Secrets stay out of reach
.env and key files are unreadable where the agent runs. Keys and tokens never reach the agent.
The neutral control layer for teams of people and AI agents. Every action is checked against your rules, the right person decides, and everything is recorded.
It might do something I can't undo.
Delete files, push to main, deploy, change a database.
Preflight: deletes, pushes and deploys stop and ask. The agent can't push your code at all.
It might leak a secret.
Read a .env file, send keys somewhere they shouldn't go.
Preflight: secret files are unreadable where the agent runs, and your keys never reach it.
I can't tell what it actually did.
No record of what ran, why, and who allowed it.
Preflight: every plan, action, decision and result is kept, and nobody can edit the record.
Each action the agent asks for is checked here before it runs.
An example flow. A GitHub issue about a checkout total that is off by a cent is picked up by the Bug fixer, an always-on agent. It proposes 7 steps, two of them in parallel, and two other models review the plan as advice. The tech lead adds a limit, never change src/billing/, and approves. Every action passes 7 checks in a fixed order: reading Sentry and the code is allowed, an edit to the billing code is blocked by the limit, reading .env.production is blocked as a secret file, and the tests fail once, are fixed and pass. A team rule holds the production deploy until the CTO approves, and another holds the email to 312 customers until the Support lead approves. Every event is kept in the record.
Inside the approved plan the agent works alone. Outside it, it stops and asks.
When an agent wants to deploy
only if environment is production
in all projects then require the CTO
The rule matches: the command itself says production. The flow waits, and only the CTO is told.
No AI decides whether a rule applies. Unknown values never pass.
config/stripe.keyRefusedApprovals go to the job role that signs off. Silence never approves anything.
| Action | vercel deploy --prod |
| Asked by | Agent, in step 4 of plan v2plan approved by the tech lead |
| Rule | Production deploys need the CTOversion 3 |
| Evidence | environment = productionread from the command's --prod flag |
| Decision | Approvedby the CTO, 6 minutes after asking |
| Result | Ran, exit code 0 |
If an action can't be recorded, it doesn't run.
The sandbox has no internet. A command a person approved opens it, only to allowed sites, and it closes after.
.env and key files are unreadable where the agent runs. Keys and tokens never reach the agent.
Each flow gets its own worktree and branch. The agent can read Git but can't commit or push. People do.
API keys for Claude, OpenAI, Gemini or Grok, or your Claude Code, Codex, Gemini CLI or Grok Build plan.
Docker on your computer or Vercel Sandbox in the cloud, chosen per team.
Each flow knows what it spent. Budgets per flow, per day and per team.
Up to 3 models from different makers review a plan before you approve it. They advise; you decide.
Preview, code editor and terminal on the same files the agent works on.
| Capability | Agent alone | Approvals in one AI tool | A sandbox provider | Preflight |
|---|---|---|---|---|
| Works across models and tools | — | One tool | Yes | Yes |
| Team rules with business values | — | Limited | — | Yes |
| Approval by job role | — | — | — | Yes |
| Permanent record | — | Partial | Logs | Yes |
| Isolated place to run | — | Varies | Yes | Uses one |
No. It controls agents. The agent can think with Claude, OpenAI, Gemini or Grok. Preflight decides what it may do.
No. Inside the approved plan the agent works alone. You choose how much it decides by itself, and only risky or unexpected actions ask.
No. Rules are checked by plain code, the same way every time.
No. Git is read-only for the agent. People commit, in Preflight or in their own tools.
Secret files like .env are unreadable where the agent runs, and your keys never reach it. Keep production keys out of project folders, since a script the agent writes could use credentials stored there.
In an isolated sandbox: Docker on your computer, or Vercel Sandbox in the cloud. Your team chooses.
Your own API keys for Claude, OpenAI, Gemini or Grok, or the subscriptions you already have: Claude Code, Codex, Gemini CLI or Grok Build.
No. Your team's content is used only to run the service, and it's encrypted with your team's own key.
Yes. Every plan, action, decision and result is kept, and the record can't be edited.
We're opening Preflight to a small number of software teams first. Leave your work email and we'll write when there's a place for you.