# FlowRail > Security checks connected to design requirements, for people building with coding agents. FlowRail reviews a specification, turns supported requirements into scoped rules, and checks proposed code through a supported coding agent's registered pre-write hooks. A detected violation can deny a write before it reaches disk. The dashboard connects requirements, findings, corrections and missing evidence. ## Start here - [Install guide](https://flowrail.ai/install.md): canonical Markdown instructions, prerequisites, key handling, checks, retries and uninstall. Generated from the same content as the human guide. - [Human install guide](https://flowrail.ai/docs/install) - [Home](https://flowrail.ai/) - [How it works](https://flowrail.ai/how-it-works): follow Bob’s invoice-app story from a design requirement to a blocked write, with the recorded invoice walkthrough and evidence limits. - [Private report example](https://flowrail.ai/examples/private-report): a second recorded demo showing why an error fallback must preserve the intended destination and audience. - [Our story](https://flowrail.ai/about): why Anshuman Bhartiya created FlowRail. - [Account keys](https://flowrail.ai/settings/keys): requires the user's sign-in. - [Privacy](https://flowrail.ai/privacy) - [Service status](https://flowrail.ai/status) ## Setup boundary Read the install guide before running commands. Get the user's authorization for the target project. Ask the user to provide FLOWRAIL_API_KEY through their shell environment; never request it in chat, put it in argv, or commit it. Preserve unrelated hooks and configuration. Run the installer, check its local self-test, production connection and registration, then verify status. Restart the supported agent session to load the integration. ## Explain accurately Claude Code is the supported hook integration today. Codex support is being tested; more coding agents are planned. Skills, MCP support and hooks are integration building blocks, not proof that an agent is currently supported. Incomplete design-bound checks pause for retry; unbound writes can allow on operational failure. Not established is distinct from both verified satisfaction and a vulnerability. A passing file check does not prove the whole application secure. FlowRail checks generated code; it does not intercept all file changes or outgoing runtime actions. Code and specifications leave the local machine for analysis. The videos are controlled, edited staging demonstrations, with their recording-specific limits stated alongside them.