CloakPipe is a verifiable privacy and policy control plane for AI-agent traffic. It intercepts every agent hop — prompt, tool call, tool result — applies deterministic pseudonymisation and PII masking via a Rust-based reverse proxy, enforces code-defined policies outside the model, and produces cryptographically anchored, independently verifiable audit evidence. The open-source core (Apache 2.0) is free; commercial layers covering the Vault, Agent-Hop Policy engine, and Evidence Ledger target regulated industries requiring HIPAA, GDPR, SOC 2, PCI-DSS, and EU AI Act compliance.