Enterprise · Conductor · v3.3.0 · Aug 8, 2026

You already run Pipelock on every agent. Now govern them as a fleet.

Run Pipelock free on every agent for protection. The Conductor governs the fleet from one place: shared rules, signed records of mediated actions, and one emergency stop no single person can pull alone. Anyone can check the signatures offline, no account needed.

Need a private walkthrough or design review? Talk to us about evaluation.

159

Public attack
cases (Bench)

7

Compliance
frameworks

Go

Single Go
binary

31,000+

Test cases
with race detection

11

Scanner
layers

65

DLP patterns
signed

Corpus snapshot verified against agent-egress-bench@fb75dbf6e381.

01 · Fleet

Running one agent is easy. A fleet is the hard part.

Already covered

You are already running Pipelock free on every agent.

The full scanner and enforcement engine is in the open-source core. One agent or a hundred, each instance protects itself and stands on its own.

The fleet question

At scale, one question has no single answer: what is every agent enforcing right now?

Per-host configs drift. There is no one place to see, set, and prove the policy the whole fleet is running, or to stop it at once when something goes wrong.

What it takes

Govern the fleet as one, and keep a record you can hand an auditor.

Distribute one signed policy, aggregate the signed evidence, and pull a kill switch that no single operator can fake or quietly undo.

02 · Conductor

What the Conductor does

01 Set the rules

Set your security rules once. Every agent runs them.

Push one policy to the whole fleet. No agent can quietly roll back to an older one, and once its signed policy expires, an agent that has lost the Conductor denies traffic by default instead of drifting.

What you get One policy across every agent
02 Emergency stop

Cut off every agent at once when something goes wrong.

One switch stops internet access across the fleet, or for a single agent. Turning it on, or back off, takes sign-off from more than one person, so a single rogue or hacked operator can't pull it or undo it alone.

What you get Takes more than one person to pull
03 The record

Keep a tamper-evident record of mediated agent actions.

Each agent signs its own record and sends it to the Conductor, which holds them all in one place. Because every agent signs its own, you don't have to trust the central system to believe what it says.

What you get Signed by each agent, not the server
04 See everything

See your whole fleet enrolled in one place.

One view, for an auditor or admin, lists every agent enrolled with the Conductor, its identity, and whether it is active. One roster instead of a pile of spreadsheets.

What you get One roster for the whole fleet
05 Onboard safely

Bring a new agent in with a one-time pass, not a shared key.

Each agent joins with its own one-time pass and gets its own identity. No shared secret pasted across every machine, waiting to be the one thing an attacker steals.

What you get One-time pass, per-agent identity
06 The long haul

Run the fleet for years, not just install day.

Retire an old agent for good so its access stops working, and back up the Conductor's data so a lost Conductor is a restore instead of a rebuild. Signing keys stay in your own key store.

What you get Add, retire, back up, restore

The scanner and enforcement run free on every agent. The Conductor is what ties them into one fleet you can govern. For what a single agent does on its own, see Pipelock.

03 · Proof

The part procurement cares about: you do not have to trust us

A Signed where it happens

Each agent signs its own record the moment it acts.

The signature comes from outside the agent's own code, so a compromised agent cannot rewrite it as its own log after the fact.

What you get Signed outside the agent process
B Check it yourself

Check the proof with the free Pipelock binary and the published signing key.

No Conductor, no account, no call home. The proof stands on its own math. If the control plane disappeared tomorrow, an auditor could still check the signed records on their own.

What you get Works offline, even without us
C Check vs create

Anyone can check the proof. Only the Conductor can create it.

That split is the whole point. The free version lets any team check a record itself. The paid Conductor is what produces one signed record across the whole fleet in the first place.

What you get Open to check, paid to produce
Pipelock operator console Signed Action Workbench: shipped conductor publish, kill, and rollback commands with read-only replay of past decisions
The Signed Action Workbench in the operator console: it prepares and replays signed fleet actions, and it is deliberately unable to submit them. Publish, kill, and rollback run through the shipped CLI with keys the console never holds. How the console works →
04 · Evidence

Evidence and auditability

Artifact 01

Flight recorder

Hash-chained audit log of scanner decisions, policy actions, and session events. Replayable.

Format: NDJSON · chain: SHA-256

Artifact 02

Signed assessments

pipelock assess generates HTML and JSON reports with framework mappings.

Signature: Ed25519 · 7 frameworks mapped

Artifact 03

Mediator-signed action receipts

Optional per-decision records signed from outside the agent trust boundary.

Verifier: pipelock-verify-python

Artifact 04

Posture verification

pipelock posture verify and pipelock verify-install support repeatable evaluation and CI gates.

CI gate: exit code 0 / non-zero

Artifact 05

Public proof surfaces

Public benchmark results, public docs, public mappings, and published release artifacts.

Public: /proof/ · /gauntlet/

Framework mappings, published in the public repo docs

OWASP Agentic AI Top 10 OWASP LLM Top 10 OWASP MCP Top 10 MITRE ATLAS NIST 800-53 EU AI Act SOC 2
verify.sh Reproducible · offline
$ pipelock verify-receipt receipt.json --key 70b991eb77816fc4ef0ae6a54d8a4119ddc5a16c9711c332c39e743079f6c63e
$ pip install pipelock-verify
$ pipelock-verify receipt.json --key 70b991eb...
05 · Adopt

Adopt without breaking production

Roll in safely

Start in observe-first mode across the live fleet.

The first objection at scale is that a blocking firewall takes down legitimate traffic on day one. Progressive enforcement answers it: observe first, then promote.

See before you block

Review what would have been blocked before you turn on enforcement.

Turn on shadow recording and every request that would have been blocked is written as a signed shadow receipt, so you promote with evidence instead of a guess.

Reversible

Rollback writes its own audit record.

Roll back to a policy you already approved, and the rollback is signed and logged like any other change. Nothing changes what the fleet enforces without leaving a record.

06 · Tiers

Free core, paid coordination

01

Free, on every agent.The full scanner and enforcement engine is the open-source core, Apache 2.0, a single binary. Detection is never behind a license, one agent or a thousand.

02

Pro adds multi-agent coordination.Per-agent policies and budgets for one operator running several agents. See pricing.

03

Enterprise is the Conductor.The fleet control plane: one set of rules everywhere, a remote kill switch, a signed record from every agent, and the tools to run it for years. Gated on the fleet license.

04

The rule behind the split.No attacker gets past the scanner because a team is on the free tier. The paid line is fleet coordination and governance, never the protection itself.

07 · Start

Where it is today.

The Conductor ships now as pipelock conductor commands: add and remove agents, publish policy, hit the kill switch, resume, and back up and restore. Self-service Enterprise purchase is live: start a $5k evaluation, take a design-partner slot, or buy the annual license. Prefer a conversation first? Talk to us.

Available now → shipped conductor commands and self-service purchase on the pricing page
Evaluation or design partner → luckypipe@pipelab.org