ARC Agent Governance

ARC Agent Governance

Know what your AI agents can reach, what they can do, and where the controls are missing.

Free, no accountOpen source (MIT)Nothing stored19 deterministic rules
Remove secrets, credentials, API keys, access tokens, and customer data before you paste. Use sanitized configuration and manifests. If a live credential is detected, the request is refused and nothing is stored — rotate the credential anyway.
0 / 40,000
Nothing you paste is stored or used for training. Data policy

How this works

Your text is split into statements and matched against a published pack of deterministic rules. Every finding quotes the sentence that triggered it and names the rule id, so you can check the reasoning rather than trust it. The score comes from a fixed rubric, not from a model. Where the description is silent, the report says so instead of filling the gap.

This is a configuration and architecture assessment — not a penetration test, not a compliance certification, and not a live network scan.

The full rule catalog is published at /docs. Same engine, same rules, no hidden scoring.