Existing AI security tools scan code or manage secrets — nothing watches what agents actually DO at runtime. Grimdall intercepts every tool call (shell, files, APIs, deploys) and enforces your policy in milliseconds: block destructive commands, mask secrets, require human approval. Its audit trail is hash-chained and tamper-evident — edit one character and verification fails. One command: npx grimdall init --hooks. Open-source core, zero-config, works offline.