Strentis gives autonomous AI a hard boundary on what it may do, and a machine-verifiable contract for what it must deliver, enforced outside the agent, not left to its own judgment.
The shift already happened
That's a feature. It's why autonomous AI is useful at all. But every extra bit of autonomy you grant an agent is also an extra bit of blast radius the moment that agent is compromised, confused, or simply wrong. Most tooling today asks you to choose between a leash so short the agent is useless, or trust so wide a single bad session can touch everything it can reach.
is usually all it takes for a mis-scoped agent to touch files, keys, or systems far outside the task it was actually given.
is what a properly contained agent leaves behind, even when it's compromised — because containment was enforced by the kernel, not by the agent's own good behavior.
Our products
Layer one decides what an agent is allowed to do. Layer two decides whether it did what it agreed to. Both rely on real evidence: kernel enforcement, file contents, and exit codes. They never rely on an agent's own self-report.
# give an agent a narrow, real authority ceiling $ agent-immune init . $ agent-immune run --session backend --write ./backend -- claude # it asks, you decide $ agent-immune pending $ agent-immune approve <id> # the moment a session's authority goes bad $ agent-immune quarantine backend → that session, and every descendant, stopped instantly. → every other session keeps working, untouched.working name: "anti-agentic" — a better one is coming
# say exactly what counts as done, before the agent starts $ agent-contract propose --hirer orchestrator --hired worker \ --write ./work --deadline 600 \ --deliverable ./work/report.json --schema ./report.schema.json \ --verify-script ./verify.py --verify-write ./verify_scratch \ --reason "analyze the dataset" # hire it, exactly as you'd run it yourself $ agent-contract run <id> -- claude -p "analyze the dataset..." → status=needs_trust (a human still approves cross-session reads) $ agent-immune approve-trust <id> $ agent-contract verify <id> → status=fulfilledrequires agent-immune — every action goes through it, nothing is bypassed
How it works
agent-immune provides the enforcement layer underneath the stack. agent-contract builds on that same boundary, so contract execution and verification inherit the same containment and artifact-trust guarantees.
Every session starts with an explicit boundary set by a human. Landlock and bubblewrap enforce what the agent can access and modify at the OS level, outside the agent's own control.
An agent can ask for more authority, but it cannot grant that authority to itself. A human must approve the request, and the added authority only applies to the session's next execution.
Quarantine one compromised session and its entire authority branch is stopped with it. Descendants, pending requests, and unused grants are revoked while unrelated sessions keep running.
Code produced by a lower-authority agent does not automatically inherit the authority of whoever reads or runs it. Trust requires human approval and is bound to the artifact's exact contents and consumer session.
If a required protection cannot be verified, agent-immune refuses to launch the session. Missing kernel support or sandboxing never results in a silent downgrade.
No daemon, cloud service, or account. Install one local tool and run the coding agents you already use through it.
Why Strentis
The next decade of software is agentic by default. The systems that win won't be the ones that trust their agents the most. They'll be the ones that don't have to.
Authority. What is an agent allowed to do?
Obligation. What did it agree to do, and did it?