RUNESTONE LABS
Tools for trustworthy
AI agents.
We build the layer between AI agents and the real world — the place policy gets enforced, risky actions get approved, and every tool call gets audited. Open source. Self-hosted by default.
45 seconds · what the foundation enables, in production
What we build
Gatekeeper
Policy enforcement, approval gates, and audit trails for AI agent tool calls. Every shell command, file write, and HTTP request goes through a decision: allow, approve, or deny.
npm i @runestone-labs/gatekeeper-client
More, coming.
We're building additional tools on top of Gatekeeper. Get in touch if you want early visibility.
Why Runestone
Local-first.
Your policy, your approvals, your audit log — on your hardware. No SaaS proxy, no vendor lock-in.
Honest threat models.
We document what we do and don't protect against. You won't find "AI safety" handwaving here.
Apache-2.0.
Real OSS. Read the source. Fork it. Run it yourself. No "open core" bait-and-switch.
Investors
Backing infrastructure for trustworthy agents.
If you invest in developer tools, AI infrastructure, or security — and you want to see the roadmap, traction, and thesis — reach out. Founder-direct replies.