Why guardrails matter
Traditional security tools run after code is committed—by then, the vulnerability exists and requires remediation. Corridor’s guardrails shift security left by integrating directly into the AI code generation process:- Prevention over detection: Security context guides the AI to avoid vulnerable patterns
- Zero developer friction: No separate security review step—it happens during coding
- Reduced remediation costs: Fixing a vulnerability before it’s written costs nothing
How guardrails work
Guardrails operate through MCP and Hooks, which allow Corridor to participate in AI interactions:- Developer prompts AI: “Write a function to query the database”
- Corridor analyzes context: Project type, existing code patterns, security policies
- Security context provided: Guardrails inform the AI about relevant risks (e.g., SQL injection, parameterized queries)
- AI generates secure code: The response incorporates security best practices
- Activity logged: The interaction is recorded for audit and analytics
- During code generation: Guardrails provide additional context to AI models (via MCP) so the AI avoids insecure suggestions. This happens invisibly as you code
- During code review: Guardrails run as checks on code diffs in pull requests. If code in a PR violates a guardrail, Corridor catches it and flags it for review
Configuring guardrails
By default, Corridor applies the Corridor Default Security Pack: a comprehensive pack of essential security guardrails covering common vulnerability classes including injection attacks, authentication issues, and access control flaws. Corridor also provides pre-loaded security packs tailored to specific languages, app types, and standards. Teams can create custom packs on the Guardrails page comprised of guardrails unique to their needs. See Configuring Guardrails for detailed instructions on setting up default packs, custom guardrails, and custom context.Guardrail versioning
Guardrail versioning is in private beta. Corridor must enable it for your team.
In the app
When versioning is on, each guardrail shows a vN chip. Click it to open Version history. Each version records:- The version number
- When it was written
- Who wrote it
- A short reason
- The content at that version
Through MCP
Owner and Admin can use these tools when versioning is on:getGuardrailVersions is read-only. restoreGuardrailVersion needs custom guardrails on your plan. Standard Users cannot use either tool.
See Corridor MCP for the tool list.
Update and archive through MCP
Updating and archiving guardrails through MCP is a separate private beta feature. Corridor must enable it for your team.
Owner and Admin can use these tools. Both need custom guardrails on your plan. Standard Users cannot use them.
updateGuardrail is available when versioning is on. archiveGuardrail needs archive enabled as well.
There is no MCP tool to un-archive a guardrail. Un-archive it on the dashboard.
When archive is on, the dashboard also shows Archive instead of Remove. Archived guardrails stay in history and do not run. An Owner can still permanently delete an archived guardrail.
Restore a version does not un-archive a guardrail.
See Corridor MCP for the tool list.
Change History
Open Guardrails → Change History to see team-wide edits.- By change lists every edit in time order
- By guardrail groups edits under each guardrail
Managing guardrails via AI assistant
If you have the Corridor MCP integration set up, your AI assistant can interact with guardrails directly. Owner and Admin:- View guardrails: Ask your AI “What guardrails should I follow?” and it will call
getGuardrails - Create guardrails: Tell your AI “Create a guardrail for SQL injection prevention” and it will call
createGuardrail
- View versions: Ask your AI for a guardrail’s version history and it will call
getGuardrailVersions - Restore a version: Tell your AI to restore an earlier version and it will call
restoreGuardrailVersion
- Edit guardrails: Tell your AI to update a guardrail and it will call
updateGuardrail - Archive a guardrail: Tell your AI to archive a guardrail and it will call
archiveGuardrail
analyzePlan only. They cannot list, create, edit, restore, or archive guardrails.
See Corridor MCP for the full list of available tools and requirements.
Next steps
Configuring Guardrails
Set up and customize guardrails for your projects
PR Reviews
Automated security reviews on pull requests
Findings
Track and remediate security issues
Scheduled Agents
Private beta. Run Corridor Agent on a schedule or when findings change