LOCAL FIREWALL FOR SOLOPRENEURS & BUILDERS

Agents that can't leak keys, blow budgets, or break prod.

A local firewall for your AI coding tools. One command to install, no DevOps required.

Order Samurai enforces deterministic execution hooks to stop runaway API spend, scrub secrets, and halt dangerous AI commands at the shell layer — 100% on your Mac with zero model calls for policy evaluation.

⚡ 60-Second Terminal Setup • One curl|bash Command • Mac OS 12+
FIRST-INSTALL AUDIT < 60s REPORT
Target Machinelocal (~/.samurai)
PostureFAIL-CLOSED
Prompt Injections2 Intercepted
Secret Leakage1 Scrubbed (.env)
Spend Delta$318.40/wk saved
Reads existing logs automatically • Zero Setup
PROTECTS CLAUDE CODECODEX CLIGEMINI CLICURSORLANGGRAPHOPENCODE
ZERO DEVOPS REQUIRED

How Order Samurai Protects Your Business in 3 Steps

STEP 01

60-Second Terminal Install

Run one command in Terminal (curl | bash). No complex server setup required — it installs a local CLI and background scripts that run silently.

STEP 02

Set Your Daily Guardrails

Pick your maximum daily API budget (e.g. $15/day). If an AI agent enters an infinite loop, Order Samurai pulls the emergency brake.

STEP 03

Build Without Fear

Run Claude, Cursor, or ChatGPT freely. Passwords are hidden, dangerous file wipes are blocked, and you get a clean daily report.

[SECURITY]Blocked Chain 13 prompt injection in subagent spawn (Claude Code)
[SPEND]Enforced active daily spend cap threshold ($5.00 limit)
[SCRUB]Redacted AWS_SECRET_ACCESS_KEY from stdout
[RONIN]Auto-remediated 14 ATT&CK kill chain vulnerabilities
[VERIFIER]Enforced fail-closed sandbox policies across 42.5 agent hours
Dojo Targets & Impact

Engineered for Builders, Solopreneurs, and Custom Harnesses.

Whether you are running raw agents or developing complex local wrappers, the Dojo enforces discipline where generic prompts fail.

SOLOPRENEURS

Protect Your Single-Point-of-Failure Business

As a solo developer, you rely on AI agents to act as your team. But a single unchecked command can break your client databases, install compromised dependencies, or wipe local repos. Order Samurai runs as your silent co-pilot, letting you build fast without the risk of a business-ending mistake.

// Safety rails for one-person operations
CUSTOM HARNESSES

Power Up Your Agent Runtimes Safely

Developing custom wrappers, CLI interfaces, or workflows for Claude, Codex, or Gemini? Order Samurai acts as a secure local middleware. Wrapping your runtimes directly in standard inputs/outputs, it redacts credentials and isolates execution without adding latency to your pipeline.

// Sits seamlessly between your harness & the shell
VISIBLE METRICS

Making the Invisible Visible: Observe Your Peace of Mind

Usually, security is under-appreciated because when it works, it is invisible. Nothing breaks, and no keys leak. Order Samurai makes that security tangible. Our dashboard tracks and displays every single exfiltration block, budget save, and runtime kill, showing you exactly how hard your Dojo is working.

// Hard security metrics you can actually see
FOUR SAFETY SHIELDS · HOW WE PROTECT YOU

Four core safety pillars. One simple dashboard. Zero cloud telemetry.

Every tool call, file edit, and AI command is checked against four non-negotiable business safety rules before execution.

PILLAR 01 · SECURITY & PRIVACY

SWORD — Password & Key Shield

Real-time security defense that hides secret keys, passwords, and customer credentials from AI agents before commands execute. Halts malicious prompt injection attacks instantly.

✓ Password & Key Redactor✓ Dangerous Command Interceptor
METRICSTATUSVALUE
Prompt Injection DefensePROTECTED100 / 100
Credentials LeakedCLEAN0 Leaked
Emergency BrakeACTIVEFail-Closed
METRICSTATUSVALUE
Daily Spend CapENFORCED$12.50 / $50.00
Infinite Loop BreakerARMEDMax 3 Retries
Spend ProtectionACTIVE$3,940 Saved
PILLAR 02 · SPEND & BUDGET CONTROL

BOW — Runaway Spend Guard

Set a hard daily budget cap (e.g. $15/day). Prevents $1,000+ surprise API bills by detecting and stopping infinite AI retry loops automatically.

✓ Daily Budget Cap✓ Infinite Loop Breaker
PILLAR 03 · CODE SAFETY & INTEGRITY

BRUSH — Safe Code Enforcement

Verifies every code edit before it touches your files. Mandates strict backup and safety checks so AI agents never corrupt your project databases or wipe files.

✓ File Safety Shield✓ Automated Health Checks
METRICSTATUSVALUE
Suite Pass Rate100%1,000+ tests
Vulnerabilities Detected0 HIGH0 Critical
Database SafetySAFEProtected
METRICSTATUSVALUE
Telemetry LocationLOCAL~/.samurai
Telemetry to UsNONEBy Default
Default AnalysisLOCALOn-Device
PILLAR 04 · LOCAL DATA PRIVACY

ARTS — 100% On-Device Protection

Order Samurai performs local analysis by default and sends zero cloud telemetry to us. Optional third-party AI review runs only when you explicitly enable a provider using your own credentials — data sent to that provider is then governed by the provider's terms. See our Privacy Policy for details.

✓ Local-First Execution✓ Complete Data Privacy
AUTONOMOUS GOVERNANCE ARCHITECTURE

Ronin Mode & The Self-Improving Loop.

Observability without reflexes is just an expensive audit log. Order Samurai pairs continuous background Ronins with real-time reflex interception and overnight Dojo cycles — transforming reactive agent oversight into an autonomous self-healing engine.

01 · THE RONIN LOOP

Continuous Fleet Guardian

Operates as an autonomous background guardian across IDE namespaces and agent runtimes. Evaluates every tool execution and file change against the four-pillar governance contract without requiring active prompt engineering.

02 · REFLEX ALERTS

Defending the Floor

Deterministic, zero-latency interception. When a pillar metric degrades (prompt injection attempt, secret in staged diff, runaway spend spike), reflexes fire instantly to block the action and isolate the process before failures compound.

03 · DOJO CYCLES

Raising the Ceiling

Structured, autonomous training runs (Keiko) that run while you sleep. The Dojo processes task backlogs, executes automated regression sweeps, stages patches via maker-checker verification, and continuously recalibrates baselines.

SELF-IMPROVING FEEDBACK LOOP

From Traps to Calibrated Baselines.

Every intercepted prompt injection and completed Dojo work-unit feeds back into local calibration coefficients. The system learns the exact baseline performance of your fleet across Claude, Codex, Antigravity, and Cursor — making defenses sharper every night.

AGENTIC LOOP FLOW
1. REACTION → Intercept injection / scrub secret
2. ISOLATION → Stage patch to pending_remediation
3. DOJO CYCLES → Execute overnight keiko backlog run
4. CALIBRATION → Update empirical metrics & thresholds

Proof, labeled honestly.

Anonymized 30-day pilot fleet. A figure stays SIMULATED until twenty empirical samples exist — we'd rather print a gap than fake a graph.

$3,940
median runaway-spend incident intercepted before execution
● MEASURED
42.5h
agent time returned per week through overnight remediation
● MEASURED
212
secrets scrubbed pre-commit across 14 monitored kill chains
● MEASURED
42s
mean time to heal a routine degradation, unaided
○ CALIBRATING (12/20)
Built by Gemkai & Order Samurai Open-Core Contributors
47 metrics in catalog22 live reducers1,000+ automated tests · counted 2026-08-09
ENGINEERING JOURNAL & RESEARCH

Dispatches from the Frontier.

Deep dives into agent runtime security, token governance math, and fail-closed architecture patterns.

SECURITY DISPATCH ISSUE #01

Fail-Closed Security Hooks for Autonomous Coding Fleets

How to intercept prompt injection attacks and credential leaks at the shell layer before tool calls reach execution.

Read Published Dispatch #01 →
UPCOMING DISPATCH

Next Dispatch: The LLM Judge Paradox →

Why self-grading observability dashboards flatter failure modes and how deterministic verifiers preserve metrics integrity.

A flat price, kept flat.

"Your agents' verbosity is your productivity, not our tax — zero token markups."

No trace metering or per-token upcharges. All software runs locally on your hardware.

FREE CORE — SOLO DEVS
$0 forever
For solo developers auditing local agent logs. Includes 4-pillar scoring, credential scrubbing, and 60-second initial log audit.
Download Core Version (.zip) View Source Code on GitHub →
PRO LIFETIME — AUTONOMOUS FLEETS
$199 one-time
For fleets that run while you sleep. Active spend capping, Nightly Dojo, autonomous reflex remediation, and offline perpetual key.
$3,940 → $120
$3,820 saved. Median runaway spend loop halted before execution.
● MEASURED
Get Pro Lifetime ($199)

Core vs Pro Initial Audit Comparison

Governance & Audit Capability Free Core ($0) Pro Lifetime ($199)
Automatic First-Install Audit ✓ 60-Second Log Ingestion ✓ 60-Second Log Ingestion
Historical Audit Depth 7-Day History Window Full 90-Day Trajectory Archive
14-Chain ATT&CK Security Hooks ✓ Fail-Closed Interception ✓ Fail-Closed Interception
Initial Vulnerability Sweep Scrubbing & Log Warnings Auto-Stages Fix Patches
Fault Remediation & Self-Healing Manual Staged Patches (.patch) ✓ Autonomous Ronin Auto-Apply (Worktrees)
Operator Mutation Security Standard Terminal Confirmation ✓ Touch ID Authorization (LocalAuthentication)
Multi-Model Consensus & Audit Single-Pass Heuristics ✓ Sensei Rival Verification Loop
Knowledge Retrieval Telemetry Basic Hit Counts ✓ 9-Point Deep Telemetry (p50/p95, Cache %)
Audit Ledger Integrity Local State JSON ✓ Cryptographic SHA-256 Hash Chain
Spend Capping & Model Routing Alert-Only Warning Caps ✓ Active Runtime Kill Enforcement

Download & Install Order Samurai

Get up and running in under 60 seconds via a single terminal command — no separate Mac app required.

Download Core (.zip)
OR RUN VIA TERMINAL (DEVELOPERS):
$curl -fsSL https://www.ordersamurai.ai/install.sh | bash

Scans existing Claude Code and local AI logs automatically, generating your initial safety & spend report in under 60 seconds.

What happens after installation?
✓ Runs as a local CLI + background scripts
✓ Daily spend caps activate automatically
✓ Password & key redactor begins shielding output
✓ Daily morning safety report generated locally