Your agent can reach production. Curber decides what it's allowed to do there.
Curber sits between an AI agent and its tools. It is not released yet. Join the beta waitlist below.
What has already gone wrong
- PocketOS, April 2026. A coding agent found an API token with broader access than intended and used it to delete a production database volume. The company's backups were deleted too. The hosting provider restored the data about an hour later. The Register
- Replit, July 2025. An AI coding agent deleted a production database during a code freeze the user had stated explicitly. The rollback turned out to work. The Register
- OpenClaw, February 2026. An agent lost the instruction "confirm before acting" when its context was compacted, then bulk-deleted hundreds of emails from its owner's inbox. Windows Central
In these cases the limit was a prompt or a token. Nothing outside the agent checked the action before it ran.
How Curber is designed to work
- Rules first. Every tool call is checked against your rules. Anything the rules don't cover is denied by default.
- Then judgement. Where a rule says so, an AI check looks at the context. It can only make a decision stricter, never looser.
- Then your approval on Slack. Risky calls wait for a person. The approval covers the exact call that was shown.
Use a sandbox and scoped tokens too. Curber is the approval and audit layer on top.
Join the beta waitlist
Curber is in development. We use your answers to decide what to build first and who to contact.