Hadeda is a VPC-resident security gateway for AI coding tools like Cursor, Claude Code, and Windsurf. It filters commands, authorizes actions, enforces policies, and audits everything — inside your network, always.
We kept seeing the same pattern: teams adopting AI coding tools like Cursor, Claude Code, and Windsurf, but having no visibility or control over what those tools were sending to external APIs. Secrets leaking, commands running unchecked, zero audit trail.
Security teams were saying "block it entirely." Engineering teams were saying "we can't give this up." We built Hadeda to solve that standoff — a lightweight gateway that sits between your AI tools and the outside world, enforcing your policies without killing velocity.
What problem were you trying to solve?
Three things:
Secrets in transit — API keys, tokens, and PII flowing through AI agents with no scrubbing
No audit trail — When something breaks, there's no log of what the agent did or tried to do
All-or-nothing security — Teams either blocked AI tools completely or had zero guardrails
How did your approach evolve?
We started building a full proxy with its own config language. Realized nobody wanted another thing to learn. Pivoted to a flat YAML config, regex-based rules, and sub-2ms latency. The whole thing runs inside your VPC — your data never leaves your network.
It's free, open source, and under 10 minutes to set up.
Report
No reviews yetBe the first to leave a review for Hadeda