VORIM
We use cookies

We use cookies to analyze site traffic and improve your experience. You can choose to accept all cookies or only essential ones. See our Privacy Policy.

AI SecurityClaudeEnterpriseComplianceProduct

Answering a Prompt Before It Runs: Vorim and Claude Inference Hooks

For about two years, the conversation about controlling AI has lived at the edges. You filter the output after the model speaks. You scan the logs after the fact. You train the model to refuse. All useful, all after or around the moment that actually matters.

This month Anthropic shipped something that moves the checkpoint into the middle. It is called Inference Hooks, and it is available to Claude Enterprise organisations in beta.

What it does

When someone in a Claude Enterprise organisation sends a prompt, Anthropic can now forward that prompt to an external server — an "AI security server" the organisation runs — for a verdict, before the model runs. The server answers allow or deny. On allow, inference proceeds as normal. On deny, the request is rejected and the user sees a blocked-by-policy message. The prompt never reaches the model.

One hook governs every surface: claude.ai in the browser and desktop app, Claude Code in the CLI, and Cowork. Because it runs on Anthropic's side, after the request leaves the user's device and before the model runs, there is nothing to install on anyone's laptop. A contractor on an unmanaged machine is governed the same as an employee on a locked-down one.

That is a meaningful shift. It is the first time a company can enforce its own policy at the moment of use, on the prompt itself, rather than cleaning up afterwards.

Vorim is that server

As of today, Vorim works as an AI security server for Claude Inference Hooks. Point your Claude Enterprise organisation at your Vorim endpoint, and every governed prompt runs through the same policy engine that already guards what your AI agents do — now applied one step earlier, to the prompt.

The exchange is exactly what you would want from a security control. Vorim verifies the request is genuinely from Anthropic by checking its signature over the raw bytes, evaluates the transcript against your organisation's rules, and returns a verdict well inside the timeout. If your rules say a prompt carrying customer card numbers or a particular class of regulated data should not reach the model, it does not.

The part we care about most

A filter blocks a prompt and forgets it. That is not enough for a regulated business, because the question an examiner asks is not "did you have a filter." It is "prove which prompts you allowed and which you denied, and why."

So every verdict Vorim returns is signed into a tamper-evident record. Not the prompt text — the decision: which request, allowed or denied, against which rule, at what time. It is idempotent, so a retried delivery does not double-count, and it carries a reference you can line up against the denial records in your own Claude Enterprise activity feed. You do not just stop a prompt. You end up with evidence you can stand behind.

That is the whole Vorim thesis, one layer earlier than usual. For an agent taking an action, we prove which agent did it and whether it was allowed. For a prompt reaching a model, now we can prove the same. The through-line is accountability you can verify, not trust you are asked to extend.

Why this matters beyond the feature

Step back from the mechanics and there is a pattern worth naming. As AI moves into work that carries real consequences — moving money, touching regulated data, acting on a customer's behalf — the interesting problem stops being whether the model is capable. It is whether what it did can be accounted for. Who allowed this, and can you prove it later.

Inference Hooks are Anthropic building the socket for exactly that question at the prompt layer. We think the answer plugged into it should not just say yes or no. It should leave a record worth trusting.

If you run a Claude Enterprise organisation and want your prompts checked and signed before they run, or you are putting AI agents into regulated production and need to prove what they do, that is the whole of what we build.

Book a demo →

Found this useful? Share it.

Share
Get started

Ready to build with AI agents?

See how Vorim gives your agents identity, permissions, and a signed audit trail. Book a walkthrough with our team.