Product

How Lilith is built. Policy on the call, kernel on the syscall, a log that still means something.

How it is built

1 Enroll-2 Decide-3 Bind-4 Seal

1 Enroll

The agent is a process on a Linux kernel. Coding agents and custom agents. Enrollment is the process, not a vendor plugin. WSL counts. A Mac is a desk.

2 Decide

Policy engine. Each tool call: principal, action, resource, context. An interoperable protocol, so custom agents use the same path. Expressive enough for the real rule. Formal verification is built in. Proven before anything goes live.

3 Bind

Kernel enforcer. We halt syscalls. BPF extensions, verified by the kernel before they attach. Userspace does not get to argue with a deny. Fail closed: enforcer dies, the process is caged.

4 Seal

Observability. Each decision is written to a node log sealed with HMAC. A Merkle tree chains the events. The root is the tip. Edit a past deny, verify fails. Search copies are not the seal. Tamper evident.

Two parts make the decision hold: the engine writes the rule, the kernel makes it bind. The fourth part is so the story of what happened cannot be quietly rewritten. Simple machinery. Highest guarantee.

Properties

Platform
Systems
LinuxKubernetesWSLMac
Agents

Coding agents and custom agents. Lilith integrates because the policy engine is an interoperable protocol, not a vendor plugin.

CursorClaude CodeCopilotCodexGeminiWindsurfCustom

Use cases

Fintech and banks

Banks already put agents on fraud queues, KYC, and payment ops. The useful work is reading the case and drafting what a human should do. The failure is the last mile: ACH, SWIFT, an internal book transfer, a CSV of every customer. Lilith allows the score and the draft. The send and the export are denied at the syscall, even if the model has already said yes. That deny is in the sealed log.

Medicine

A hospital agent that can open one chart will try to open all of them. Same for PACS, claims files, the research extract. Policy names the patient and the action: this encounter, this study. Bulk export and the next MRN over are denied. If it already had her labs, that still counts when it reaches for the rest of the ward. The control is which record, on which call.

Defense

Classified and restricted shops still want coding agents on the project tree. The model will fetch from the public internet or pack up a share if the prompt asks. Enrolled, the process talks where policy says: the internal model, the repo, a ticket system on the same side of the fence. Crossing a classification boundary is a kernel deny. Unenrolled processes do not get a seat. The record of the deny survives a rewrite of the chat.

Live systems

Merge bots and coding agents are fine in staging. They become an incident when the same process holds prod credentials: the kubeconfig, the root CA, terraform on the money VPC. Lilith keeps npm test and the staging cluster. Production apply and the secret store stay closed. A prompt that says to fix prod does not open those paths. The kernel never takes that meeting.

Home OpenSource Write

BadCompany, 2026. Born out of mesh.(R)

Team | Git