Workflow
One local check, on the device, before a prompt ever reaches the AI — then only content-free signals flow to the console.
Multi-layer agentic security that runs entirely on your device. Most AI-security tools are a single filter — and most run in a cloud or gateway your prompts, files, and outputs have to pass through to be inspected. MoorAI is different on both counts: it defends in five layers — decode/normalize, content-free deterministic detectors, on-device semantic escalation, action-layer enforcement, and tamper-evident evidence — and every one of them runs locally. It's content-free by construction: no prompt, response, or file content ever leaves the machine — only metadata and a keyed one-way hash. And because the agent is open source (MIT), a CISO can audit that, not just trust it. Built for the AI-Agents era: it goes deepest on coding agents — Claude Code, Codex, Copilot CLI, where an injected instruction can reach a shell and a cloud credential in one step — and the same on-device engine governs the everyday AI your whole team uses.
Not one filter.
Five layers, all on the device.
A single prompt filter fails the moment an attacker encodes the payload, rephrases the jailbreak, or slips it in over several turns. MoorAI is defense-in-depth: five independent layers, each running locally and content-free, so getting past one still runs into the next — and the decisive one sits at the tool call itself.
validate-blocking suite, 100% of malicious tool-calls were blocked at the action layer (12/12) even after a jailbreak succeeded upstream. Full enforcement on Claude Code via PreToolUse hooks; Codex and Copilot CLI are detection-only.Three moves, on every prompt.
MoorAI reviews each prompt where it's typed, decides what to do, and reports only redacted metadata upstream.
MoorAI is governance without surveillance. Prompts and conversations are reviewed on the device and, by default, never leave the machine; security teams receive only redacted, content-free signals — a category, a risk level, and a keyed one-way hash. Two exceptions, stated rather than buried: an administrator can turn on a capture tier, which does store the matched text it was enabled to collect — that's your choice, per tenant, and it's logged — and on platforms whose OS can't read an image locally, a pasted screenshot goes to your own AI provider for text extraction, never to us. It's a guardrail for how your organization uses AI, not a window into what people type.
Why you can trust the content-free claim.
“Content-free” is only worth something if you can verify it. Anyone can print the words on a page. Here's what actually backs the claim — and, honestly, what's still on the roadmap.
moorai-redteam): run the adversarial suite against your own active policy and confirm it acts on each attack class, on your own machine. Every published run so far was executed by the maintainer, who also authors MoorAI — that is stated in the results rather than glossed over, and no third-party lab has reproduced it. See the runs →Small footprint.
On the device.
A local agent that reviews prompts where they're written, and a separate console for the fleet.
Review it
on the device.
Coach, alert, or block — before the prompt reaches the agent.