Open source · Apache 2.0 · Compliance-by-design

The governance layer that makes AI autonomy possible.

Super Tanks is not a detection tool that reacts after something goes wrong. It's 10 simultaneous security layers that stop it from happening in the first place — every action an AI agent takes is mediated before it reaches a tool, a model, or the outside world.

Apache 2.0 · Works fully offline · Built against the OWASP Top 10 for Agentic Applications 2026
Built against the first globally peer-reviewed agentic-AI security standard: OWASP Top 10 for Agentic Applications (2026) EU AI Act — in force Aug 2, 2026 GBER-funded R&D · Innovation Norway

Autonomous AI agents are shipping faster than the guardrails.

In 2026 alone the industry saw poisoned MCP registries (nine of eleven, per OX Security), ~200,000 unauthenticated MCP instances exposed to the internet, credential breaches via LiteLLM, and natural-language prompts that triggered arbitrary command execution. The problem isn't that teams aren't watching — it's that watching happens after the agent has already acted.

"Most AI security is compliance-by-audit. By then the agent has already run the command."

Ten enforcement layers. One default answer: deny, unless explicitly allowed.

Super Tanks sits between your agents and everything they can touch. Every tool call, memory write, and inter-agent message passes through 10 layers running simultaneously. Nothing is implicit — you set the access levels and the filters, and Super Tanks enforces exactly what you decided.

01

ZEF Firewall

A secondary LLM filter that catches obfuscated prompt injection.

02

Soul Files

SHA256-sealed agent identity. Tamper-evident by design.

03

DIQ Layer

Frozen, declarative tool contracts. No surprise tool surfaces.

04

Allowlists

Explicit allow, default deny, per agent.

05

GO-Gate

Human-in-the-loop approval for risky actions, via Telegram.

06

Sandbox

Docker isolation for any untrusted execution.

07

Circuit Breaker

Per-agent rate limits on tool invocations.

08

Tool Zone Isolation

49 tools partitioned into 7 zones.

09

MCP Security Manager

Trust-level enforcement for every MCP server.

10

allowed_agents

Skill-level isolation, agent by agent.

Compliance-by-design, not compliance-by-audit.

Most EU AI Act obligations apply from August 2, 2026. Super Tanks gives you the architectural controls — before deployment, not after.

Mapped end-to-end to the OWASP Top 10 for Agentic Applications 2026 (ASI01–ASI10). See the full mapping →

Who Super Tanks is for.

Enterprises deploying AI agents

Pass GPAI deployment audits with controls that already exist. Human oversight, audit trails, and access governance out of the box.

Platform & security teams

Drop a default-deny governance layer in front of your MCP/A2A stack instead of building one. Apache 2.0, self-hosted, no vendor lock-in.

Regulated & sovereignty-sensitive operators

Runs fully offline on local models (Ollama). No data leaves your perimeter. Public sector, defense, healthcare.

Open research · We're listening

Help us pressure-test the controls.

We're running short, no-strings validation conversations with security and AI-governance leaders ahead of the EU AI Act deadline. 20 minutes, not a sales call — just learning where the real gaps are.