Skip to content

The Control Plane for AI

Every AI tool, agent, and model call across your company: surfaced, monitored, and governed from one plane.

Get startedBook a demo$9.99 a device · free for three

no card, no call · one laptop reporting in a minute

surfaces monitoring governance
pass warn serious fail
what it is

endlayer surfaces every AI running on your machines, monitors what it touches, and governs it against your policy.

One agent on the device feeds all three. There is no connector to build, no proxy in the path and no gateway to route through. Everything is read from files already on the disk.

01 · surfaces

Surface what is there

An unprivileged agent on every machine finds the AI apps, coding agents, MCP servers, local models, browser AI usage, accounts and exposed credentials, without being told they exist.

21 signals · no integration
02 · monitoring

Monitor what it touches

Which apps and agents are active, what they can reach through MCP, whose account they run on, which projects and repositories they see, what they cost, and which machines have gone quiet.

apps · agents · MCP · accounts · spend
03 · governance

Govern it against your policy

Every signal is graded against your immutable policy version. Unsanctioned tools, unattended agents, personal accounts and credential-bearing MCP servers are flagged, owned and tracked to closed, with the record kept.

graded · guardrails block in real time
why

Your people already use AI and agents. Nobody knows what they can reach, or what they do.

Every tool arrived the same way: one person, one laptop, one Tuesday. Nothing was recorded, so nothing can be seen, attributed or proved.

01You cannot see what is there

Invisible

answered by Surfaces · devices, MCP servers, the map
  • Desktop apps, coding agents and local models run on the machine, never through the gateway.
  • Provider keys sit in shell profiles and in .env files git is not ignoring.
  • MCP servers carry credentials off the device, and no CASB has a connector for them.
So the inventory does not exist.
02So you cannot see what it does

Untracked

answered by Monitoring · apps, agents, users, spend
  • Agents act unattended, in permission modes nobody reviewed.
  • Corporate work runs through somebody’s personal ChatGPT and Claude logins.
  • Tokens are spent on the laptop; the invoice arrives monthly and aggregated.
So none of it can be attributed.
03So you cannot answer for it

Unprovable

answered by Governance · policies, remediations, history
  • No rule was ever written for any of it, so nothing is graded against anything.
  • When something is wrong there is no owner, no state, and no date it closed.
  • Asked what existed in March and what the rule said then, the answer is a shrug.
So the auditor’s question has no answer.
your AI inventory, todaynot zero. Unknown, which is worse
surfaces
AI tools running across the fleetunknown
Machines with a provider key in a fileunknown
MCP servers carrying credentials off-deviceunknown
monitoring
Agents configured to run unattendedunknown
Work happening on personal accountsunknown
Spend on tokens last monthunknown
governance
What any of this looked like in Marchno record
Which tools were ever approvedno record
What evidence exists for an auditno record
InvisibleSurfaces finds every AI tool, agent, key and MCP server on each device. Surfaces →
UntrackedMonitoring counts them across the fleet, with the account, the reach and the cost. Monitoring →
UnprovableGovernance grades every one against a versioned policy and keeps the record. Governance →
how it works

One agent on the device. Three things it makes possible.

No proxy in the path, no gateway to route through and no connector per tool. Everything is read from files already on the disk.

21signals on every device

Including whether a coding agent may act unattended. All 21 →

15minutes between snapshots

A tool installed at 9:00 is in the inventory by 9:15.

7platforms, one agent

mac, Windows, Linux, iOS, Android, servers and cloud.

0changes to your network

No proxy to route through, no gateway to stand up.

connect
Runs onlaptops, phones, servers and cloud
Installs throughIntune · Jamf · SCCM · your fleet tooling
Local agentinstalls, no dependencies
Runs asthe device user, never elevates
Deliveryoff until you turn it on
monitor
Tools and agents17 recognised, autonomy from config
MCP serverstransport, capability, credential flag
Accounts and spendcorporate vs personal, priced usage
Postureencryption, lock, firewall, patch level
govern
Graded againstan immutable policy version
What failsgets an owner and a state
Historyevery transition retained
Guardrailswarn, redact or block in real time

guardrails act on every device today; cloud connectors and SDK ingestion are planned, and the same rules apply to them the day they ship

layer by layer

Control your AI, layer by layer.

Six layers, and each one is useful on its own. Together they turn AI nobody catalogued into something you can see, price, stop and prove. One agent on the device feeds all six.

01

Discover

no integration

Know what is actually running.

read from files on the disk, never executed

  • Apps, coding agents, MCP servers and local models
  • Accounts and API keys, including the key in a dotfile
  • Found without an integration to install first
87 tools
what one scan returns
02

Inventory

one record

Turn every report into one record.

macOS, Windows, Linux, servers and cloud

  • One row per tool, with its version and autonomy level
  • Sanctioned, undecided or unsanctioned, per tool
  • Machines that go quiet are surfaced, not assumed healthy
1,231 machines
the fleet, as it reports
03

Access

blast radius

See what each one can reach.

declared, never dialled

  • Every MCP server, and whether it carries a credential
  • Repositories and projects inside an agent’s scope
  • Whose account each tool runs on — corporate or personal
312 MCP servers
one agent’s reach
04

Spend

attributed

Know what it costs before the invoice.

by tool, person and project

  • Token usage attributed to the team that caused it
  • Which tools the money is actually going to
  • $9.99 per device per month, so the bill is a multiplication
$18.4k / 30d
spend by project
05

Guardrails

real time

Act at the moment it happens.

inside the agent, on the device

  • Prompts scored before they run
  • Secrets and personal data redacted on the way out
  • The matched text never leaves the machine
warn · redact · block
the prompt path
06

Govern

the record

Grade it, and keep the proof.

every publish is a version

  • Nineteen rules, graded on every device within fifteen minutes
  • A failure gets an owner, a state and a date it closed
  • An exportable record for SOC 2, EU AI Act, ISO/IEC 42001, NIST AI RMF
9 of 19 rules on
policy v4

21 signals every fifteen minutes · Surface, Monitor and Govern are the three pages behind the six layers

what you get

Five things you get. From one agent, nothing else installed.

Claude Codecoding agent
Cursoreditor
chatgpt.comnot approved
4 MCP serversdeclared
Complete visibility of AI in useEvery tool, agent and AI site on every device, including the ones nobody approved, without asking anyone. Shadow AI discovery and a live AI inventory across laptops, desktops and cloud.
$18.4k
last 30 days · 4 models
AI spend you can attributeToken spend per tool, person and project, before the invoice arrives. AI cost monitoring for coding agents, chat assistants and local models.
work loginapproved
personal loginflagged
key on disknot ignored
Company work stays inside the companyPersonal logins on work tools and exposed keys are flagged the same day. Data loss prevention for AI usage, without a proxy or gateway.
2of 6
can act unattended
Oversight of what agents do on their ownWhich agents act unattended, what they can reach, and what was pre-approved. AI agent governance for coding agents and MCP servers, on the device.
CC6.1CC6.3CC6.6CC6.7CC6.8CC7.1CC8.1CC9.2
Proof for your auditor, on demandEvery check graded against a policy version, with the evidence attached. Audit evidence for SOC 2, the EU AI Act, ISO/IEC 42001 and NIST AI RMF.

21 signals every fifteen minutes · every signal, listed →

what it finds

Every kind of AI on the machine.

Six surfaces, one agent, and nothing installed in the path. Pick a surface to see what is read off the disk.

Coding agents

They write and run code on the machine, sometimes without being watched.

what is invisible

The permission mode nobody reviewed, the MCP servers it can reach, and which repositories are in its scope. None of it crosses a gateway.

what it reads

The agent's own configuration, in the user's home directory.

settings file · permission mode · MCP clients · repo scope
laptop-01 · claude-coderead 09:15
how it runs
permission modeacceptEditsunattended
last active4 min ago
what it reaches
MCP servers42 carry creds
repositories in scope11
fleet · Claude Code 412 devices · Cursor 388 · GitHub Copilot 244

Desktop AI apps

The chat window that never goes through your network.

what is invisible

Which account it is signed in on. Corporate work runs through somebody's personal ChatGPT and Claude login, over TLS to a domain you already allow.

what it reads

Installed applications, and the account each one is signed in as.

.app / .exe · signed-in account · last active
laptop-04 · ChatGPT Desktopread 09:15
identity
signed-in account@gmail.compersonal
corporate SSOnot used
standing
graded against policyv4unsanctioned
last activetoday
fleet · ChatGPT Desktop 261 devices · Claude Desktop 173

MCP servers

The connectors that hand an agent your credentials.

what is invisible

They are declared in a client's config file and carry tokens off the device, and no CASB has a connector for them.

what it reads

The client config files that declare them. Declared, never dialled.

server name · transport · credential-bearing
laptop-01 · 4 servers declaredread 09:15
transport, across the fleet
stdio, on device271
http, off device41
credentials
credential-bearing41 of 312off-device
URLs and env valuesnever recorded
fleet · 312 declared · Cursor 134 · Claude Code 96 · VS Code 44

Local models

A model running on the laptop. No invoice, no log, no gateway.

what is invisible

It runs entirely on the device, so nothing you bill against will ever show that it existed. And nothing in the path can see it.

what it reads

The runner on disk, the models it has pulled, and the port it listens on.

runner · pulled models · listen address
laptop-07 · ollamaread 09:15
on disk
models pulled7 · 41 GB
listening127.0.0.1:11434
cost
tokens counted2.1M
invoiceunpriced
fleet · Ollama and LM Studio 96 devices · none of it invoiced

Browser AI

The extension and the side panel that read the page you are on.

what is invisible

Extensions install per browser profile, ask for permission once, and are never inventoried again.

what it reads

Extension manifests, per profile, and what each one declares it can see.

extension · profile · declared host access
laptop-02 · Chrome, profile 2read 09:15
extensions
AI extensions3
can read page contents2broad
scope
profilepersonalsigned in
declared host accessall sites
fleet · AI extensions on 188 devices · 61 read page contents

Keys and accounts

A provider key in a file git is not ignoring.

what is invisible

Keys sit in project .env files and in shell profiles. One of them is one push away from public.

what it reads

Presence and location only. The value is discarded before evidence is built.

file path · exposure · never the value
fleet · keys found in filesread 09:15
where they are
project .env38
shell profile21
exposure
repository-visible24one push from public
tool-managed storenever opened
fleet · 64 machines carry a key in a file · 40 local only
all seventeen, recognised by nameno connector for any of them
Claude CodeCursorGitHub CopilotCodex CLIWindsurfAiderClineContinueOpenCodeAmpGooseGemini CLIOpenClawChatGPT DesktopClaude DesktopOllamaLM Studio

the eighteenth tool needs a signature, not an integration

at any size

One laptop, or fifty thousand.

How you start depends on how big you are. What you get does not.

Just me · Download it and run it
Installing it
Download it and run it.
Switching it on
Click Connect this device, then accept it yourself.
What you look at
One device, and everything on it.
Installing it
Everyone downloads it, or you send them a link.
Switching it on
Each person clicks Connect. You accept them.
What you look at
A list short enough to read top to bottom.
Installing it
Push it out with the tools you already use for laptops.
Switching it on
One shared secret. Nobody has to click anything.
What you look at
What needs fixing, rather than everything that exists.
Installing it
The same push, released in waves.
Switching it on
The same secret and the same settings, for every wave.
What you look at
What changed since yesterday.

no minimum number of people · no charge per tool connected · nothing in the path of your traffic

how to get it

Three ways in.

01free

Log in and use it now.

Free for three devices. No card.

Get started
02your infrastructure

Or run it on your own servers.

Nothing about your devices leaves your network.

How that works →
03open source

A small free tool.

What AI ran on one machine, and what it cost. Not the platform.

Open source ↗
the first minute

Sixty seconds, then it is reporting.

laptop-01 · zsh
$ endlayer enroll
enrolment code 4F2K-9QX1
waiting for an organisation to accept…
accepted · credential stored 0600 · org set by the approver
$ endlayer doctor
config /etc/endlayer/endlayer.toml
ignored none
delivery reachable · next scan in 847s
$ first snapshot delivered
21 signals · 3 pass · 2 warn · 3 fail · 13 info

that was one laptop · the same thing runs on five thousand

no card · delivery off until you turn it on · never elevates

common questions

The six we are asked first.

Does it read our conversations?

Yes, for PII leaking into a prompt, and for tools being used in ways nobody authorised. It is not on by default, and turning it on records who enabled it and the reason why. Your admin can narrow what is collected at any time, and the agent cannot widen it.

Do we have to put a proxy or gateway in the path?

No. Nothing changes on your network. Everything is read from files already on the disk, which is also why desktop apps, coding agents and local models show up at all. none of them go through a gateway.

Does the agent need admin rights?

No. It runs as the person using the machine and reads only what that account can already read. It never elevates, and it never executes any of the AI tools it finds.

What if we use a tool that is not on your list?

Seventeen are recognised by name. Anything else still surfaces as an unidentified AI process with the account and the machine attached, and naming it properly takes a signature, not an integration, so there is no per-tool work for you either way.

How quickly does something new appear?

Within fifteen minutes. Every device sends a snapshot every fifteen minutes, so a tool installed at 9:00 is in the inventory by 9:15.

Can it block anything, or does it only watch?

Both. Every signal is measured against your policy version, and what fails gets an owner, a state and a date it closed. Real-time guardrails inside the agent act on the device as it happens: prompts are scored before they run, and secrets and personal data are warned on, redacted or blocked on the way out. Removing an installed app is the one action that waits for a person: an administrator approves the request before anything is uninstalled. Every action is recorded.

start with endlayer

Take control of the AI already in your company.

It is already installed on the laptops. You can see all of it by this afternoon.

activity4h slices
30d ago22d15d7dnow