Platform Overview
Gaussian Documentation
AI agent runtime security for developer workstations.
AI Agent Runtime Security
AI can act. Gaussian decides what it is allowed to do.
Gaussian is the inline macOS agent firewall. It mediates MCP tool use, coding assistants, and autonomous agent execution with policy, identity, and kernel-level enforcement before side effects land on your workstation.
Getting Started & Concepts
Quickly understand Gaussian's threat model, deploy the signed macOS agent, and test attack scenarios.
Installation Guide
Deploy the signed Gaussian app bundle, approve ES/NE extensions, and verify your installation.
Core Concepts
Threat model for autonomous AI agents, MCP tool mediation, and workstation risk surfaces.
Attack Scenarios
Real-world developer workstation attack simulations, baseline policy rules, and enforcement logs.
Gaussian vs Existing Tools
How Gaussian compares to CrowdStrike Falcon, SentinelOne, Lakera Guard, and legacy EDR/CASB.
Secure Baseline
Recommended factory settings and security baselines before deploying autonomous coding agents.
Mac Runtime Architecture
Deep dive into Apple Endpoint Security (ES), causal graph behavioral analysis, and real-time execution gates.
Mac Runtime Architecture
Apple Endpoint Security & Network Extension architecture governing agent processes on macOS.
Behavioral Detection
Causal graph reasoning linking credential access, file modifications, and network egress.
Enforcement Planes
Deterministic kernel-level deny, kill-switch execution, and interactive human-in-the-loop approvals.
Runtime Paths & IPC Reference
Domain sockets, local daemon communication, and posix_spawn interception specifications.
Agent & Capability Governance
Mediate Model Context Protocol (MCP) servers, audit SKILL.md instructions, and govern shadow AI processes.
MCP Security & Mediation
Discover, risk-tier, and mediate Model Context Protocol (MCP) tools/call invocations before side effects land.
Agent Skill Governance
Inspect SKILL.md packages, instruction frontmatter, prompt safety, and embedded helper scripts.
Shadow AI Discovery
Continuous endpoint-native discovery across 35+ developer AI clients, local models, and IDE extensions.
Policy Engine Guide
Define zero-latency allow/deny policies, rate limits, and approval workflows for AI tools.
Policy Schema Reference
Complete JSON schema reference for Gaussian PolicyEngine configuration.
Enterprise & Operations
SIEM telemetry exports, evaluation frameworks, security assurances, and design partner deployment.
SIEM & Telemetry Export
Stream causal graph events, tool invocations, and policy decisions into Splunk, Datadog, or Snowflake.
Evaluation & POC Guide
Step-by-step proof-of-concept runbook for enterprise security engineering teams.
Security & Trust Center
Zero-retention data privacy, Apple notarization, and workstation security posture guarantees.
Running AI agents on Mac at scale? We'll tune policy with you.
Design partners →