Developers

Free, open source, local first, and it governs the agent tools you already use.


You write the law. Consequential actions escalate to a human before they happen. Agents can appeal, and the appeal is recorded. Nothing runs on our servers.

# Rust

cargo add web4-core@0.3

# Python

pip install web4-core==0.3

# v0.4.0 is in source; 0.3.0 is what crates.io and PyPI serve, since 2026-07-10.

Hestia exposes 31 MCP tools to agents as of 2026-08-27, most of them the governance surface rather than convenience wrappers. An agent calls begin_action and query_policy before it touches a tool, and the decision either way lands on the witness chain.

Scoped, revocable delegations from you to each agent, so authority stays with the person.

A policy gate that runs before the tool call, not a log you read afterwards.

A hash-chained witness record of every action and every policy decision, with the signer's identity on every row.

An appeal path with a cross-vendor arbiter, and the ruling on the record.

Licence

AGPL-3.0

The patent grant is royalty-free for non-commercial, research and AGPL-compliant open-source use. Commercial licensing is separate.

Source

Public implementations

github.com/dp-web4 holds the working code. Start with web4, hestia, web4-trust-core and SAGE so you land somewhere legible.

Repository text moves faster than this page. Whatever a repository says on the day you click is what it says.

Apps

Android APK today

The Hestia desktop app is source today. The public app artifact is an Android APK. We do not offer a desktop bundle.

Why this and not a log

Refusals are a rate, not an anecdote.


1,827 refusals in 46 days

On one machine, 1.65% of 110,401 governed acts. Treat it as a floor: scope denials on that seat never reach the chain, so recorded refusals undercount actual refusals by an unmeasured amount.

It refuses us

The agents building this cannot edit the gate, the hooks or their own configuration without a human-approved escalation. An interpreter bypass was caught and reverted under approval on 2026-08-27.

30+ open self-filed issues

As of 2026-08-27. The defect list is public inside the system, and the appeals that went against us are on the record with their caveats.

Three vendors, one law

Agents built on Anthropic, OpenAI and Moonshot models are gated identically. At the 2026-08-25 meter, 67.5% of law-bearing code was still per-seat; CI ratchets that down and the first collapse slice landed.

The part that follows you to work

The proof travels with the person, not the vendor.

A developer who already governs their own agents arrives at work able to answer the security question with an artifact instead of an assurance.