HOL Guard

Open-source local guard that vets an AI coding agent's shell, file, package and MCP actions before they run.

ToolAI Agent SecurityOpen SourceCloudSelf-hosted

Pricing: Free tier at USD 0 with local scanning, on-device decisions and approvals; Guard Cloud plans at USD 4.99 per month (Solo), USD 15 per month (Pro) and USD 30 per seat per month (Team), with two months free on annual billing; Enterprise is custom pricing with SSO, SIEM integration and on-premises options.

Reviewed by the Cyber Vendor Guide editorial team against the public sources cited below · Last reviewed September 2026 · How we review listings

What is HOL Guard?

HOL Guard is an open-source, local-first runtime security layer that sits between an AI coding agent and the tools it wants to run. It evaluates shell commands, file access, package installs and MCP tool calls before execution and allows, blocks or routes them for approval according to policy, with the vendor stating that checks take under 50 ms and that files never leave the machine. It supports agents including Claude Code, Codex, Cursor, Gemini CLI, OpenCode and GitHub Copilot CLI, installs via pipx on Python 3.10 or later, and offers desktop installers for Apple silicon macOS 13 and later, Linux x86_64 and Windows x64, with Windows marked experimental. The core is Apache-2.0 and needs no account, while an optional Guard Cloud adds shared history, team policy and dashboards at USD 4.99 (Solo), USD 15 (Pro) and USD 30 per seat (Team) per month. It is made by HOL, operated by Hashgraph Online DAO LLC, a consortium established in November 2024 whose founding members include HashPack and Hgraph. The GitHub repository shows 570 stars and 3,705 commits, and PyPI lists version 3.0.131 released on 8 September 2026.

Best for: Developers and teams using AI coding agents who want local pre-execution controls on risky actions without sending data to a cloud service.
Pros
  • Apache-2.0 source on GitHub with 570 stars and PyPI releases using Trusted Publishing
  • No account or cloud connection needed for the free local tier
  • Published pricing for the optional cloud tiers
Things to check
  • Windows support is marked experimental on the install page, with WSL recommended
  • No certifications listed in the trust packet and no company location published

Reported in public reviews and vendor documentation. See sources below.

Key Features

Intercepts shell commands, file access, package installs and MCP tool calls before execution
Policy outcomes of allow, block or ask, with bundled strict, balanced and permissive presets
Runs locally with no account required on the free tier
Supports Claude Code, Codex, Cursor, Gemini CLI, OpenCode, GitHub Copilot CLI and other agents
Apache-2.0 licensed, with source on GitHub and PyPI releases published via Trusted Publishing
Plugin Scanner for agent plugins and MCP integrations, plus a GitHub Action with SARIF upload
Structured JSON SIEM events with raw commands, prompts and secret material redacted
Optional Guard Cloud for shared history, team policy and fleet dashboards

Do you work at HOL Guard? to confirm the details or send us a correction.

Quick Info
PricingFree tier at USD 0 with local scanning, on-device decisions and approvals; Guard Cloud plans at USD 4.99 per month (Solo), USD 15 per month (Pro) and USD 30 per seat per month (Team), with two months free on annual billing; Enterprise is custom pricing with SSO, SIEM integration and on-premises options.
ModelOpen source (Apache-2.0) with optional paid cloud subscription
Founded2024
CloudYes
Self-HostedYes
Open SourceYes

Last updated: Sep 8, 2026