
Harden AIF
Local policy enforcement for tool calls made through supported coding-agent integrations.
Information checked: Sep 12, 2026 ·View sources
Tool details
- Type
- Developer workflows
- Platforms
- macOS, Linux
- Free plan
- Yes
- Open source
- No
- Bring your own key
- Not verified
- Local models
- Not verified

Overview
Best for
- Developers adding local controls to supported coding agents
Strengths
- Adds decisions at the point where supported agent tools are invoked.
- Processes security decisions locally rather than requiring a cloud account.
Limitations & trade-offs
- Windows-only environments
- Users expecting model acceleration on every daemon-supported machine
- Full model operation requires Apple Silicon; published guidance calls for at least 16 GB RAM and 15 GB disk space.
- Coverage depends on the configured integration; it is not a universal operating-system sandbox.
Get started
Pricing & usage limits
Official pricingFree tier available
Core local protection is free for individuals. No account is required; suitable local hardware is still needed.
Pricing checked: Sep 12, 2026 · Subscription, usage limits, and model costs may be billed separately.
Features & details
Execution policy
- Checks supported tool calls before execution
- Allow, block, redact, ask, and log outcomes
- Local decision history
Agent and hardware support
- Integrations include Claude Code, Codex, Cursor, Antigravity CLI, and Kiro
- Full local model path uses Apple Silicon and Metal
- CLI and daemon support macOS and Linux x86-64
Inspect the proposed action before it runs
Harden AIF sits between a supported agent integration and tool execution. A policy can allow a routine operation while stopping or escalating an operation that needs review. Its decisions are distinct from the filesystem and network boundaries provided by a sandbox.
A useful evaluation separates harmless permitted actions from harmless actions that your test policy intentionally forbids. That makes it possible to check both outcomes without using real secrets or destructive commands.
Check one integration end to end
- Compare your machine with the requirements on the Harden website, including the distinction between daemon and full-model support.
- Install using the official instructions and run the configuration flow for one supported coding agent.
- Start a disposable project and issue a simple read-only task, then inspect the local decision record.
- Test a deliberately restricted but harmless action and confirm that the configured block or approval behavior occurs.
After installation, configuration starts with:
aif configureEvaluate coverage as well as interruptions
Review which tools the integration actually intercepts and whether legitimate development tasks are repeatedly interrupted. Keep your existing workspace permissions in place while measuring that behavior. The relevant result is understandable enforcement on your workflow, not simply the number of blocked calls.
Model support & data privacy
Privacy & data handling
Security decisions run locally. Optional telemetry can be disabled. Connected coding agents retain their own model-provider data handling.
Guides, reviews & fixes
View allNo published guides yet. Start with the official documentation above.
Product updates
No verified product updates listed yet. Follow this tool to see new relevant content in Saved.
See the content timelineSources & verification
Verification dates record when this directory checked the information. Product release dates appear separately above.