ShieldCortex
The security layer for AI agent memory. Like Cloudflare, but for everything your AI remembers. 6-layer defence pipeline, Iron Dome behavioural protection, and credential leak detection across 19 providers. One package. Full solution.
Free & open source β MIT licensed
6-Layer Defence Pipeline
Every memory write passes through six layers of protection β all running locally, all free
Input Sanitisation
Strips control characters, null bytes, zero-width chars, BOM markers, and bidirectional overrides before any analysis runs.
Pattern Detection
Regex-based firewall scanning for prompt injection, privilege escalation, and encoding obfuscation attacks.
Sensitivity Classification
Classifies content as PUBLIC, INTERNAL, CONFIDENTIAL, or RESTRICTED β blocks restricted content automatically.
Fragmentation Detection
Cross-references recent memories to detect attackers spreading malicious payloads across multiple entries.
Trust & Anomaly Scoring
Source-based trust scoring with automatic decay for sub-agents, plus entropy and anomaly heuristics.
Credential Leak Detection
39 patterns across 19 providers plus Shannon entropy analysis β catches API keys, tokens, and secrets before they reach memory.
Local Security Dashboard
Full visibility into your agent's security posture β running locally on your machine
Shield Overview
Real-time defence stats, threat breakdown, and pipeline health at a glance
Audit Log
Full searchable log of every scan β filter by result, source, and time
Quarantine Queue
Review and approve or reject quarantined memories before they enter storage
Real-Time Alerts
Live event feed for blocks, quarantines, and credential detections
Iron Dome
Agent-aware security that controls what your AI can do, not just what it remembers
Injection Scanning
Deep pattern matching for prompt injection, jailbreaks, and social engineering in any text
Action Gates
Control which actions agents can take β send emails, delete files, call APIs β with approval rules
PII Guard & Kill Switch
Block PII from leaving the agent, plus emergency stop to halt all agent activity instantly
Security Profiles
4 pre-built profiles β school, enterprise, personal, paranoid β or create custom policies (Pro)
Works With Your Stack
Use ShieldCortex as a standalone MCP memory server or integrate with your existing agent toolchain
OpenClaw
Native hook β auto-memory on by default with smart deduplication and novelty filtering
Claude Code
MCP memory server with 24 tools β remember, recall, scan, graph, and more
VS Code & Cursor
MCP integration for Copilot Chat and Cursor agent β one command setup
Universal Memory Bridge
Guard any memory backend with the full defence pipeline via the scan() API
Hierarchical Trust Security
Running multiple agents? ShieldCortex prevents rogue sub-agents from accessing sensitive data with automatic trust decay.
Credential Isolation
RESTRICTED memories blocked below trust 0.7 β sub-agents can't access your API keys or secrets
Trust Decay
Each sub-agent level reduces trust: user (0.9) β task (0.63) β subtask (0.44)
Depth Circuit Breaker
Agents beyond depth 5 get trust = 0. Automatic protection against runaway chains
Auto-Quarantine
Low-trust agents write to quarantine for human review before storage
Trust β₯0.7 β Read all, write direct Β |Β Trust 0.5β0.7 β Limited read, quarantine writes Β |Β Trust <0.5 β Own data only
Simple Pricing
Full defence pipeline, free and open source. Unlock custom rules and cloud sync with a licence key.
Free
- β Full 6-layer defence pipeline
- β Iron Dome (built-in profiles)
- β Credential leak detection (39 patterns)
- β Local dashboard
- β MCP memory system + knowledge graph
- β Skill scanner
- β Agent hooks (OpenClaw, Claude Code, Cursor)
Pro
- β Custom injection patterns (up to 50)
- β Custom Iron Dome policies
- β Custom firewall rules
- β LLM verification (AI-powered scan review)
- β Audit export (JSON/CSV)
- β Skill scanner deep mode
- β Priority email support
Team
- β Cloud audit sync across devices
- β Multi-device visibility
- β Team management & invites
- β Shared custom patterns
- β Unlimited injection patterns
Enterprise
- β Self-hosted deployment
- β SIEM integration
- β Compliance exports
- β Volume licensing + SSO
- β Dedicated support + SLA
Free and Pro run entirely on your machine β no cloud, no account required. Team adds cloud sync.
Iron Dome
ShieldCortex protects what your agent remembers. Iron Dome protects what it does. Injection scanning, action gating, PII protection, and emergency kill switch β all included free.
Built For
Secure Your AI Agent Memory
Open source, MIT licensed. Get started in under a minute.