Open source · Apache 2.0 · Compliance-by-design

A governance layer for autonomous AI agents.

Super Tanks is not a detection tool that reacts after something goes wrong. It mediates every action an AI agent takes — before it reaches a tool, a model, or the outside world — across 10 security layers running at once.

Apache 2.0 · Works fully offline · Built against the OWASP Top 10 for Agentic Applications 2026
Built against the first globally peer-reviewed agentic-AI security standard: OWASP Top 10 for Agentic Applications (2026) EU AI Act — obligations phasing in 2026–2028 GBER-funded R&D · Innovation Norway Independently threat-modeled by 7ASecurity →

Autonomous AI agents are shipping faster than the guardrails.

In 2026 alone the industry saw poisoned MCP registries (nine of eleven, per OX Security), ~200,000 unauthenticated MCP instances exposed to the internet, credential breaches via LiteLLM, and natural-language prompts that triggered arbitrary command execution. The problem isn't that teams aren't watching — it's that watching happens after the agent has already acted.

"Most AI security is compliance-by-audit. By then the agent has already run the command."

10 enforcement layers. One default answer: deny, unless explicitly allowed.

Super Tanks sits between your agents and everything they can touch. Every tool call, memory write, and inter-agent message passes through 10 layers running simultaneously. Nothing is implicit — you set the access levels and the filters, and Super Tanks enforces exactly what you decided.

01

ZEF Firewall

A secondary LLM filter that catches obfuscated prompt injection.

02

Soul Files

SHA256-sealed agent identity. Tamper-evident by design.

03

DIQ Layer

Frozen, declarative tool contracts. No surprise tool surfaces.

04

Allowlists

Explicit allow, default deny, per agent.

05

GO-Gate

Human-in-the-loop approval for risky actions, via Telegram.

06

Sandbox

Docker isolation for any untrusted execution.

07

Circuit Breaker

Per-agent rate limits on tool invocations.

08

Tool Zone Isolation

49 tools partitioned into 7 zones.

09

MCP Security Manager

Trust-level enforcement for every MCP server.

10

allowed_agents

Skill-level isolation, agent by agent.

Compliance-by-design, not compliance-by-audit.

The EU AI Act's obligations phase in through 2028: transparency duties from August 2026, most stand-alone high-risk duties (logging, human oversight, robustness) expected ~December 2027 under the Digital Omnibus agreement — dates may still move, and this is not legal advice. The obligations are coming, and preparing takes time. Super Tanks gives you the architectural controls early — before deployment, not after.

Mapped end-to-end to the OWASP Top 10 for Agentic Applications 2026 (ASI01–ASI10). See the full mapping →

Who Super Tanks is for.

Enterprises deploying AI agents

Bring controls that map to GPAI deployment-audit requirements. Human oversight, audit trails, and access governance out of the box.

Platform & security teams

Drop a default-deny governance layer in front of your MCP/A2A stack instead of building one. Apache 2.0, self-hosted, no vendor lock-in.

Regulated & sovereignty-sensitive operators

Runs fully offline on local models (Ollama). No data leaves your perimeter. Public sector, defense, healthcare.

Open research · We're listening

Help us pressure-test the controls.

We're running short, no-strings validation conversations with security and AI-governance leaders as the EU AI Act obligations phase in. 20 minutes, not a sales call — just learning where the real gaps are.