LUVEO Technologies logo

New · Open source · Apache-2.0 / MIT

Vark.

A sub-millisecond execution firewall for AI agent tool calls. Vark sits between agent runtimes and system capabilities — even a fully compromised model can't execute what Vark blocks. Entirely offline, zero telemetry.

<2ms

Overhead per call

8

Pipeline gates

0

Cloud dependencies

100%

Open source

The pipeline

Every tool call runs 8 gates. Fail one, get blocked.

01

Normalize

Unicode NFKC, strips zero-width/bidi tricks, folds homoglyphs, recursively decodes URL/Base64/Hex/HTML layers.

02

Schema

Arguments validated against the tool's JSON Schema before execution — zero-dependency Draft-07 validator.

03

Breaker

Per-tool error thresholds halt cascading agent loops in under a millisecond.

04

Policy + Taint

Role-based YAML/JSON rules plus data provenance — untrusted web context never reaches sensitive arguments.

05

HITL

High-risk ops (db:drop, stripe:refund) pause for async human approval or a signed webhook.

06

Sandbox

Tool logic runs in isolated V8 heaps, permission-locked workers, or containers with copy-on-write virtual filesystems.

07

DLP

Outputs scanned for PII, secrets, entropy anomalies, and tracking leaks — without mutating streams.

08

Audit

Every invocation HMAC/Ed25519-signed into a tamper-proof, append-only hash chain.

Threat detection & DLP

Catches what blocklists miss.

  • Multilingual injection & jailbreak scanning across obfuscated formats
  • On-device semantic similarity checks against known threat clusters
  • Honeytoken canaries that freeze sessions on echo-back
  • Entropy scoring that catches memory dumps and prompt reflection
  • Reversible PII pseudonyms, restored only at authorized egress
  • Credential scanning for AWS, GCP, Azure, OpenAI, Anthropic, GitHub & more

Sandboxing & hardening

Execution with no way out.

  • V8 isolate sandboxes with strict memory ceilings and timeouts
  • Ephemeral copy-on-write virtual filesystem with automatic rollback
  • Shell AST parsing + strict argv exec — never shell: true
  • Path traversal & TOCTOU defense via realpath, O_NOFOLLOW, re-verification

Policy, MCP & access control

Rules the model can't talk its way around.

  • Declarative YAML/JSON policies with dry-run evaluation
  • MCP tool pinning by SHA-256 against rug-pull modifications
  • Taint tracking from untrusted sources to sensitive sinks
  • Ephemeral credential broker — the LLM never sees raw secrets
  • SSRF egress proxy with DNS pinning and metadata-IP blocks
  • Rate, cost, token, and output-size quotas per tool and identity

CLI & observability

Built for real workflows.

$ vark check <file>

Dry-run tool calls against policy

$ vark audit verify <log>

Verify cryptographic hash chains

$ vark policy test <policy>

Unit-test declarative policies

Deterministic replay

Exact 1:1 post-mortem replays

OTel + SIEM

Splunk, Datadog, webhooks

State stores

In-memory + Redis adapters

SDK adapters

Saturn, OpenAI, Anthropic, Vercel, LangChain, LlamaIndex

At a glance

Repositorygithub.com/luveo-technologies/vark
Licensing100% free & open source (Apache-2.0 / MIT)
Cloud requirementsZero — fully local & self-hosted
Execution overheadSub-millisecond (< 2ms per tool call)
Isolation targetsV8 isolates, QuickJS WASM, Worker Threads, containers
Audit verificationTamper-proof HMAC-SHA256 & Ed25519 hash chains
FrameworksSaturn AI, OpenAI, Anthropic, Vercel AI, LangChain, LlamaIndex, MCP

Free forever. Self-host in minutes.

Apache-2.0 / MIT. No cloud, no telemetry, no tiers. Read the code, run it locally, ship it on-premise.