# PRAE > PRAE is the control plane for enterprise AI agents: operator policy enforced at the moment an agent's tool call runs, a human hold on consequential actions, live steering of running agents, and a tamper-evident, signed record of every decision. It installs beside the agent as an npm package; nothing is sent to prae-ai.com. PRAE (prae-ai.com) is built and operated by the PRAE team in Tel Aviv, Israel. The software is published on npm as `prae-gate` (the gate: a plugin that judges every tool call against a policy pack) and `prae-cli` (the `prae` command: check a pack, explain a decision, test a pack against security invariants, verify a decision log, render and serve the console, and serve gated filesystem access over MCP). The policy pack format is JSON; decisions are sealed into a hash-chained ledger signed with the ledger key, and an operator's ALLOW, DENY or STEER of a held call is signed with the operator key. Every page on this site has a Markdown twin: request it with `Accept: text/markdown`, or append `index.md` to a page path (for example https://prae-ai.com/trust/index.md). A missing page returns a Markdown or JSON 404 for readers that ask for one. ## When to use PRAE Reach for PRAE when the job is one of these: - An autonomous agent (Claude Code, Codex, Cursor, Copilot, Windsurf, a custom agent, or an MCP client) can call tools that reach production data, payments, cloud infrastructure, source control or external channels, and the organisation needs those calls judged by its own policy before they run — not detected afterwards. - A consequential call must wait for a person: a refund above a threshold, an export of customer records, a push to a protected branch, a destructive cloud operation. PRAE holds the call, shows the operator exactly what would run, and releases it only on a signed answer. - An operator must change what a running agent, or a whole cohort of agents, does next — pause, steer to a constraint, require approval, contain — without stopping the fleet. - Security, GRC or a customer's reviewer needs proof: which policy was in force, what each agent tried, what PRAE decided, and a chain of receipts that any party can verify offline (`prae verify`). - A team wants to red-team its own agent setup: PRAE ships a deterministic attack suite (path traversal, policy forgery, replay, policy expiry, fail-closed, credential exposure, connector blast radius) and publishes the latest results on the trust center. Do not reach for PRAE to detect prompt injection, to sandbox a process at the OS level, or as a hosted API: it bounds what an injected agent can execute, it is not a sandbox, and it has no cloud endpoint. Details and limits: https://prae-ai.com/trust/ ## How an agent calls PRAE - Install: `npm install -g prae-cli` (the `prae` command) and add `prae-gate` to the agent harness as a plugin. - `prae check ` validates a policy pack; `prae explain [key=value …]` says why a call is allowed, held or refused; `prae test ` runs a pack against security invariants; `prae verify ` checks the hash chain and signatures offline; `prae console --out [--serve [port]]` renders the console from a ledger and, with `--serve`, serves its record API on localhost. - `prae mcp --root [--pack ]` is an MCP server (stdio transport): gated filesystem access for any MCP-capable IDE or agent, every call judged by the pack and sealed into the ledger. There is no hosted MCP endpoint. - The HTTP API (self-hosted, localhost only) is described at https://prae-ai.com/openapi.json: the record, ledger and verification endpoints that `prae console --serve` exposes, and the Command Center's operator, fleet and trust endpoints, which today ship with the Command Center server rather than in prae-cli. - There is no public API key and no SaaS endpoint. Anything that looks like one is not PRAE. ## CLI - [prae-cli on npm](https://www.npmjs.com/package/prae-cli): `npm install -g prae-cli`, or `npx prae `. Open source, MIT. - `prae check ` · `prae explain [key=value …]` · `prae test ` · `prae scan ` · `prae verify ` · `prae report ` · `prae console --out [--serve [port]]` · `prae mcp --root ` · `prae init` - Every command prints `--help`; JSON output where it matters (`--json`), so an agent can parse what it reads. - [prae-gate on npm](https://www.npmjs.com/package/prae-gate): the gate the CLI's packs are written for. ## Docs - [Developers](https://prae-ai.com/developers/): packages, install, CLI, API description, policy pack format - [Trust center](https://prae-ai.com/trust/): latest validation run, scenario coverage, limitations, build provenance and SBOM references - [Platform](https://prae-ai.com/platform/): how PRAE sits beside the controls an enterprise already runs - [Why PRAE](https://prae-ai.com/why-prae/): who it is for, and where it stands against detection-only tools - [Compliance](https://prae-ai.com/compliance/): the controls PRAE evidences and the frameworks they map to - [Privacy](https://prae-ai.com/privacy/): what this site collects (one analytics beacon), and that the software never contacts us ## Products - [Policy enforcement](https://prae-ai.com/products/policy-enforcement/): the gate at the tool seam - [Live fleet steering](https://prae-ai.com/products/fleet-steering/): cohort control of running agents - [MCP gateway](https://prae-ai.com/products/mcp-gateway/): inspection of every MCP tool call before it reaches the server - [Developer agents](https://prae-ai.com/products/developer-agents/), [Custom agents](https://prae-ai.com/products/custom-agents/), [Deployed SaaS agents](https://prae-ai.com/products/deployed-saas-agents/), [Shadow AI](https://prae-ai.com/products/shadow-ai/) ## Solutions by surface - [Claude Desktop](https://prae-ai.com/solutions/claude-desktop/), [Cursor](https://prae-ai.com/solutions/cursor/), [GitHub Copilot](https://prae-ai.com/solutions/github-copilot/), [Windsurf](https://prae-ai.com/solutions/windsurf/), [MCP servers](https://prae-ai.com/solutions/mcp-server/), [Node / TypeScript](https://prae-ai.com/solutions/node-typescript/), [AWS ECS, EKS and Lambda](https://prae-ai.com/solutions/aws-ecs-eks-lambda/), [Cloud agent services](https://prae-ai.com/solutions/cloud-agent-services/), [Microsoft 365 Copilot](https://prae-ai.com/solutions/microsoft-365-copilot/), [Slack AI](https://prae-ai.com/solutions/slack-ai/) ## Company - [About](https://prae-ai.com/about/) - [Contact](https://prae-ai.com/contact/): thetalosteam@gmail.com, Tel Aviv, Israel - [Security policy](https://prae-ai.com/.well-known/security.txt) - [Sitemap](https://prae-ai.com/sitemap.xml) ## Optional - [Command Center demo](https://prae-ai.com/console/): the operator surface, rendered from a recorded run - [Playground](https://prae-ai.com/console/playground/): a 250-agent simulated fleet judged by the real policy engine in the browser - [npm: prae-gate](https://www.npmjs.com/package/prae-gate), [npm: prae-cli](https://www.npmjs.com/package/prae-cli)