Skip to content
endlayer agents

Everyone else watches.Ours work.

One agent, three tiers. 3 MB to 300 MB. They live on your machines and inside your servers, not at a gateway watching traffic go by.

The checks run where your data already is. Your data does not go to a model.
the difference

A monitor sees. An agent acts.

conventional controlsendlayer
Sit at the edge and inspect traffic crossing a gateway.Run inside, on the device and in your servers.
Miss local models, AI agents and MCP servers entirely.Discover them where they run, then grade, investigate and test.
Send what they see to somebody else's cloud.Nothing leaves the machine. The checks run where the data already is.
the ladder

Put the right amount of intelligence on every machine.

agent 01

Sensor

3 MB
Every device

Finds what a network never will.

One binary. No runtime, no dependencies, no model. It inventories every AI tool, local model, agent, extension and MCP server on the machine, and the AI sites it reaches, then grades all of it against deterministic policy without sending a prompt anywhere.

Discover
Decide
Understand
Act
Complete local AI inventoryShadow AI discoveryMCP server detectionAI tool and site useDeterministic policyOffline operation
Footprint3 MB
Memory<40 MB
ModelNone
DeployDevice
agent 02

Decoder

30 MB
Devices sending AI traffic

The encrypted stream, readable on the machine that made it.

A local gateway, not a network one. Decoder terminates TLS on the device, so a prompt is readable in the clear at the moment it is sent, and re-encrypts it before it goes anywhere. That is what makes a real-time block possible: a request to a consumer AI service can be stopped on the wire, on the machine, before it reaches the network. The decrypted text never leaves the device.

Discover
Decide
Understand
Act
Local TLS gatewayBlocks a request in real timeReads AI traffic in the clearRe-encrypts before it leavesDecrypted text stays on the deviceEverything in Sensor
Footprint30 MB
Memory<120 MB
ModelClassifiers
DeployDevice
agent 03

Guardian

300 MB
Devices running agents

It watches agents talk to each other.

Guardian sits where agents meet. It sees one agent call another, an agent reach an MCP server, or a tool ask for a permission it was never granted — and it blocks the request and applies the rule on the device, as it happens. Every decision is written down against the policy version it was graded on.

Discover
Decide
Understand
Act
Agent-to-agent detectionBlocks a request as it happensApplies policy on the deviceMCP call inspectionVersioned decision recordEverything in Decoder
Footprint300 MB
Memory<400 MB
ModelClassifiers
DeployDevice
start at the bottom of the ladder

Sensor on three devices, free. Move up when a machine needs more.

Every tier reports into the same console with the same policies. Upgrading a device is a package swap, not a new rollout.

apex · offence

Every other tool waits for something to go wrong.

  1. 01

    Inventory

    Agents, prompts, MCP servers and tools.

  2. 02

    Attack

    Injection, extraction, jailbreak and escalation.

  3. 03

    Score

    What got through, why and how far.

  4. 04

    Harden

    Turn each success into an enforceable policy.

Governance you can prove. A policy that has never been tested is a document. One that survived an attack is a control.

start with endlayer

Take control of the AI already in your company.

It is already installed on the laptops. You can see all of it by this afternoon.

activity4h slices
30d ago22d15d7dnow