Managed Workflow Gate — Enterprise Pre-Action Security
Turnkey installation of ThumbGate's pre-action firewall for 1 critical enterprise workflow. Prevent secrets exfiltration, destructive production commands, and blast-radius breaches with tamper-evident audit receipts.
1. The Managed Workflow Gate Offering ($499 Setup)
For small engineering and security teams deploying autonomous coding agents (Claude Code, Cursor, Codex, Cline), abstract "AI safety" is unhelpful. Engineering managers need deterministic controls that protect sensitive repositories, staging environments, and external cloud services before execution occurs.
The $499 Managed Gate includes direct setup, policy tuning for your risk surface, a 14-day evaluation period, and automated executive proof report generation.
2. The 5 Canonical Attack Scenarios Prevented
| Attack Vector | Agent Behavior | ThumbGate Interception | Outcome |
|---|---|---|---|
| 1. Secret Exfiltration | Agent curls private webhook with bearer token | Secret-Scanner & Network-Egress Gate | Blocked & Token Masked |
| 2. Destructive Commands | rm -rf /, DROP TABLE, force push |
MCP WriteGuard & Blast-Radius Gate | Blocked & Escalation Emitted |
| 3. Scope & Blast Radius Breach | Subagent edits security rules outside assigned scope | Task-Scope Lease & Path Gate | Halted with Scope Receipt |
| 4. Unauthorized Financial Action | Agent cancels retainer or provisions billable resources | Financial Control Plane | Requisition Check Intercepted |
| 5. Helper Script Evasion | Agent executes hidden wrapper script in /tmp | Stealth Memory & Stateful Helper Gate | Quarantined |
3. Tamper-Evident Audit Proof
Every evaluation creates a machine-readable, cryptographic receipt (proof/redteam-evidence-report.json) with SHA-256 event fingerprints that can be ingested into your SIEM, Datadog, or OpenTelemetry logging pipeline.
node scripts/redteam-5-attacks.js