Know every AI agent.
Govern every action.

Damn discovers and connects the agents already running across your company, gives each one an owner and a boundary, gates what it can reach and spend, and keeps the record on your infrastructure.

Self-host it
The Registry: every AI worker with an owner, what it can reach, its spend, and its control level

Governs the AI your teams already run

🦞OpenClawClaude CodeCodexCursorGeminiHermesOllamaOpenRouter
Self-hostedNothing leaves your perimeterSource-reviewable under NDABuilt in the EU

Every agent creates the same five questions.

Claude Code on a laptop. A vendor agent inside a SaaS product. An experiment a new hire installed on Tuesday. Each arrives with its own credentials, logs, and approval model.

QuestionWithout Damn
Who owns it?unknown
What can it access?unknown
What did it do?unknown
Who approved it?unknown
Who is accountable?unknown

If nobody can answer, the agent is operating on trust.

The mechanism

Govern at the keys and the doors.

You do not need to move every agent onto one platform. When an agent reaches a real system, it crosses a credential, a network destination, an execution boundary, or a file path. Damn applies policy there.

Doors

Everywhere

Where control lands when the resource is yours: your systems, your network, your files.

Keys

Where issuable

Stronger where we can issue the credential. Scope it, cap what it spends, revoke it once.

The box

Enterprise

For agents nobody is watching. Cron, CI, anything unattended runs inside a boundary we provide.

Any agent. Any model. Any runtime. No gateway in front of your traffic, and no routing through anyone's cloud.

Built here

Ops agents

Finance · Support · Legal

Connected

Coding agents

Claude Code · Cursor · Codex

Connected

External agents

Vendor & SaaS agents

Your infrastructure

One control layer

Keys · Doors · Files

Allow · Ask · Deny

Gated

Your systems & data

APIs · Repos · Databases

Where this sits

Your stack governs people and machines. Agents are neither.

Damn does an agent-native version of every layer you already run, and the one nothing covers today.

IdentityIAM · IdP
Your stackIs this person allowed to reach that system?
DamnIssues each agent its own credential, scoped and revocable.
NetworkSSE · SASE
Your stackIs this traffic permitted to flow?
DamnLimits which hosts an agent may reach.
DeviceMDM · UEM
Your stackIs this machine enrolled and compliant?
DamnKnows which machines are running agents.
ComplianceGRC
Your stackCan we prove the controls exist?
DamnRecords every decision on a chain you hold.
Runtime actionNo category
Your stacknothing covers this
DamnDecides whether this action happens, before it does.Without inspecting a single prompt, response or reasoning step.

Where you already run a corporate network chokepoint, enforcement rides it rather than replacing it.

It is also the only layer that produces the evidence you will eventually be asked for.

One boundary for every team.

Know what is running.One registry across employee-built, vendor, coding and operations agents.
Limit what each agent can reach.Scope credentials, systems, destinations, files and spend to the job.
Put a human at the right decisions.Hold sensitive actions for approval without reviewing every action by hand.
Revoke once.Remove access at the credential instead of chasing copies across tools and machines.
Let more teams use AI.Replace a blanket no with explicit boundaries and accountable owners.

The proof stays with you.

Every action and policy decision lands on a hash-chained record on your infrastructure. Change a past entry and the chain no longer verifies.

By default, Damn governs access without reading prompts, code, or business data. If you enable content inspection, it runs inside your environment behind your own certificate authority. Content does not reach Damn.

Trace: every consequential action on a hash-chained record, filterable by person, agent and session

Your teams are already using AI.

Give every agent an owner, a boundary, and a record before the next one reaches production.

Self-host it

FAQ

Governance and observation are free to self-host on your own machine or server. Install it and see what your agents are doing at no charge. Running your own agents on the platform needs a license. Managed hosting and Studio are paid options for people who want it run, or built, for them.

On your infrastructure. Nothing leaves it. With managed hosting it runs on a dedicated VPS where you are the sole admin; we never access your workspace without your explicit, time-boxed consent.

No. Observability is a camera: it tells you what happened, after the fact. Damn is a lock plus a notarized logbook: it stops what shouldn’t happen and proves the rest. You set the rules agents act under, risky actions wait for a human, and every decision lands in a tamper-evident record you can export.

Those govern access: which credentials an agent holds and what it is allowed to reach. Damn governs the action: what the agent actually does with that access, the moment it acts. A password tool is a key card that decides which doors open; damn.dev is the guard in the room that can approve, deny, or gate what happens once the agent is inside, and records every action on your own infrastructure. They are not rivals: identity hands the agent a key, damn.dev governs what it does with it. You will likely want both.

Every agent has a named owner and a department, an explicit boundary of what it can access, and a tamper-evident record of everything it does. No agent runs anonymously.

Yes. A connector captures what Claude Code, Cursor, Devin, or Codex did into the same registry and audit trail as the rest of your workforce: who ran what, where, when. Observed, not enforced: policy enforcement over external coding agents is on the roadmap, and we’d rather say so than overclaim. (Claude Code also appears as a runtime above. That’s different: an agent you build in Damn using it as its engine, fully governed like any native agent.)