WINDOWS SECURITY LAYER FOR AI CODING AGENTS

Phylax stops agents before they touch your private files.

User-mode Windows ACL enforcement. DENY ACEs + Mandatory Integrity Control labels. Phase 1 — kernel minifilter driver in development.

100% local  ·  No accounts  ·  No cloud  ·  No telemetry

phylax daemon
08:16:08 AGENT opencode.exe detected
08:16:08 TRY opencode.exe → .env
08:16:08 MATCH deny bucket → .env
08:16:08 BLOCK ACCESS_DENIED
08:16:09 AUDIT stored in local SQLite
Phylax ● LIVE
01

Why Phylax

The problem is real. The solution is local.

The problem

AI agents like Claude Code, Cursor, and OpenCode have full filesystem access. They can read, write, or delete anything.

The solution

Phylax puts a real OS-level boundary between them and your secrets. No proxy, no wrapper. The kernel enforces it.

100% Local

No account, no cloud, no telemetry. Everything stays on your machine. Audit logs in local SQLite. Works fully offline.

Multi-Agent Detection

Recognizes Claude, Cursor, OpenCode, Copilot, Windsurf, Aider, and more. Detects agents by process name, environment variables, and child inheritance.

OS-level Enforcement

Applies real Windows ACLs (DENY ACEs + Mandatory Integrity Control). The kernel itself returns ACCESS_DENIED - the agent never touches the file.

Anti-bypass protection

Phylax applies three layers of Windows security to every denied file: DENY ACEs for read/write/delete, WRITE_DAC protection for ACL modification, and Mandatory Integrity Control to stop privilege bypass.

02

How it works

Three steps. Zero cloud.

No cloud proxy, no API keys, no network required. Everything runs locally on your machine.

01

Detect

Identifies AI agent processes by image name, environment variables, and command-line inspection. Child processes inherit the agent label automatically.

02

Decide

Checks your phylax.toml rules against the file path and operation. Deny always wins. Priority-ordered buckets resolve every access attempt.

03

Block

Applies real Windows ACLs. The kernel returns ACCESS_DENIED before the agent touches a single byte. No userspace trick can bypass it.

target="_blank" rel="noreferrer"> See full architecture → Docs
03

Real example

A real example.

This is what happens when an AI agent tries to access a protected file.

phylax audit tail ● LIVE
08:16:08AGENTopencode.exe detected (env: OPENAICLIENT)
08:16:08TRYopencode.exe → read .env.local
08:16:08MATCHdeny bucket → .env.*
08:16:08BLOCKDENY ACE applied → ACCESS_DENIED
08:16:08MICHigh Integrity label applied
08:16:09AUDITevent stored in local SQLite

Three layers of Windows security: DENY ACEs block file access, WRITE_DAC prevents ACL modification, and Mandatory Integrity Control stops privilege bypass. The kernel returns ACCESS_DENIED, the agent never sees a single byte.

04

Policies

Choose your protection level.

Phylax uses six permission buckets ordered by priority. Deny always wins. Start with a preset, then customize via phylax.toml.

Priority
deny Complete block
ask User approves
full Unrestricted
delete Read + Delete
write Read + Write
read Read only

Conservative default When no rule matches: read = Allow, write = Ask, delete = Deny.

Maximum control

Strict

Maximum security. Every source edit and lockfile change requires explicit approval.

Denies .env, .pem, .key, .p12, .pfx, secrets/**. Asks for every source edit. Read-only by default.

[project]
name = "phylax-strict"
default = "conservative"

[deny]
files = [".env", ".env.*", "secrets/**", "keys/**", "*.pem", "*.key", "*.p12", "phylax.toml"]

[ask]
files = ["src/**", "tests/**", "Cargo.lock", "package-lock.json", "migrations/**"]

[read]
files = ["README.md", "docs/**", "src/**", "tests/**"]
Low friction

Fast & Flexible

Lets agents edit freely. Only secrets and the manifest are protected.

Blocks .env, .pem, .key, phylax.toml. Everything else is writable. No prompts for normal edits.

[project]
name = "phylax-fast"
default = "conservative"

[deny]
files = [".env", ".env.*", "secrets/**", "*.pem", "*.key", "phylax.toml"]

[write]
files = ["src/**", "tests/**", "docs/**", "examples/**", "Cargo.lock", "package-lock.json"]

[read]
files = ["README.md", "docs/**", "src/**", "tests/**", "examples/**"]
04

Security Status

Phase 1 limitations & transparency

Phylax is under active development. Phase 1 provides real protection, but understanding its boundaries is essential before relying on it.

What Phase 1 protects
  • Blocks read, write, and delete operations on files matching [deny] patterns
  • Applies real Windows DENY ACEs enforced by the kernel at ring 3
  • Three-layer anti-bypass: DENY ACEs + WRITE_DAC + MIC labels (High Integrity)
  • Detects 9 AI agents via 5 priority-ordered signals
  • All audit events stored in local SQLite
  • Zero network requests — runs fully offline
Known limitations (Phase 1)
  • Protection is active while the daemon runs. phylax stop removes DENY ACEs
  • DENY ACEs apply to Everyone (including you). Stop the daemon to edit protected files
  • ~750ms polling window between agent detection and ACE application
  • Audit logs in SQLite are user-writable — an agent with filesystem access could modify them
  • Killing the daemon process removes all protection
  • No per-agent differentiation yet (Phase 2)
Phase 2 (in development) will address these

The kernel minifilter driver (driver/phylax.sys) will provide: agent-only blocking (you keep access), IRP-level interception with zero polling delay, protection that survives daemon restart, tamper-proof kernel audit, and per-agent overrides.

FeaturePhase 1 (Current)Phase 2 (In Dev)
EnforcementWindows ACLs (user-mode)Kernel I/O IRP interception (ring 0)
Protection on daemon stopRemovedPersists (driver stays loaded)
Agent vs human distinctionNo (blocks Everyone)Yes (PID-based resolution)
Detection latency~750ms pollingZero (kernel callbacks + ETW)
Audit integrityUser-writable SQLiteKernel-level, tamper-proof
Bypass via killing daemonPossibleBlocked (driver persists)
Ask flow enforcementNot enforceableIRP paused, waits for user
Per-agent overridesStored, not evaluatedActive per-agent policy

Transparency note: This page exists so you can make an informed decision. No software is bug-free. If you find a vulnerability, please report it responsibly.

05

Install

Inspect the source first. Then install.

Read the code. Verify the checksum. Understand what you're running. No accounts, no cloud, no telemetry.

PowerShell
PS> irm https://raw.githubusercontent.com/TheUser99-spec/Phylax/main/install.ps1 | iex
No admin required. The daemon runs in the background.
Copied
⚠️ Before you run the installer

1. Inspect the installer script on GitHub — it's a single PowerShell file.

2. Verify the checksum before execution:

# SHA256 of install.ps1
Get-FileHash install.ps1 -Algorithm SHA256

Checksums are published with each GitHub release.

🛠️ Manual install (build from source)

Prefer to compile yourself? No problem.

git clone https://github.com/TheUser99-spec/Phylax.git
cd Phylax
cargo build --workspace --release

Requires Rust toolchain. The compiled binary will be in target/release/.

phylax init Creates phylax.toml and starts the daemon
phylax run Daemon + live terminal dashboard (60fps)
phylax stop Stops daemon and releases file locks
phylax status Live view: projects, agents, events, blocks
Runs locally No login No cloud No telemetry