEQCY Works
Conceptual integration boundary.
Intercept agent prompt
Check formatting
Evaluate intent
Match security rules
Determine action
Human oversight
Security by Design
Developer Integration
Integrate the policy engine into your agent framework.
const decision = await FirewallClient.evaluateRequest({
tool: "DELETE_FILE",
action: "delete",
target: "/example.txt"
});
console.log(decision);
{
"tool": "DELETE_FILE",
"action": "delete",
"target": "/example.txt"
}
decision = firewall.evaluate_request({
"tool": "DELETE_FILE",
"action": "delete",
"target": "/example.txt"
})
print(decision)
Security Response
Structured response returned by the firewall security layer.
SIMULATION MODEDocumentation & Quick Start
Learn how to use the ZEQCY AI Agent Firewall.
1 Quick Start Guide
2 Python SDK Integration
ZEQCY currently provides a local Python integration for agent requests. You can connect a local Python AI agent to the firewall to evaluate its tool execution requests. Note: The current v0.1.2 release operates strictly in simulation-only mode. Real tool execution is disabled by the firewall, and external AI APIs are not required.
- Start ZEQCY: Download and run the ZEQCY Firewall locally.
- Import: Include the
zeqcy_agent.pyconnector in your Python project. - Initialize: Configure the connector with your agent's identity.
- Health Check: Safely verify connectivity to the local firewall.
- Evaluate: Submit a simulated agent action.
- Read Decision: Inspect the firewall decision (ALLOWED, REVIEW_REQUIRED, BLOCKED, or ERROR).
3 Framework-Neutral Agent Integration
You can use the framework-neutral adapter to consistently wrap the SDK for different agent implementations. This is an abstraction layer that allows your custom agents to interact seamlessly without duplicating integration logic. Note: This is an integration abstraction, NOT universal framework support. Real tool execution remains disabled.
- Connect: Create/connect to the ZEQCY SDK.
- Adapter: Create an agent adapter.
- Submit: Submit an action through the adapter.
- Receive: Receive the firewall decision safely.
- Handle: Handle the decision appropriately. No tool is executed automatically.
4 Agent Request Interception
You can build a reusable interception workflow using the ZEQCY request interceptor. This allows agent actions to consistently pass through ZEQCY before any future execution layer. Note: Current ZEQCY integration is simulation-only and does not execute tools.
- Action: Agent creates an action intent.
- Intercept: Interceptor receives the action.
- Evaluate: ZEQCY evaluates the action securely.
- Decision: Firewall returns the authoritative decision.
- Gate: Interceptor returns the decision, enabling the future execution layer to use it securely.
5 Lifecycle Hooks
You can attach safe, observational callbacks (hooks) around the ZEQCY request interceptor. Hooks are invoked before interception, after evaluation, or on error. Note: Lifecycle hooks are observational integration points. They do not control ZEQCY security decisions and do not execute tools. Callbacks cannot modify internal state, and callback exceptions are caught safely.
6 Security Context
Security Context provides a structured, framework-neutral mechanism to attach safe observational metadata to agent requests. It is heavily bounded to basic types (strings, numbers, booleans) to protect sensitive data. Note: Security Context is metadata for tracing and integration only. It does not control ZEQCY security decisions and cannot alter firewall logic.
2 Architecture & Simulation
The current release operates strictly in Simulation Mode. The system evaluates AI agent prompts, classifies the risk, and returns a security decision without executing any real-world actions.
- No Real Execution: The system does NOT run shell commands, delete real files, or access your network.
- Security Evaluation: It focuses purely on analyzing intent, matching security rules, and providing the correct decision boundary.
- Authoritative Backend: All decisions are made by the compiled local Python firewall engine, not the web frontend.
3 Understanding Decisions
ALLOWED
The original firewall policy permits the request. In a live system, this would proceed to execution.
REVIEW_REQUIRED
The request requires human oversight and is not executed. It is held for manual approval.
BLOCKED
The firewall identified a high-risk policy violation. The request is permanently blocked.
ERROR
The request could not be safely processed (e.g., malformed data) and is rejected.
4 Security Analytics Query & Filtering
The Local Simulation API provides powerful read-only filtering capabilities for analyzing past security events. Filters respect strictly enforced agent and session isolation boundaries to prevent sensitive metadata leakage.
GET /api/security/events
decision: ALLOWED, BLOCKED, REVIEW_REQUIRED, ERRORagent_id&session_id: Identity isolation filterspattern_type: Filter by security correlation patterns (e.g. MULTI_TOOL_SESSION, CONTEXT_REUSE)workflow: Search by sanitized Security Context referencetool,execution_statusstart_time,end_time: Time-bounded searches
limit (max 100) and offset to navigate large datasets deterministically.
5 Security Timeline & Correlation Explorer
The Timeline Explorer renders a deterministic chronological stream of security events alongside their active correlation groups. It operates entirely in a read-only capacity and enforces the exact same isolation controls as the query engine.
GET /api/security/analytics/timeline
timeline: Array of event objects (timestamp, action, tool, decision, patterns)correlation_groups: Group objects describing aggregated risk patterns
Frequently Asked Questions
ZEQCY is a security infrastructure layer that sits between your AI agent and your system. It evaluates the agent's intent before allowing it to execute tools, preventing destructive or unauthorized actions.
No. Version 0.1.2 operates strictly in Simulation Mode. It evaluates intent as text and determines the security decision, but never executes real filesystem or shell operations.
No. The current release is fully local and self-contained. It does not require an internet connection, API keys, or cloud infrastructure to operate.
No. The Windows EXE package bundles the necessary runtime. You can run it directly without installing Python or external dependencies.
All simulated security evaluations are logged to an immutable audit trail. You can view them in the local Security Console by clicking the Events or Cases tabs.
Currently, only Windows x64 is supported. macOS and Linux support is planned for future releases.
Download AI Agent Firewall
Secure your AI agent workflows with the ZEQCY AI Agent Firewall.
Current Release
ZEQCY AI Agent Firewall — Version 0.1.2
Build: Simulation / Prototype • Execution: Local only • External API: Not connected
Platform
Only the Windows package is currently available. macOS and Linux are not yet supported.
System Requirements
- OS: Windows 10 or later (64-bit)
- Browser: Any modern browser (Chrome, Firefox, Edge) for the Security Console
- Network: No internet required — fully local operation
- Disk: ~50 MB free space
- Python: Not required — runtime is bundled in the EXE
Installation & Launch
- Download the EXE or ZIP package above.
- Extract (ZIP only): Right-click → Extract All → choose a folder.
- Run
ZEQCY-AI-Agent-Firewall.exe— no installation wizard needed. - Open your browser and navigate to
http://127.0.0.1:8080for the Security Console. - Submit a test request in the Security Console simulator.
- View the security decision — ALLOWED, REVIEW REQUIRED, or BLOCKED — returned by the firewall.
The firewall API runs locally at 127.0.0.1:8081. No internet connection is required.
What's Included
- ZEQCY AI Agent Firewall engine (bundled runtime)
- Security Console website (local HTML/JS/CSS)
- Security Dashboard, Event Explorer, Investigation View, Case Management
- Policy Visibility & Control Center
- Simulation-mode execution boundary (no real system commands)
Current Limitations
- Tool execution is simulated — no real filesystem, network, or shell commands are executed
- No external AI API or cloud dependency
- No payment or subscription required
- No public Agent API — local operation only
- No authentication system in this prototype release
- Windows x64 only in this release
Security & Integrity
ZEQCY AI Agent Firewall currently operates as a simulation-first security prototype. No real system commands, network actions, email actions, or money transfers are executed. Verify the SHA-256 checksum above before running the downloaded file.