Skip to main content

SASY policy enforcement runtime for Claude Code (engine + daemon + native hook)

Project description

sasy-guard

The SASY policy-enforcement runtime for Claude Code, distributed as a platform-specific wheel. uv tool install sasy-guard puts the prebuilt binaries on your machine — no need to clone the SASY repo or install a build toolchain.

This is the runtime (the binaries you run), distinct from the sasy package, which is the pure-Python SDK (a client library you import).

What's inside

The wheel for your OS/arch vendors three binaries:

  • sasy — the (restricted) policy engine
  • sasy-watch — the enforcement daemon: reconstructs the message-dependency graph from Claude Code's transcript and runs the policy check
  • sasy-hook — the native, fail-closed PreToolUse hook (~2 ms)

plus the policy profiles and the SessionStart/PostToolUse/SessionEnd scripts.

Install & enable

uv tool install sasy-guard                          # 1. the runtime (binaries vendored)
sasy-guard install                                  # 2. binaries → ~/.sasy/bin + policy config
claude plugin marketplace add sasy-labs/sasy-demo   # 3. add the marketplace
claude plugin install sasy-guard                    #    install the hooks (standard way)

Then run claude — every tool call is checked against the security policy; denials surface a [SASY] … reason the agent relays.

  • Select rule groups: sasy-guard install --rule-off a,b (drop) / --rule-on a,b (opt-in).
  • Inspect the install: sasy-guard doctor.
  • No-marketplace alternative: sasy-guard enable [project] writes the hooks straight into <project>/.claude/settings.json instead.

Building (maintainers)

Wheels are built per platform by CI and assembled with build-wheel.sh, which injects the binaries, syncs the profiles/scripts from plugins/sasy-guard, and retags the wheel for the current platform. See make sasy-guard-wheel and make sasy-guard-publish.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distributions

No source distribution files available for this release.See tutorial on generating distribution archives.

Built Distributions

If you're not sure about the file name format, learn more about wheel file names.

sasy_guard-0.2.0-py3-none-manylinux_2_35_x86_64.whl (44.5 MB view details)

Uploaded Python 3manylinux: glibc 2.35+ x86-64

sasy_guard-0.2.0-py3-none-manylinux_2_35_aarch64.whl (43.6 MB view details)

Uploaded Python 3manylinux: glibc 2.35+ ARM64

sasy_guard-0.2.0-py3-none-macosx_11_0_x86_64.whl (31.7 MB view details)

Uploaded Python 3macOS 11.0+ x86-64

sasy_guard-0.2.0-py3-none-macosx_11_0_arm64.whl (28.6 MB view details)

Uploaded Python 3macOS 11.0+ ARM64

File details

Details for the file sasy_guard-0.2.0-py3-none-manylinux_2_35_x86_64.whl.

File metadata

File hashes

Hashes for sasy_guard-0.2.0-py3-none-manylinux_2_35_x86_64.whl
Algorithm Hash digest
SHA256 bdef2b9814d0d421d645531df3862258406c70036c92a54bf9c8f57272119bc1
MD5 455bb685107e39dafc319d74247f7e94
BLAKE2b-256 17ae157f6cfa3512d490d0ef0c2be86fc5c7199f5b02f85d11b4c76fa09268b1

See more details on using hashes here.

File details

Details for the file sasy_guard-0.2.0-py3-none-manylinux_2_35_aarch64.whl.

File metadata

File hashes

Hashes for sasy_guard-0.2.0-py3-none-manylinux_2_35_aarch64.whl
Algorithm Hash digest
SHA256 18844ccdd10b512f3f747f573a9efd28dfee1f3bacaeea4d3df6b37118159aa2
MD5 8654bb31d49fe4aa34f8b4da9975cb3f
BLAKE2b-256 a69bd45e3e15b8ae37f216e7ba4bd29666dc86c213f604f21c77bc6b86a73d53

See more details on using hashes here.

File details

Details for the file sasy_guard-0.2.0-py3-none-macosx_11_0_x86_64.whl.

File metadata

File hashes

Hashes for sasy_guard-0.2.0-py3-none-macosx_11_0_x86_64.whl
Algorithm Hash digest
SHA256 ecf93b51c64e9f49c06d9ac44592391443a4b4cffb5bac90104260fa9693b14f
MD5 8d583ed957050106bd930f7f58ea4a43
BLAKE2b-256 8ec1aca669d4f20cb8ef8c1e0f29a4bde4772a79c15d9a0c5aee900b07b93cf8

See more details on using hashes here.

File details

Details for the file sasy_guard-0.2.0-py3-none-macosx_11_0_arm64.whl.

File metadata

File hashes

Hashes for sasy_guard-0.2.0-py3-none-macosx_11_0_arm64.whl
Algorithm Hash digest
SHA256 9235c70d8f487f25f0c1d93537a96639c48215479dbac4b4251886baef12a44b
MD5 2e2ee727ca2b9448ff812210d9dcd30e
BLAKE2b-256 8d5c0612e923f0ee48582d36f522466147834da315a7fdebbf0420cebd12c293

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page