---
title: "gate22 vs cordum"
type: "comparison"
canonical_url: "https://www.graphcanon.com/compare/aipotheosis-labs-gate22-vs-cordum-io-cordum"
tools: ["aipotheosis-labs-gate22", "cordum-io-cordum"]
---

# gate22 vs cordum

*GraphCanon updated Sep 20, 2026*

## Verdict

Pick gate22 if gate22 is an open-source MCP gateway and control plane for governing AI agents' tool usage and actions with comprehensive auditability; pick cordum if cordum is an action firewall for AI agents, designed to enforce policy and human approval before risky operations, with a focus on auditability and compliance.

[gate22](https://gateway.aci.dev) reports 178 GitHub stars, 24 forks, and 23 open issues, last pushed Dec 12, 2025. [cordum](https://github.com/cordum-io/cordum) has 507 stars, 33 forks, and 30 open issues, last pushed Sep 17, 2026. Figures are from public GitHub metadata via [gate22's repository](https://github.com/aipotheosis-labs/gate22) and [cordum's repository](https://github.com/cordum-io/cordum).

| | [gate22](/tools/aipotheosis-labs-gate22.md) | [cordum](/tools/cordum-io-cordum.md) |
| --- | --- | --- |
| Tagline | MCP gateway and control plane for agent governance | The action firewall for AI agents, enforcing policy and human approval before risky operations. |
| Stars | 178 | 507 |
| Forks | 24 | 33 |
| Open issues | 23 | 30 |
| Language | TypeScript | Go |
| Adopt for | Gate22 is an open-source MCP gateway and control plane for governing AI agents' tool usage and actions with comprehensive auditability. | Cordum is an action firewall for AI agents, designed to enforce policy and human approval before risky operations, with a focus on auditability and compliance. |
| Persona | - | - |
| Runtime | - | - |
| License | Apache-2.0 | Other |
| Categories | AI Agents, Evaluation & Observability | AI Agents, Evaluation & Observability |

## Trust and health

_Sourced signals - not a safety guarantee. No winner column._

| | [gate22](/tools/aipotheosis-labs-gate22.md) | [cordum](/tools/cordum-io-cordum.md) |
| --- | --- | --- |
| Maintenance | Slowing (36%) | Very active (96%) |
| Days since push | 274d | 0d |
| Open issues (now) | 23 | 30 |
| Stars delta | +3 (30d) | +13 (30d) |
| Open issues delta | 0 (30d) | +14 (30d) |
| Full report | [trust report](/tools/aipotheosis-labs-gate22/trust.md) | [trust report](/tools/cordum-io-cordum/trust.md) |

## Decision facts: gate22

- **Adopt for:** Gate22 is an open-source MCP gateway and control plane for governing AI agents' tool usage and actions with comprehensive auditability.

## Decision facts: cordum

- **Adopt for:** Cordum is an action firewall for AI agents, designed to enforce policy and human approval before risky operations, with a focus on auditability and compliance.

## Choose when

### Choose gate22 if…

- gate22 is primarily TypeScript; cordum is Go.
- License: gate22 is Apache-2.0, cordum is Other.
- Tags unique to gate22: agents, ai-agents, control-plane, gateway.
- When you need to standardize governance over the tools and actions across various AI environments such as agentic IDEs.

### Choose cordum if…

- cordum is primarily Go; gate22 is TypeScript.
- License: cordum is Other, gate22 is Apache-2.0.
- Tags unique to cordum: agent-framework, ai-governance, audit-trail, human-in-the-loop.
- cordum ships Docker support for self-hosted deployment.
- When you need a framework that ensures human approval before AI agents execute risky operations, such as shell commands or production changes.

## When NOT to use gate22

- For scenarios where a closed-source solution is preferred due to specific confidentiality or proprietary concerns.
- If the organization's tech stack does not align well with TypeScript, which Gate22 employs for its development.

## When NOT to use cordum

- If you are looking for a solution that can be offered as a competing hosted service before January 1, 2029, as the current license restricts this use case.
- When your deployment environment does not meet the prerequisites for running Cordum, such as Docker Desktop v4+, Go 1.26.3+, and at least 4 GB of RAM.
- If your organization does not require a full stack setup including an API gateway, scheduler, safety kernel, workflow engine, context engine, dashboard, NATS, and TLS-secured Redis.
- When you prefer a tool that does not enforce a human-in-the-loop approval process for AI actions, and you are comfortable with less stringent governance measures.

## Common questions

### What is the difference between gate22 and cordum?

gate22: MCP gateway and control plane for agent governance. cordum: The action firewall for AI agents, enforcing policy and human approval before risky operations.. See the comparison table for live GitHub stats and shared categories.

### When should I choose gate22 over cordum?

Choose gate22 over cordum when gate22 is primarily TypeScript; cordum is Go; License: gate22 is Apache-2.0, cordum is Other; Tags unique to gate22: agents, ai-agents, control-plane, gateway; When you need to standardize governance over the tools and actions across various AI environments such as agentic IDEs.

### When should I choose cordum over gate22?

Choose cordum over gate22 when cordum is primarily Go; gate22 is TypeScript; License: cordum is Other, gate22 is Apache-2.0; Tags unique to cordum: agent-framework, ai-governance, audit-trail, human-in-the-loop; cordum ships Docker support for self-hosted deployment; When you need a framework that ensures human approval before AI agents execute risky operations, such as shell commands or production changes.

### When should I avoid gate22?

For scenarios where a closed-source solution is preferred due to specific confidentiality or proprietary concerns. If the organization's tech stack does not align well with TypeScript, which Gate22 employs for its development.

### When should I avoid cordum?

If you are looking for a solution that can be offered as a competing hosted service before January 1, 2029, as the current license restricts this use case. When your deployment environment does not meet the prerequisites for running Cordum, such as Docker Desktop v4+, Go 1.26.3+, and at least 4 GB of RAM. If your organization does not require a full stack setup including an API gateway, scheduler, safety kernel, workflow engine, context engine, dashboard, NATS, and TLS-secured Redis. When you prefer a tool that does not enforce a human-in-the-loop approval process for AI actions, and you are comfortable with less stringent governance measures.

### Is gate22 or cordum more popular on GitHub?

cordum has more GitHub stars (507 vs 178). Stars measure visibility, not whether either tool fits your constraints.

### Are gate22 and cordum open source?

Yes - both are open-source projects on GitHub (gate22: Apache-2.0, cordum: Other).

### Where can I find alternatives to gate22 or cordum?

GraphCanon lists graph-backed alternatives at [gate22 alternatives](/tools/aipotheosis-labs-gate22/alternatives) and [cordum alternatives](/tools/cordum-io-cordum/alternatives) ([gate22 markdown twin](/tools/aipotheosis-labs-gate22/alternatives.md), [cordum markdown twin](/tools/cordum-io-cordum/alternatives.md)), ranked by typed relationship edges rather than popularity votes.

### Is there a machine-readable version of this comparison?

Yes. The markdown twin at [this comparison](/compare/aipotheosis-labs-gate22-vs-cordum-io-cordum.md) mirrors this page for agents and LLM crawlers, with the same stats table and FAQ answers.

### Which is better maintained, gate22 or cordum?

gate22: Slowing. cordum: Very active. Compare maintenance labels, days since push, and release cadence in the trust section below - stars alone do not measure maintenance.

### Where are the full trust reports for gate22 and cordum?

GraphCanon publishes per-repo trust reports with dated maintenance, provenance, and scan summaries: [gate22 trust report](/tools/aipotheosis-labs-gate22/trust); [cordum trust report](/tools/cordum-io-cordum/trust).

---

**Machine-readable endpoints**

- JSON: [`/api/graphcanon/graph?tool=aipotheosis-labs-gate22`](/api/graphcanon/graph?tool=aipotheosis-labs-gate22)
- LLM index: [/llms.txt](/llms.txt)
- Full corpus: [/llms-full.txt](/llms-full.txt)

_GraphCanon - The knowledge graph for AI development. https://www.graphcanon.com/_
