archestra-ai/OpenAPPA
Deterministic policy engine that enforces data-flow guardrails between AI agents and their tools.

OpenAPPA is a Rust-based guardrail system that sits between an agent and its tools, checking every tool call against declarative TOML policies before execution. It tracks the sensitivity and trust of data an agent reads and ensures sensitive information does not reach unauthorized destinations. The engine makes decisions deterministically from an event log without network or file calls, and can run in-process or as a sidecar. It is designed to provide security guarantees for agentic systems without blocking valid work.
Frequently asked
- What is archestra-ai/OpenAPPA?
- Deterministic policy engine that enforces data-flow guardrails between AI agents and their tools.
- Is OpenAPPA open source?
- Yes — archestra-ai/OpenAPPA is open source, released under the MIT license.
- What language is OpenAPPA written in?
- archestra-ai/OpenAPPA is primarily written in Rust.
- How popular is OpenAPPA?
- archestra-ai/OpenAPPA has 1.2k stars on GitHub.
- Where can I find OpenAPPA?
- archestra-ai/OpenAPPA is on GitHub at https://github.com/archestra-ai/OpenAPPA.