OpenBox AI and Mastra Add Default Runtime Governance to TypeScript Agents

May 05, 2026
OpenBox AI and Mastra have partnered to integrate runtime governance directly into the Mastra TypeScript agent framework, enabling compliance-ready oversight and audit capabilities by default.

OpenBox AI and Mastra have partnered to make runtime governance a built-in feature for all TypeScript agents built on the Mastra framework, announced in a press release.

The integration introduces automatic oversight for every tool invocation, workflow step, and inter-agent message within Mastra. Each action is scored using the OWASP AI Vulnerability Scoring System and classified into one of five verdicts: allow, constrain, require approval, block, or halt. Verdicts are returned in under 250 milliseconds under normal workloads, and all actions are cryptographically attested and logged.

The system also supports human-in-the-loop approvals that persist across restarts and includes built-in detection for personally identifiable information and content moderation. Enterprises can access compliance-ready dashboards and governance for multi-agent workflows, with new tools automatically covered as applications grow.

The integration is available now for all Mastra developers, with documentation and a free tier accessible at openbox.ai.

We hope you enjoyed this article.

Subscribe to Cybersecurity AI Weekly

Weekly newsletter about AI in Cybersecurity.

Market report

AI’s Time-to-Market Quagmire: Why Enterprises Struggle to Scale AI Innovation

ModelOp

The 2025 AI Governance Benchmark Report by ModelOp provides insights from 100 senior AI and data leaders across various industries, highlighting the challenges enterprises face in scaling AI initiatives. The report emphasizes the importance of AI governance and automation in overcoming fragmented systems and inconsistent practices, showcasing how early adoption correlates with faster deployment and stronger ROI.

Read more