Cyntro Systems · Engineering

CONTROL LAYERS FOR AI SYSTEMS.

AI systems act. The interesting question is what keeps them in bounds. We build the layers that decide what an AI may install, change, remember and say – as running systems, not slides.

Everything on this page exists as running code. Part of it is open source – you can read it instead of taking our word.

SafeInstall

Open source · MIT

A CLI gate that evaluates policy before npm, pnpm or bun run a single install script: release age, lifecycle scripts, non-registry sources and trust downgrades by default; typo-squatting and Sigstore provenance opt-in. Built for developers and AI coding agents – shell hooks in Claude Code, Codex and Cursor, plus an MCP server through which agents consult the policy up front. A manipulated agent could simply rewrite the rules, though – which is why a committed hash baseline protects configuration, hooks and agent rule files themselves.

ACPIP

SDK in production use · two utility models filed

Adaptive Context Perception Injection Protocol – the control layer for what a live real-time AI perceives and when it speaks. Sensor and environment context enters the running session as a discrete event – no continuous audio or video stream. The AI stays silent about it until it becomes relevant, speaks up on its own when a deterministic detector demands it, and requests perception (camera, location, sensors) only when its reasoning needs it.

AgentGuard

Private beta

Vendor-neutral local control plane for repositories where several AI agents and humans work in parallel: tasks, branches, worktrees and pull requests in one view. It does not integrate with every tool individually – it instruments the places everyone passes through, git references and worktree state, and therefore also sees agents that have never heard of it. The question “who changed what, and is it merged?” gets exactly one true answer.

Continuity Core

In daily internal use

Every AI session starts from zero: decisions, findings and open questions die with the window. Continuity Core keeps them – readable by the next session, vendor-independent across Claude, Codex and Cursor sessions. Every entry carries its provenance; the log is append-only and auditable: not a notepad, but a record of evidence. It carries our own operations, every day.

Talk to the engineer

No sales layer. If you want to discuss protocols, agent infrastructure or a pilot, you reach the person who wrote the code.

office@cyntro.at