An AI agent is code that decides, at run time, what to fetch, call, and send. A normal firewall was never built for that. RIL Warden is an application-layer firewall built specifically for AI agents: every outbound request an agent makes runs through one policy engine first.
What an agent firewall controls
Egress allowlist
Default-deny. Each agent can only reach the sites you approve. Everything else is blocked and logged.
Secret protection
API keys are injected server-side by name and only to the hosts they belong to. The agent (and the model) never sees the raw key.
Exfiltration + SSRF blocking
Known exfiltration and command-and-control channels are refused, and requests to internal/metadata addresses are blocked.
Kill switch
Freeze one agent or an entire fleet instantly when something looks wrong.
Why a prompt guardrail is not enough
Guardrails that filter what a model says do nothing about what an agent does once it has tools. A compromised or jailbroken agent can still call an API, read a secret, or post your data somewhere. Warden sits in the action path, so policy is enforced on the request itself, not on the text. See the full comparison on Warden vs NVIDIA guardrails.
Deploy it any way you run agents
Use the Python or Node SDK, the MCP server for Claude and Cursor, zero-code proxy mode, or raw HTTP. Lock down a Kubernetes namespace so agents can only egress through Warden. Read the quickstart.
Frequently asked questions
- What is an AI agent firewall?
- An AI agent firewall is a gateway that every outbound request from an autonomous AI agent passes through, enforcing which destinations are allowed, protecting API keys, blocking data exfiltration, and logging every action. RIL Warden is purpose-built for this.
- How is it different from a network firewall?
- A network firewall filters packets by IP and port. An agent firewall understands agent requests: it ties each request to a specific agent and policy, injects secrets the agent never sees, detects exfiltration patterns, and keeps a tamper-proof audit trail.
- Does it stop a jailbroken agent?
- It limits the damage. Even if the model is tricked, the agent still cannot reach a site you did not approve, cannot read a raw key, and cannot exfiltrate to a blocked channel - and every attempt is recorded and can trip a kill switch.
- How do I add it to my agent?
- Route the agent's web/tool calls through Warden via the SDK, MCP server, or proxy mode. It usually takes a few minutes; see the quickstart in the docs.
Related
Put a wall around your agents in 5 minutes
Free tier: 3 agents, 25,000 gateway requests a month, full signed history.
Start freeRead the guide