Start here

CloakPipe documentation

CloakPipe is the reliability layer for AI agents. It gives one exact agent configuration a name (the release), turns your evaluation results about that release into a signed certification, makes the runtime act on that certification, and records evidence that a third party can verify offline.

The model: Evaluate, Certify, Enforce, Prove

Step What happens Where it runs
Evaluate You keep your evaluation tool. cloakpipe eval import turns JUnit XML, a Braintrust experiment or a Langfuse dataset run into a native EvaluationRun bound to the release’s manifest hash. CLI, offline
Certify cloakpipe release certify applies a CertificationPolicy to the runs and reaches a deterministic CERTIFIED or BLOCKED decision, optionally signed as a DSSE-wrapped in-toto statement with Ed25519. CLI, offline; GitHub Action
Enforce The cloakpipe mcp-proxy tool gate lets only a certified release call the tools its manifest declares. CloakPipe Cloud’s proxy feeds the release’s certification status into Cedar policy, gates production promotion and watches the running release with sentinels. CLI (MCP); Cloud (LLM proxy, registry)
Prove Every hop is written to a hash-chained, Ed25519-signed ledger. The standalone cloakpipe-verify binary checks an exported bundle offline. Core ledger + verifier; Cloud export

Everything hangs off one identifier: the release’s manifest hash, sha256:<hex> over a canonical view of the manifest. A passing test of one configuration can never certify a different one. See Agent releases.

Open source and cloud

Open source in rohansx/cloakpipe (MIT; the standalone verifier crate is Apache-2.0):

  • The Rust privacy proxy (cloakpipe start): detect, mask, forward, unmask, with an encrypted vault.
  • The MCP server (cloakpipe mcp) and MCP interceptor (cloakpipe mcp-proxy).
  • The evidence ledger and the offline verifier (cloakpipe-verify).
  • Release manifests (cloakpipe release), evaluation import (cloakpipe eval import), certification and the GitHub Action, and the MCP tool gate.
  • External anchoring of evidence bundles (cloakpipe anchor, RFC 3161 and Sigstore Rekor) and release audit packs (cloakpipe release audit-pack, cloakpipe-verify release-pack). See Evidence & verification and Audit packs.

All of this is on main; the quick start installs it.

CloakPipe Cloud Cloud is the hosted service (early access: join the waitlist). It is not open source. It adds:

  • The release registry: cloakpipe release register from CI, environment pointers and promotion history.
  • Release-aware runtime enforcement in the hosted LLM proxy: Cedar context, unmask rules, the production promotion gate, break-glass, scoped API keys and sentinels. See Runtime enforcement.
  • Evaluation upload from CI or the dashboard, converted by the same importers as the CLI. See Evaluation import.
  • A signed audit pack download for every release. See Audit packs.
  • The India DPDP compliance pack at the proxy. See Runtime enforcement.
  • Evidence export and verification endpoints, the dashboard, and team features.

CloakPipe Cloud is in early access with design partners. To get access, join the waitlist; everything on main above works today without it.

Status labels

Every page says what state each feature is in:

  • Main merged to main of the open-source repo.
  • Cloud runs in CloakPipe Cloud.
  • Building in progress or planned, not usable yet.

Where to go next