Support matrix

Which AI coding agents and DefenseClaw features work on Linux, macOS and Windows, in the open-source and enterprise editions, and what live tests verified for DefenseClaw 1.0.

This page answers three questions: does DefenseClaw protect my agent on my operating system, which features come with each edition, and how the enterprise edition attaches to each agent. Every Supported cell was verified by a live test in this release. Everything else is labeled.

Supported
Verified by live tests in this release
Preview
In the code, not verified live in this release
Not supported
The code refuses it on that OS or edition
Not offered
Not part of that edition
  • Open source is the per-user install: one command, and each user runs their own DefenseClaw. Start with the Download page.
  • Enterprise is the managed standalone profile an administrator deploys with a package or an MDM. Users can't turn it off. Start with Deploy to a fleet. The Secure Client profile is covered in Secure Client managed deployment.

Agents

Supported means a live test on that OS verified the agent's hooks and a block before the tool call ran. A cell says so when the agent's telemetry to Grafana and Galileo wasn't verified there. Switch to Enterprise for the managed edition. Select an agent for its setup page.

AI coding agents by operating system, open-source edition
AgentLinuxx86_64, arm64macOSApple siliconWindowsx64Min versionlowest tested
Claude CodeNative hooks
Supported
Supported
Supported
2.1.154
CodexNative hooks
Supported
Supported
Supported
0.124.0
GitHub Copilot CLINative hooks
Supported
Supported
Supported
1.0.18
CursorNative hooks
Supported
Supported
Supported
2.4.0
DevinNative hooks
Supported
Supported
Supported
3000.4.25
AntigravityNative hooks
Supported
Supported
Supported
1.1.8
KiroNative hooks
Supported
Supported
Supported
Not gated
OpenCodePlugin
Supported
Supported
Supported
1.18.10
AmpPolicy plugin
Supported
Supported
Supported
0.0.1785334225
HermesNative hooks
Supported
Supported
Supported
0.19.0
OpenHandsNative hooks
Supported
Supported
Not supported
1.12.0
OmniGentPolicy API
Supported
Supported
PreviewTelemetry: preview
0.7.0
Version and platform notes
Claude Code
Windows: Native executable hooks. WSL is outside the native contract.
Codex
Windows: System PowerShell bridge to the packaged hook executable.
GitHub Copilot CLI
Windows: Uses Copilot CLI's PowerShell hook field.
Cursor
Cursor Agent 2.4.0 up to 4.0.0, and Agent build 2026.07.23-e383d2b. Windows: Managed PowerShell adapter.
Devin
Reviewed Devin CLI 3000.4.25 on every OS and 3000.11.3 on Linux; newer builds run as untested newer versions. Windows: Devin's own hook runner starts the protected hook executable directly; no PowerShell bridge.
Antigravity
Windows: Packaged PowerShell hook launcher.
Kiro
Per-user installs are not version-gated. The enterprise standalone profile requires kiro-cli 2.24.1 or Kiro IDE 1.0.182.
OpenCode
Contract covers 1.18.10 up to 1.19.0; newer versions run as untested newer versions.
Amp
Windows: Owner-only TypeScript plugin in the user plugin directory.
Hermes
Contract covers 0.19.0 up to 0.22.0. Windows: Hermes' own terminal tool needs its bundled Git Bash.
OpenHands
Windows: OpenHands CLI needs WSL, and DefenseClaw has no WSL connector path.
OmniGent
Contract covers 0.7.0 up to 0.14.0. Windows: Degraded mode: server and SDK policy path only, without terminal wrappers or sandbox parity.

The connector contract behind each row (block events, native ask, fail closed, sandbox tier) is on the capability matrix. Exact version ranges are on Compatibility.

Features

DefenseClaw features by edition and operating system
FeatureOpen sourceEnterprise
LinuxmacOSWindowsLinuxmacOSWindows
Protect
Guardrails: observe, action, blockSupportedSupportedSupportedSupportedSupportedSupported
Policy and rule packsSupportedSupportedSupportedSupportedSupportedSupported
CodeGuardEnterprise: part of the local policy engine in the standalone profile.SupportedSupportedSupportedPreviewPreviewPreview
Skill scannerSupportedSupportedPreviewSupportedSupportedPreview
MCP scannerSupportedPreviewSupportedSupportedSupportedPreview
LLM judgeSupportedSupportedPreviewPreviewPreviewPreview
Redaction profilesSupportedSupportedPreviewNot offeredNot offeredNot offered
OpenShell sandboxesLinux and macOS only. Managed installs don’t start the sandbox runtime yet.PreviewPreviewNo: Not supportedNo: Not supportedNo: Not supportedNo: Not supported
ACP guard (Kiro, Zed)PreviewSupportedPreviewPreviewPreviewPreview
Discover
AI discoverySupportedSupportedSupportedSupportedSupportedPreview
Runtime discoverySupportedSupportedSupportedSupportedSupportedPreview
Tool inventorySupportedSupportedSupportedNot offeredNot offeredNot offered
Plugin inventory and scanPreviewSupportedSupportedNot offeredNot offeredNot offered
RegistriesPreviewSupportedSupportedNot offeredNot offeredNot offered
AIBOMSupportedPreviewPreviewNot offeredNot offeredNot offered
Observe
OpenTelemetry export (Grafana)SupportedSupportedSupportedSupportedSupportedSupported
GalileoSupportedSupportedSupportedSupportedSupportedSupported
SplunkNeeds a Splunk Observability Cloud organization, and Terraform for the dashboards.PreviewPreviewPreviewPreviewPreviewPreview
Local observability stackNeeds Docker.SupportedSupportedPreviewNot offeredNot offeredNot offered
AlertsSupportedSupportedSupportedNot offeredNot offeredNot offered
WebhooksSupportedSupportedSupportedPreviewPreviewPreview
Audit log and exportSupportedSupportedPreviewPreviewPreviewPreview
Operate
InstallOpen source: the one-line installer. Enterprise: the .rpm, .pkg or Setup.exe package.SupportedSupportedSupportedSupportedSupportedSupported
UpgradeSupportedSupportedSupportedSupportedSupportedSupported
UninstallSupportedSupportedSupportedSupportedSupportedSupported
Health check and repairOpen source: doctor. Enterprise: verify and repair.SupportedSupportedSupportedSupportedSupportedSupported
Keys and secretsEnterprise: the Cisco AI Defense key is a protected credential only the gateway service can read.SupportedSupportedSupportedPreviewPreviewPreview
Terminal UISupportedSupportedSupportedNot offeredNot offeredNot offered
macOS menu-bar appNot offeredPreviewNot offeredNot offeredNot offeredNot offered
Enterprise controls
Machine policy for agent hooksNot offeredNot offeredNot offeredSupportedSupportedSupported
Tamper resistanceStandard users can’t turn DefenseClaw or its hooks off.Not offeredNot offeredNot offeredSupportedSupportedSupported
Multi-user enroll and revokeNot offeredNot offeredNot offeredSupportedSupportedSupported
Foreign-hook guardNot offeredNot offeredNot offeredSupportedSupportedPreview
MDM deploymentIntune, Jamf, Iru (formerly Kandji), Workspace ONE, ConfigMgr and Linux configuration management. Verified by simulating the MDM run context; the recipes have not been run in a live MDM tenant.Not offeredNot offeredNot offeredSupportedSupportedSupported

Protect

  • Guardrails: observe, action, block
    Open source
    LinuxSupportedmacOSSupportedWindowsSupported
    Enterprise
    LinuxSupportedmacOSSupportedWindowsSupported
  • Policy and rule packs
    Open source
    LinuxSupportedmacOSSupportedWindowsSupported
    Enterprise
    LinuxSupportedmacOSSupportedWindowsSupported
  • CodeGuardEnterprise: part of the local policy engine in the standalone profile.
    Open source
    LinuxSupportedmacOSSupportedWindowsSupported
    Enterprise
    LinuxPreviewmacOSPreviewWindowsPreview
  • Skill scanner
    Open source
    LinuxSupportedmacOSSupportedWindowsPreview
    Enterprise
    LinuxSupportedmacOSSupportedWindowsPreview
  • MCP scanner
    Open source
    LinuxSupportedmacOSPreviewWindowsSupported
    Enterprise
    LinuxSupportedmacOSSupportedWindowsPreview
  • LLM judge
    Open source
    LinuxSupportedmacOSSupportedWindowsPreview
    Enterprise
    LinuxPreviewmacOSPreviewWindowsPreview
  • Redaction profiles
    Open source
    LinuxSupportedmacOSSupportedWindowsPreview
    Enterprise
    LinuxNot offeredmacOSNot offeredWindowsNot offered
  • OpenShell sandboxesLinux and macOS only. Managed installs don’t start the sandbox runtime yet.
    Open source
    LinuxPreviewmacOSPreviewWindowsNo: Not supported
    Enterprise
    LinuxNo: Not supportedmacOSNo: Not supportedWindowsNo: Not supported
  • ACP guard (Kiro, Zed)
    Open source
    LinuxPreviewmacOSSupportedWindowsPreview
    Enterprise
    LinuxPreviewmacOSPreviewWindowsPreview

Discover

  • AI discovery
    Open source
    LinuxSupportedmacOSSupportedWindowsSupported
    Enterprise
    LinuxSupportedmacOSSupportedWindowsPreview
  • Runtime discovery
    Open source
    LinuxSupportedmacOSSupportedWindowsSupported
    Enterprise
    LinuxSupportedmacOSSupportedWindowsPreview
  • Tool inventory
    Open source
    LinuxSupportedmacOSSupportedWindowsSupported
    Enterprise
    LinuxNot offeredmacOSNot offeredWindowsNot offered
  • Plugin inventory and scan
    Open source
    LinuxPreviewmacOSSupportedWindowsSupported
    Enterprise
    LinuxNot offeredmacOSNot offeredWindowsNot offered
  • Registries
    Open source
    LinuxPreviewmacOSSupportedWindowsSupported
    Enterprise
    LinuxNot offeredmacOSNot offeredWindowsNot offered
  • AIBOM
    Open source
    LinuxSupportedmacOSPreviewWindowsPreview
    Enterprise
    LinuxNot offeredmacOSNot offeredWindowsNot offered

Observe

  • OpenTelemetry export (Grafana)
    Open source
    LinuxSupportedmacOSSupportedWindowsSupported
    Enterprise
    LinuxSupportedmacOSSupportedWindowsSupported
  • Galileo
    Open source
    LinuxSupportedmacOSSupportedWindowsSupported
    Enterprise
    LinuxSupportedmacOSSupportedWindowsSupported
  • SplunkNeeds a Splunk Observability Cloud organization, and Terraform for the dashboards.
    Open source
    LinuxPreviewmacOSPreviewWindowsPreview
    Enterprise
    LinuxPreviewmacOSPreviewWindowsPreview
  • Local observability stackNeeds Docker.
    Open source
    LinuxSupportedmacOSSupportedWindowsPreview
    Enterprise
    LinuxNot offeredmacOSNot offeredWindowsNot offered
  • Alerts
    Open source
    LinuxSupportedmacOSSupportedWindowsSupported
    Enterprise
    LinuxNot offeredmacOSNot offeredWindowsNot offered
  • Webhooks
    Open source
    LinuxSupportedmacOSSupportedWindowsSupported
    Enterprise
    LinuxPreviewmacOSPreviewWindowsPreview
  • Audit log and export
    Open source
    LinuxSupportedmacOSSupportedWindowsPreview
    Enterprise
    LinuxPreviewmacOSPreviewWindowsPreview

Operate

  • InstallOpen source: the one-line installer. Enterprise: the .rpm, .pkg or Setup.exe package.
    Open source
    LinuxSupportedmacOSSupportedWindowsSupported
    Enterprise
    LinuxSupportedmacOSSupportedWindowsSupported
  • Upgrade
    Open source
    LinuxSupportedmacOSSupportedWindowsSupported
    Enterprise
    LinuxSupportedmacOSSupportedWindowsSupported
  • Uninstall
    Open source
    LinuxSupportedmacOSSupportedWindowsSupported
    Enterprise
    LinuxSupportedmacOSSupportedWindowsSupported
  • Health check and repairOpen source: doctor. Enterprise: verify and repair.
    Open source
    LinuxSupportedmacOSSupportedWindowsSupported
    Enterprise
    LinuxSupportedmacOSSupportedWindowsSupported
  • Keys and secretsEnterprise: the Cisco AI Defense key is a protected credential only the gateway service can read.
    Open source
    LinuxSupportedmacOSSupportedWindowsSupported
    Enterprise
    LinuxPreviewmacOSPreviewWindowsPreview
  • Terminal UI
    Open source
    LinuxSupportedmacOSSupportedWindowsSupported
    Enterprise
    LinuxNot offeredmacOSNot offeredWindowsNot offered
  • macOS menu-bar app
    Open source
    LinuxNot offeredmacOSPreviewWindowsNot offered
    Enterprise
    LinuxNot offeredmacOSNot offeredWindowsNot offered

Enterprise controls

  • Machine policy for agent hooks
    Open source
    LinuxNot offeredmacOSNot offeredWindowsNot offered
    Enterprise
    LinuxSupportedmacOSSupportedWindowsSupported
  • Tamper resistanceStandard users can’t turn DefenseClaw or its hooks off.
    Open source
    LinuxNot offeredmacOSNot offeredWindowsNot offered
    Enterprise
    LinuxSupportedmacOSSupportedWindowsSupported
  • Multi-user enroll and revoke
    Open source
    LinuxNot offeredmacOSNot offeredWindowsNot offered
    Enterprise
    LinuxSupportedmacOSSupportedWindowsSupported
  • Foreign-hook guard
    Open source
    LinuxNot offeredmacOSNot offeredWindowsNot offered
    Enterprise
    LinuxSupportedmacOSSupportedWindowsPreview
  • MDM deploymentIntune, Jamf, Iru (formerly Kandji), Workspace ONE, ConfigMgr and Linux configuration management. Verified by simulating the MDM run context; the recipes have not been run in a live MDM tenant.
    Open source
    LinuxNot offeredmacOSNot offeredWindowsNot offered
    Enterprise
    LinuxSupportedmacOSSupportedWindowsSupported

Not offered in the enterprise columns means the feature is a per-user command. The enterprise packages don't install the per-user defenseclaw CLI, and a managed computer refuses per-user commands. The administrator configures the managed gateway through its config instead.

Enterprise

In the enterprise edition DefenseClaw attaches to each agent in one of two ways:

  • Machine policy. DefenseClaw's hooks sit in the agent vendor's administrator-owned policy files, which apply to every user of the computer. See Machine policy.
  • Per-user. The guardian writes DefenseClaw's hook or plugin into each enrolled user's own agent config and repairs it if it changes. See Enrollment.
AI coding agents by operating system, enterprise edition, with the route DefenseClaw uses
AgentLinux.rpmmacOS.pkgWindowsSetup.exe
Claude CodeNative hooks
SupportedMachine policy
SupportedMachine policy
SupportedMachine policy
CodexNative hooks
SupportedMachine policy
SupportedMachine policy
SupportedMachine policy
GitHub Copilot CLINative hooks
SupportedMachine policy
SupportedMachine policy
SupportedMachine policy
CursorNative hooks
SupportedMachine policy
PreviewMachine policy
SupportedMachine policy
DevinNative hooks
SupportedPer-user
SupportedPer-user
SupportedPer-user
AntigravityNative hooks
SupportedPer-user
SupportedPer-user
SupportedPer-user
KiroNative hooks
PreviewPer-user
PreviewPer-user
SupportedPer-user
OpenCodePlugin
SupportedMachine policy
SupportedMachine policy
SupportedMachine policy
AmpPolicy plugin
SupportedPer-user
SupportedPer-user
SupportedPer-user
HermesNative hooks
SupportedPer-user
SupportedPer-user
SupportedPer-user
OpenHandsNative hooks
SupportedPer-user
SupportedPer-user
Not supported
OmniGentPolicy API
PreviewPer-user
PreviewPer-user
Not supported
Route notes
Kiro
Editors that start Kiro over ACP can also use the ACP guard.
OpenCode
Machine policy through the managed OpenCode plugin that the standalone package installs; per-user when that plugin is missing.

Platforms

Platforms and where each edition was verified
OSArchitecturesOpen source verified onEnterprise verified on
Linuxx86_64, arm64RHELRHEL (.rpm). The .deb is built but not certified in this release
macOSApple siliconmacOS on Apple siliconmacOS on Apple silicon (.pkg)
Windowsx64Windows x64Windows x64 (Setup.exe)

Intel Macs aren't supported, and Windows is x64 only. The full requirements are on Install and, for the enterprise packages, under Requirements on the Windows, Linux and macOS pages.

Agents that connect through the guardrail proxy aren't part of this matrix. Their pages are listed under Connectors.