tunneler.ai · private beta

Governed tunnels
for AI agents.

Your agents shouldn't act on the internet unsupervised. Tunneler captures a real session, returns a verdict before every action, keeps a human in the loop, and writes it all to a log you can trust.

Owned accounts only. Not a bot army.

One capture flow, any login RedditXFacebookLinkedInGitHubEmail
What it is

Identity ops, not posting tools.

Tunneler decides which identity speaks, whether it should speak at all, whether it can link, and when a human takes over. Six parts do that work.

01

Real session capture

You log into your own account in a real browser. The session is captured server side and encrypted at rest. No stored master password, no bot fingerprint on the login.

02

A verdict before every action

Identity fit, daily limits, link policy, disclosure, fake customer and payment checks. Run before the draft is written and again before it is sent.

03

Human approval queue

First posts, promo links from young accounts, sensitive DMs and gray areas wait for a person. Sending stays off until you arm it.

04

Append only audit log

Every action, every verdict, every permalink, written once and kept. You always know what happened and why.

05

Per account limits

Replies, posts, follows, promo links and DMs are capped per identity, so accounts season instead of getting flagged.

06

Persona and product fit

Each identity carries its tone, topics, allowed actions and products. The right account speaks, in the right voice.

The verdict is the interface

Every action gets one of three answers.

Guardrails run before anything leaves your machine. The decision is the whole point, so it is the whole color language. Refusing to post is a feature.

Allow

decision: allow

Low risk, in policy, a genuinely useful reply. Send it.

Hold

decision: approval_required

A first post, a promo link from a young account, a sensitive DM. A human approves.

Stop

decision: block

Fake customer testimony, ban evasion, spam. Refused, with a reason.

09:41:22u/plane-mbreply_posted · r/nodeposted
09:43:05@gandalfpost · promo linkapproval_required
09:44:18u/plane-mbcomment · r/dealsblocked
09:46:51@gandalfdm_sent · ownedposted
How it works

Login to governed autonomy in four steps.

01

Tunnel in

Open a relayed browser, log into your real account, and the session is captured and encrypted.

02

Gate it

Guardrails score every proposed action against identity, limits, links and disclosure.

03

Approve

Risky actions land in a human queue. The arm switch is off by default.

04

Log

Every action and verdict is written to an audit ledger with evidence.

Pricing

Start free. Add identities as you grow.

Self host the core or let us host the tunnels. Plans set how many identities and workers you run.

Free
$0
  • 1 identity
  • All guardrails
  • Approvals and audit log
  • Paste or upload sessions
Get started
Popular
Developer
$29/mo
  • 3 identities
  • 1 hosted browser worker
  • One click relay login
  • Email support
Start Developer
Team
$99/mo
  • 15 identities
  • 3 workers
  • Per account limits
  • Priority support
Start Team
Growth
$499/mo
  • 60 identities
  • 10 workers
  • Audit export
  • SSO and SLA (soon)
Talk to us
FAQ

The honest answers.

Is this a bot army?

No. The opposite. Tunneler is for owned, transparent identities you control. It refuses spam, mass DMs, fake reviews, ban evasion and impersonation. This is governance, not growth hacking.

Where are my sessions stored?

Captured cookies are encrypted at rest with AES-256-GCM and scoped to your workspace with row level isolation. We reference your session, we do not expose it, and you can disconnect any time.

How do you keep accounts from getting flagged?

You log in yourself in a real browser, so there is no automated login fingerprint. Accounts season under per account daily limits, replies stay help first, and risky actions need approval. We optimize for reputation over weeks, not volume today.

What if an agent is asked whether it is automated?

It answers honestly and casually. Tunneler never tells an agent to lie about automation, and never impersonates a human owner.

Can I self host?

Yes. The engine, API and browser worker run as containers. Host the tunnels on your own infrastructure for a stable, consistent egress, with the same guardrails, approvals and audit log.

Give your agents a passport to the internet.

Governed tunnels, a verdict before every action, a full audit trail.