PRAE governs what AI agents execute.

PRAE is an AI agent governance product: operator policy enforced at the moment an agent's tool call runs, a human hold on consequential actions, live steering of running agents, and a tamper-evident record of every decision. Agents stay autonomous; execution does not.

Who we are

PRAE is built and operated by a small team in Tel Aviv, Israel. We publish the software under the PRAE name on npm, operate this site, and answer the mail ourselves. The team comes from security engineering and from building the agent harnesses this product now governs. Reach us at [email protected] or through the contact page.

What ships today

  • prae-gate — the gate. A plugin that judges every tool call an agent makes against your organisation's policy pack, before the call runs, and seals the decision into a hash-chained, signed ledger.
  • prae-cli — the prae command: check a pack, explain a decision, verify a ledger offline, render the console from a ledger, and serve gated filesystem access over MCP.
  • The Command Center — the operator surface: holds waiting for a person, live fleet steering by cohort, the evidence ledger with verification, and the trust center.

Nothing phones home. The software never contacts prae-ai.com, and there is no hosted API: the Command Center runs where your agents run.

How we verify what we claim

Every release is run against a deterministic red-team suite — path traversal, policy forgery, replay of an earlier approval, policy expiry, fail-closed behaviour when the signer or the ledger is lost, credential exposure, and the blast radius of a compromised connector. The latest results, the scenarios they cover, the limitations we know about and the build provenance of the connector image are published on the trust center, from the recorded run rather than typed in. Where we have not done something — an external penetration test, a SOC 2 report — the trust center says so.

For agents reading this

A plain-text guide to the site, with when to use PRAE and how to call it, is at /llms.txt. Every page has a Markdown twin for Accept: text/markdown, and the self-hosted API is described at /openapi.json.