Nothing else.
You handed a program your keys, your files and an open socket. Cinctus is a self-hosted control plane that runs OpenClaw, Hermes, Claude Code — any MCP client — inside a sandbox that is locked down before you touch a single setting. Your keys, your files, your machine.
No account. No telemetry. One email when it ships, then we leave you alone.
AGPL core · Runs on a Pi or a €4 VPS · No vendor account
01 — THE PROBLEM
Personal agents went mainstream in 2026 faster than any self-hosted tool before them. The security did not come along for the ride. These are the numbers from the last few months. None of them required an attacker to be clever.
1 click
CVE-2026-25253. One link, and the agent's host is not yours any more.
NVD · CVSS 8.8341
Found in one marketplace audit, installed by one click, running with your agent's full rights. Later scans found hundreds more.
Koi Security, Feb 202640,000+
40,214 found in one scan, still rising. Most belong to someone who thinks they are on a LAN.
SecurityScorecard, Feb 2026chmod 644
Plaintext, in a config file, next to the code that reads your email.
The tooling that fixes this exists — agent firewalls, MCP gateways, policy engines. All of it assumes you are a security engineer with a spare afternoon. Cinctus is the same primitives, assembled, with the safe setting already on.
02 — WHAT IT DOES
No hardening guide, no policy language to learn. The defaults are the product; the settings are for loosening them on purpose.
Rootless container, read-only mounts, hard wall-clock and memory limits. An agent that gets owned takes its own box down with it and nothing else.
Deny by default. The agent reaches the hosts you named and no others, and every outbound request is inspected and written down before it leaves.
Keys never enter an agent's config. They are injected for the call that needs them and revoked from one place when something smells wrong.
Every skill and MCP server is checked against a reputation feed before it is allowed to run once. The feed gets better every time an install reports back.
Spending money, sending mail, touching a repo — the actions you mark wait for your yes on Telegram, or whatever channel you already read.
What ran, what it read, where it called, what it cost. One timeline you can scroll at 2am, and export when somebody asks you to prove it.
03 — THE CAVEATS
You are going to run this on the machine that holds your life. You deserve the caveats before the pitch, not in a changelog eight months in.
Nobody's product does. Cinctus assumes the agent will eventually be talked into something stupid and makes that survivable.
Inside the permissions you granted, an agent can still do a bad job. That is your call to make, not ours.
Nothing runs in our cloud. If your box is down, Cinctus is down, and that is the trade you came here for.
This is a waitlist, not a download. First build lands [LAUNCH WINDOW] — and if it slips, you get the email that says so.
04 — PRICING
The line does not move. Everything one human needs to secure their own agents is free forever and stays in the open-source core — not a trial, not a seat count that shrinks next year.
Open source. Fork it if we let you down.
Everything in Core, still on your box.
Priced per managed agent. Card, not a sales call.
We are building this in the open, alone, fast. The waitlist is how we decide whether to keep going — and it is where the first install instructions land.
Stored on our own box in Germany. Unsubscribe link in every mail. Never sold, never shared.