
Arcjet announces Arcjet Runtime Security for Coding Agents
Security teams can discover coding agents, enforce consistent policies across developer tools, and preserve a complete record of agent activity
SAN FRANCISCO, Oct. 8, 2026 /PRNewswire/ -- Arcjet, the runtime security platform for AI agents, today introduced Arcjet Runtime Security for Coding Agents, extending its Agent Runtime Security platform to the coding tools developers use. Security teams can observe agents across developer endpoints, apply consistent policies, and review actions and policy decisions.
Arcjet launched Agent Runtime Security to help engineering teams secure the custom AI agents they are building while giving security teams the governance and compliance evidence they need. Developers can integrate Arcjet directly into applications through native JavaScript, Python, and Go SDKs, as well as integrations with AI frameworks including Eve and LangChain. Arcjet is now extending those same security controls to coding agents including Claude Code, OpenAI Codex, Cursor, Muse Code, GitHub Copilot, and other tools developers use to write and ship software.
Developer endpoints are unusual in the level of access they have, often able to connect to sensitive databases and environments. That extends to coding agents, which can access source code, credentials, external APIs, MCP servers, and other systems developers rely on every day. As developers adopt different coding agents across an organization, security teams need a consistent way to understand which agents are running and control what they can access without requiring engineering teams to standardize on a single tool or model.
"Coding agents are now an essential part of how developers build software, but the speed of deployment is outpacing the ability to manage them securely," said David Mytton, CEO and founder of Arcjet. "Security teams need agent-native security tooling to allow developers to safely pick the tools they want to use, mitigating risks such as prompt injection, PII leaks, malware, and malicious MCPs and APIs."
Observe coding agents across developer endpoints
Arcjet gives security and IT teams visibility into the coding agents running across developer endpoints, providing a common view even when developers and engineering teams use different tools.
Because Arcjet is LLM and coding agent agnostic, security teams can manage a single policy engine across Claude Code, Codex, Cursor, Muse Code, Copilot, and other coding agents. Security teams can see which agents are operating and capture their activity without requiring developers to change the models or tools they use.
Enforce security policies across every coding agent
Arcjet policies can detect prompt injection and PII exposure, block calls to risky API and MCP destinations, and stop risky activity when a session shows signs of credential exfiltration.
Arcjet policies are powered by Open Policy Agent and Rego and integrate directly into coding agent hooks. This allows security teams to enforce deterministic policies at runtime through the native integrations, with an optional endpoint agent available for discovering unmanaged coding agents.
A policy applies the same way regardless of which coding agent or underlying LLM a developer chooses, and security teams can update it centrally as requirements change instead of maintaining separate controls for each tool.
Arcjet can be rolled out in minutes through AI provider managed settings or existing device management systems, allowing security and IT teams to extend policies across developer environments using infrastructure they already manage.
Audit every agent action with full context
Arcjet records each action with the agent, user, prompt or tool call, policies that ran, and resulting decision.
Teams can pipe this activity into existing SIEM platforms including Splunk, Datadog, SentinelOne, and Panther, allowing security teams to investigate coding agent activity through the same systems they already use for security monitoring, incident response, and compliance.
Together, Arcjet's Agent Runtime Security gives engineering, security, IT, and platform teams a common way to observe the agents running across custom applications and developer environments, enforce policies around their activity, and audit what happened.
About Arcjet
Arcjet is building the runtime security layer for AI applications and agents. It helps teams discover all the agents running in an organization, enforce policy across every action, prompt, and tool call, and keep the evidence to prove what happened. Detect prompt injection, authorize agent tool calls, redact PII, and block bots and abuse. Founded in 2023 by David Mytton, Arcjet is already deployed in 500+ production apps and backed by Plural, Ott Kaukver, Andreessen Horowitz, Seedcamp, and 20+ leading devtools and security angels. https://arcjet.com/
SOURCE Arcjet
Share this article