Command gating
Under enforcement, allowlists and blocked shell constructs restrict supported command execution. Review arguments and host permissions as well as the executable.
Explore this capabilitySecurity & Governance
A file can be accessible and still contain information your model should not receive. LeanCTX separates source access from content checks on supported tool results.
The approach
PathJail checks where a file read is allowed. Enabled text filters check what supported results may contain before delivery.
PathJail
PathJail validates the resolved file path against allowed roots. Traversal and symlinks must lead to a permitted destination.
Content inspection
Useful code and sensitive customer fields can sit in the same permitted source. Inspect supported text results with configured detectors and patterns before delivery. Reading locally to inspect content is different from sending that content to a model.
Response & evidence
Choose how each detector responds. Filter metadata reports categories and counts without sensitive matched values; audit detail depends on the event path.
contact: person@example.test
Warning: detected email
contact: [REDACTED:email]
[POLICY BLOCKED]
Content withheld
Example data. An active policy is required.
Organizational governance
Enterprise governance adds organization-level identity, source, provider and action policies. Apply them at the supported access and execution boundaries; an optimizer may propose a route but cannot grant permission.
In your workflow
A file boundary is one layer. Commands, credentials, network destinations and project configuration need their own decisions.
Under enforcement, allowlists and blocked shell constructs restrict supported command execution. Review arguments and host permissions as well as the executable.
Explore this capabilitySecret detection and redaction have their own configuration. They complement PII and classification filters; none replaces a review of what your integration actually returns.
Explore this capabilityProject configuration can request sensitive overrides. Review and trust that configuration explicitly before accepting broader behavior.
Explore this capabilityValidate supported network destinations and apply the deployment’s provider and processing policy. Direct calls outside that path require their own controls.
Explore this capabilityQuestions & answers
No. Enable the required filters and verify the actual integration path. Images, binary data and calls outside LeanCTX need their own controls. Keep host permissions and application safeguards in place.
No. The content-filter configuration defaults to off. Enable the required actions in your active policy and verify the supported result path. PathJail and other redaction controls have their own configuration.
No detector recognises every threat or sensitive value. The controls apply to supported calls, formats and enabled rules. Test them as part of your complete application security model.
Start with LeanCTX
Define your allowed sources, enable the relevant checks and verify a supported read against your policy.
Local-first. Model-agnostic. Your context.
Cookie settings
Your privacy. Your choice.
We use essential storage for site settings. With your permission, PostHog EU measures page visits to help us improve LeanCTX. No advertising or session recordings.
Essential
Theme, consent choice and account functionality.
Analytics
Optional page analytics · PostHog EU, Frankfurt. Off until you allow it.
Change your choice anytime in Cookie settings.