Skip to content

Pi Fortress

Early access

Pi Fortress works and is tested on a Raspberry Pi 5 and in a VM lab. The code is in review. It will be open source under Apache-2.0 at the public release.

A small box between your AI agent and the internet. With it, the agent never holds your real API keys.

AI coding agents need API keys to work. A malicious prompt, a bad skill or an MCP server can trick an agent. A tricked agent can send those keys anywhere. Pi Fortress removes the keys from the agent machine and fences them at the network. The agent sees only fake placeholder keys. The gateway puts in the real key only when the request goes to a service that the key belongs to.

It runs on a Raspberry Pi 5, or on a small VM next to the VM of the agent. The agent cannot disable it, because it does not run on the agent machine.

How is it different from a proxy, a vault or a sandbox? Refer to the comparison.

Why it exists

AI agents hold keys, and attackers hunt them. Flaws, VM escapes included, are found faster every year.

CVEs published per year

  • 2019: 17.3 thousand
  • 2020: 18.3 thousand
  • 2021: 20.1 thousand
  • 2022: 25.1 thousand
  • 2023: 28.8 thousand
  • 2024: 40.0 thousand
  • 2025: 48.2 thousand

Secrets leaked on public GitHub

  • 2022: 10.0 million
  • 2023: 12.8 million
  • 2024: 23.8 million
  • 2025: 29.0 million
When Incident
Mar 2025 VMware ESXi: three zero-days that escape a VM to the hypervisor, used in real attacks
Aug 2025 s1ngularity: npm malware told AI coding tools to search for keys. 2,349 secrets leaked
Nov 2025 Shai-Hulud 2.0: npm worm. About 400,000 secrets exposed
Apr 2026 Claude Mythos Preview: found and exploited zero-days in every major OS and browser, and a guest-to-host flaw in a production hypervisor
Sep 2026 Mandiant: a hijacked AI coding session stole GitHub tokens. About 100 repositories infected
Sep 2026 Google: an AI attack framework took thousands of credentials in less than six hours

Pi Fortress assumes that the agent can escape its VM. Thus the keys are on a separate box. Sources

How it works

  1. The agent sends a placeholder. It never holds the real key.
  2. For the service that owns the key, Pi Fortress puts in the real key.
  3. A hijacked agent sends the placeholder to a different server.
  4. Pi Fortress refuses the request and alerts you.

All requests from the agent go through Pi Fortress. The agent has no proxy setting to bypass.

  • To the right service: Pi Fortress replaces the placeholder with the real key, only in a credential header. A credential header is Authorization, X-Api-Key, or a header that you declare for that service. If the placeholder is in a different location, Pi Fortress refuses the request.
  • To anywhere else: Pi Fortress never replaces the placeholder. It strips a live key in a format that the gateway knows (Anthropic, OpenAI, GitHub, AWS, GitLab, npm and more). It strips the key from header values, the URL and the body.
  • To a known-malicious site: Pi Fortress drops the connection.

One request, step by step

sequenceDiagram
    participant A as AI agent
    participant P as Pi Fortress
    participant S as api.anthropic.com
    A->>P: Authorization: Bearer pf_…_CLAUDE_OAT (placeholder)
    P->>P: Is this site allowed this kind of key?
    P->>S: Authorization: Bearer sk-ant-oat01-… (real key)
    S-->>P: Response
    P-->>A: Response, with any real key turned back into its placeholder

If the check fails, the agent gets one plain refusal. The refusal does not give the cause. The owner gets an alert.

Where it sits in your network

flowchart TB
    Internet(("Internet")) --- Router["Your router"]
    Router --- Pi["Pi Fortress<br/>(Raspberry Pi 5)"]
    Pi ---|"one cable, two VLANs"| Desktop
    subgraph Desktop["Your desktop"]
        AgentNet["Agent VMs<br/>agent segment, full credential fence"]
        Desk["Desktop host<br/>desk segment, DNS and blocklist, optional credential fence"]
    end
    Pi --- HomeNet["Home network (optional)<br/>phones, laptops, TV"]
    classDef pf fill:#3b82f6,stroke:#93c5fd,stroke-width:3px,font-weight:bold
    classDef agent fill:#8b5cf6,stroke:#c4b5fd,stroke-width:2px
    class Pi pf
    class AgentNet agent

Your desktop and its agent VMs use one cable to the Pi. The Pi is the only uplink of the desktop. Pi Fortress assumes that an agent can escape its VM. Thus the desktop also gets DNS filtering and the blocklist.

The same box can also filter your home network. It blocks known-bad sites for phones and laptops.

What you get

Keys stay off the agent The agent holds placeholders. A stolen placeholder is useless anywhere else.
Keys go only where they belong A Claude key reaches only Claude. A GitHub token reaches only GitHub.
Known key formats stripped If a live key in a recognised format goes to the wrong place, Pi Fortress removes it before it leaves.
Bad sites blocked A blocklist of known-malicious sites. Also a log of each new site, for you to review.
No proxy setting on the agent Pi Fortress intercepts traffic at the network. Thus there is no proxy variable to unset.

By default, the agent can reach all sites except known-bad sites. You can leave Pi Fortress on all day.

Lock it down

Enable paranoid mode. Then the agent can connect only to the sites on your allowlist, and a key can go only to those sites. The risk model, with each attack that we tested and its result, is published with the source.

Who it is for

It is for all persons who run a coding agent, a skill or an MCP server with a real credential:

  • Solo developers.
  • Small teams that share one gateway.
  • Families who want the same filtering for their devices.

Refer to Use cases.

Where to go next

Page What it covers
Why it exists Recent incidents and numbers, and how Pi Fortress answers them
Getting started The ways to run it, what you need, and your first ten minutes
Pi 5 setup Hardware, uplink, the agent network, more agents, extra networks
Home network Filter phones, laptops and TVs behind the Pi, and its settings
Public Wi-Fi Keep the Pi safe when its uplink is Wi-Fi you do not control
Architecture How a request flows, where keys live, each layer of protection
Use cases Solo developer, small team, untrusted skills, family network, red-team lab
Comparison How it compares with proxies, vaults and sandboxes
FAQ Short answers: what breaks, revoking keys, new providers, performance
Tutorials The networking ideas behind it, explained from scratch