The open enforcement foundation.
from enforcecore import PolicyEngine, Sandbox
# Load policy
policy = PolicyEngine.from_yaml("policy.yaml")
# Wrap any agent
safe = Sandbox(
agent=my_agent,
policy=policy,
allow_network=["api.openai.com"],
allow_fs=["/tmp/workspace"],
max_cost_usd=5.00,
redact_pii=True
)
# Run — enforced
result = safe.run("Analyze Q3 earnings")Built for production workloads.
Sub-millisecond policy evaluation. Kernel-level isolation. Zero runtime dependencies.
- Policy latency
- < 0.5 ms
- Language
- Rust core
- SDK
- Python
- Policy format
- YAML / Rego
- Audit format
- Merkle / JSON
- Sandbox
- Kernel-level
- License
- Apache 2.0
- Deployment
- Library / Sidecar
The enforcement layer that any agent system can use.
Enforcement Primitives
Six foundational primitives that make policy violations structurally impossible at the kernel level.
Policy-as-Code Engine
Kernel Sandboxing
Merkle Audit Trails
PII Redaction Engine
Cost Kill-Switch
Tool Permission Framework
Three lines to enforce.
Works with LangChain, AutoGPT, CrewAI, or any custom orchestrator. No SDK required.
Define constraints in YAML or Rego. Version-control policies like application code.
Every decision is logged to a Merkle tree. Export JSON for compliance audits.
Policies compile to WASM. Evaluation overhead is sub-millisecond at p99.
# policy.yaml
version: "1.0"
rules:
- name: block-financial-advice
match:
output: "regex:you should (buy|sell|invest)"
action: deny
severity: critical
- name: pii-redaction
match:
output: "entity:PERSON|SSN|CREDIT_CARD"
action: redact
- name: cost-limit
match:
token_spend: "> 10000"
action: kill
notify: ops@company.comThree layers. One stack.
Foundation
EnforceCore
Open enforcement primitives (Apache 2.0). Use standalone or as the base for AKIOS.
Production
AKIOS Core
Complete runtime (GPL-3.0-only). Adds governance, RADAR observability, FLUX cost control.
Cloud
AKIOS Pro
Cloud management plane. RADAR dashboard, FLUX metering, policy sync, team RBAC, audit exports. Credit-based. The SDK is free.
We're opening EnforceCore to the community. If you're building agentic systems and need kernel-level enforcement, contribute or grab a design partner slot.
Design Partner Slot
Open Source · Apache 2.0

Frequently Asked Questions
Go beyond EnforceCore with AKIOS.
| Compare tiers | EnforceCore Free (Apache 2.0) | AKIOS Core Free (GPL-3.0-only) | AKIOS Pro Invite-only (beta) |
|---|---|---|---|
| Enforcement | |||
| Policy-as-Code Engine | |||
| Kernel Sandboxing | |||
| Merkle Audit Trails | Local | Local | Centralized |
| PII Redaction | |||
| Cost Kill-Switch | |||
| Production | |||
| Governance Workflows | |||
| RADAR Observability | |||
| FLUX Cost Control | |||
| Multi-Agent Orchestration | Basic | Advanced | |
| Cloud & Enterprise | |||
| RADAR trace dashboard | |||
| Team RBAC | |||
| Credit-based billing | |||
| SSO / SAML / VPC (Enterprise) | Enterprise add-on | ||
| Enforcement | |
|---|---|
| Policy-as-Code Engine | |
| Kernel Sandboxing | |
| Merkle Audit Trails | Local |
| PII Redaction | |
| Cost Kill-Switch | |
| Production | |
| Governance Workflows | |
| RADAR Observability | |
| FLUX Cost Control | |
| Multi-Agent Orchestration | |
| Cloud & Enterprise | |
| RADAR trace dashboard | |
| Team RBAC | |
| Credit-based billing | |
| SSO / SAML / VPC (Enterprise) | |
| Enforcement | |
|---|---|
| Policy-as-Code Engine | |
| Kernel Sandboxing | |
| Merkle Audit Trails | Local |
| PII Redaction | |
| Cost Kill-Switch | |
| Production | |
| Governance Workflows | |
| RADAR Observability | |
| FLUX Cost Control | |
| Multi-Agent Orchestration | Basic |
| Cloud & Enterprise | |
| RADAR trace dashboard | |
| Team RBAC | |
| Credit-based billing | |
| SSO / SAML / VPC (Enterprise) | |
| Enforcement | |
|---|---|
| Policy-as-Code Engine | |
| Kernel Sandboxing | |
| Merkle Audit Trails | Centralized |
| PII Redaction | |
| Cost Kill-Switch | |
| Production | |
| Governance Workflows | |
| RADAR Observability | |
| FLUX Cost Control | |
| Multi-Agent Orchestration | Advanced |
| Cloud & Enterprise | |
| RADAR trace dashboard | |
| Team RBAC | |
| Credit-based billing | |
| SSO / SAML / VPC (Enterprise) | Enterprise add-on |