This product was not featured by Product Hunt yet. It will not be visible on their landing page and won't be ranked (cannot win product of the day regardless of upvotes).
TenantGuard
Open source scanner for cross-tenant AI-agent security bugs
TenantGuard is a purpose-built CLI and MCP server for securing multi-tenant AI-agent deployments. While broad governance tools and general IaC scanners miss agent-specific isolation defects, TenantGuard goes deep. Using 16 fail-closed OPA/Rego rules mapped to real-world vulnerabilities, it instantly catches unscoped sandbox mounts, cross-tenant cron bindings, SSRF tool URLs, and exec credential leaks. It outputs in SARIF, JSON, and MCP and is licensed with Apache-2.0.
As we started deploying self-hosted, multi-tenant AI agents, we realized standard IaC scanners and broad AI governance platforms were missing critical vulnerabilities. General tools simply weren't designed to catch the nuanced, agent-specific isolation defects that can lead to catastrophic cross-tenant data breaches.
Initially, we tried adapting existing security scanners, but the approach was too broad. We realized we needed to go deep on a single, critical failure class: tenant isolation. That’s what inspired TenantGuard. We evolved our approach to focus exclusively on real-world exploits, mapping our policies directly to confirmed vulnerabilities rather than theoretical risks.
TenantGuard is an open-source (Apache-2.0) CLI and MCP server built specifically to audit multi-tenant AI-agent deployments. Powered by 16 fail-closed OPA/Rego rules, it instantly detects:
- Unscoped sandbox mounts
- Cross-tenant cron bindings
- SSRF-exposed tool URLs
- Credential leakage via exec tools
It natively outputs to SARIF, JSON, and MCP, so it drops seamlessly into your existing CI/CD pipelines.
Repo: https://github.com/RudrenduPaul/...
MCP Servers:
https://mcpservers.org/servers/r...https://glama.ai/mcp/servers/Rud...
PyPI: https://pypi.org/project/tenantg...
NPM: https://www.npmjs.com/package/te...
We built this for the community and would love your thoughts.
What is the biggest security hurdle you’ve faced when deploying AI agents in production?
No comment highlights available yet. Please check back later!
About TenantGuard on Product Hunt
“Open source scanner for cross-tenant AI-agent security bugs”
TenantGuard was submitted on Product Hunt and earned 0 upvotes and 1 comments, placing #58 on the daily leaderboard. TenantGuard is a purpose-built CLI and MCP server for securing multi-tenant AI-agent deployments. While broad governance tools and general IaC scanners miss agent-specific isolation defects, TenantGuard goes deep. Using 16 fail-closed OPA/Rego rules mapped to real-world vulnerabilities, it instantly catches unscoped sandbox mounts, cross-tenant cron bindings, SSRF tool URLs, and exec credential leaks. It outputs in SARIF, JSON, and MCP and is licensed with Apache-2.0.
TenantGuard was featured in Open Source (68.8k followers), Developer Tools (518.4k followers), GitHub (41.4k followers) and Security (2.9k followers) on Product Hunt. Together, these topics include over 130.4k products, making this a competitive space to launch in.
Who hunted TenantGuard?
TenantGuard was hunted by Sourav Nandy. A “hunter” on Product Hunt is the community member who submits a product to the platform — uploading the images, the link, and tagging the makers behind it. Hunters typically write the first comment explaining why a product is worth attention, and their followers are notified the moment they post. Around 79% of featured launches on Product Hunt are self-hunted by their makers, but a well-known hunter still acts as a signal of quality to the rest of the community. See the full all-time top hunters leaderboard to discover who is shaping the Product Hunt ecosystem.
Want to see how TenantGuard stacked up against nearby launches in real time? Check out the live launch dashboard for upvote speed charts, proximity comparisons, and more analytics.