We just released a new version of Patronus Protect:
Improved onboarding + enforce /Applications folder
Improved stability for gRPC connections
-
Improved handling of unknown carrier protocols like protobuf, msgpack, binary
Some more extraction patterns
-
Added heuristical threat analysis.
See why req, res, tools, mcps where flagged
Currently non-blocking, pure informational
-
Added ability to create Policy rules for MCP and Native Tool calls
Feel free to post some feedback, else see you next week with another amazing release and improvements :)
mailX by mailwarm
Congrats. How deep the visibility goes with MCP/tool calls, can Patronus see what an IDE agent is sending before it hits the provider, or is it mainly provider/app-level for now?
@thamibenjelloun Hey! Patronus intercepts any interaction between IDE agent and provider before it leaves the devices. MCP, A2A, native tools are discovered right away and logged as an audit.
Policy enforcement of blocking AI interactions are currently limited to only app / provider level.
In our follow-up release policies can be enabled for MCP discovery / tool calls. Also basic security for DLP, injection, safe tool usages will be integrated.
Hey PH 👋🏻, Dominik and Benedikt here, co-founders of Patronus from Regensburg.
Two things kept bugging us. First, every AI security tool we tried wanted to route every prompt through their cloud. Second, AI is scaling into everything — IDEs, browsers, OS-level agents, MCP servers — without a real last line of defense on the device itself.
So we built one. Patronus is an AI firewall that runs entirely on your Mac.
What it does:
→ Sees AI traffic across browsers, IDEs, native apps, MCP servers
→ Policies per app, per provider, per individual tool-call
→ locally and in realtime
What ships next:
→ Windows in about 2 weeks
→ Full policy engine + DLP heuristics in June
→ Full protection (PII redaction, prompt injection) in August
Free alpha, no login.
Curious: which AI tools are running on your Mac right now that your IT team has no idea about, and what workarounds (if any) do you have for securing AI today?
⁃ Dominik & Benedikt🐺