Skip to content
endlayer · governs AI on every work device

See every AI.
Govern it with evidence.

endlayer is the control plane for AI.

It finds the AI tools, agents, accounts and MCP connections running on your work devices, managed or not, then links each one to a policy, an owner and a record that holds up. The device layer today; cloud and SDK layers planned.

Free for three devices · full grading and evidence packs · no card
console / homelive
Reporting
932/ 1000 enrolled
3 paused — a deliberate blind spot
Gone quiet
65
silent means ungoverned
Controls passing
76.4%
14,802 failing · 84,912 graded
Events · 7d
34
2 critical
Token cost · 7d
£9,918
11.2B tokens · +8.4% vs prior 7 days
AI tools
7
162 unsanctioned installs
Activity changes 6,481 · 2,144 into failing scans 6,104
MonWedFriSunnow
1 h slices · last 7 days412 scans excluded, awaiting approval
  • 13:00:33osl-mba-042 reported · 5 passing, 1 failing, 1 unknown
  • 13:00:34lis-win-030 reported · 6 passing, 1 failing
  • 13:00:35nyc-mba-001 reported · 6 passing, 1 failing
Needs attentionAll requests ↗  All events ↗
decide
2
critical
2
high
5
medium
14
low
11

Decisions stay until taken · events from the last 7 days

os patch level started failing
23 devices · high · 11:41
windsurf appeared, unsanctioned
3 devices · medium · 09:12
what your gateway misses

Your gateway cannot see the agents on the laptop.

A gateway only sees traffic you send through it. Desktop apps, coding agents, local models and MCP connections never are — so endlayer starts on the machine.

found without being told they exist

17 tools recognised: claude code, claude desktop, codex cli, chatgpt desktop, opencode, openclaw, cursor, windsurf, github copilot, aider, goose, gemini cli, amp, cline, continue, ollama, lm studio.

10 browsers6 MCP clientsmac · Windows · Linux · iOS · Android · servers · cloud

A gateway

sees
Traffic you route through it.
misses
Everything installed on the machine.

Software inventory

sees
The name of a process.
misses
Whose account it uses, and what it can reach.

A spreadsheet

sees
What was true the day you wrote it.
misses
Every day after that.

Seventeen tools. Nothing configured. No connector to build, no list to maintain.

how it works

Every device. Three steps.

Connect your devices once. Surfaces finds what is on them, Monitoring watches what they do, Governance decides what is allowed.

200 laptops · what is on them
197 reporting in3 paused deliberately
step 01 · Connect

Connect your devices.

One app on each work device — downloaded, or pushed through Intune, Jamf or SCCM. It finds every AI tool, agent, local model and MCP server on them — you never give it a list to look for.

Devices connected
200
AI installs found
1,571
Off-device MCP servers
3
Cloud APIs
no connector yet
step 02 · Monitor

Watch what they do.

Which tools are approved, which nobody has decided on, and which nobody approved at all. Who runs them, what they can reach, and what they cost.

Agents acting alone
4
Installs nobody approved
162
MCP servers holding a credential
3
Token cost, 30 days
£20,341
step 03 · Govern

Check it against your rules.

Graded against your own policy and against SOC 2, the EU AI Act, ISO/IEC 42001, NIST AI RMF and GDPR. Unapproved tools are flagged, given an owner and tracked to closed, with a record of who decided and when. Guardrails in the agent block in real time; removing an app waits for an administrator.

Things to fix
16
Controls passing
9,136
Could not be evaluated
979
Rule packages
5
the three modules

Surface, Monitor, Govern.

Three modules, one agent and one snapshot behind all of them. Adding the second and third costs no new integration — they read what the first already collected.

01 · Surfaces
AI asset inventory · shadow AI discovery · MCP server inventory

Every AI tool, agent and MCP server on your devices.

A searchable inventory of what is actually installed — AI apps, coding agents, local models, accounts, credentials and the MCP servers your fleet can reach . Read from files already on the disk.

DevicesMapMCP serversCloud APIs · plannedDevice detail
how you connect it
One machine at a timeclaim code
Fleet installone org secret
AWS · Azure · GCP · SDKs7 planned
console / surfaces / devices
Controls passing
75.2%
Devices
200
Stopped reporting
65
lon-mbp-900macOS 26.5.2 · 7 passing
blr-imac-587macOS 26.4.1 · 2 failing
nyc-win-377Windows 10 · 1 failing
osl-mba-312macOS 26.5.2 · 7 passing
off-device MCP hosts the fleet can reach
api.figma.com154
api.github.com153
sentry.io146
reporting every 15 minlocal stdio servers excluded
02 · Monitoring
AI agent monitoring · AI usage tracking · AI spend management

What each one does, who runs it, and what it costs.

Not a static asset list. Which tools are sanctioned, undecided or unsanctioned; which agents act unattended; what they reach; what they cost — by tool, model, project, person and machine.

OverviewAppsAgentsCost by deviceToken costActivity log
what it needs from you
New integrationnone
Cost is attributed totool, project, person and machine
Unpriced modelsshown, never folded in
console / monitoring / agentsread, never executed
Autonomous agents
4
Unsanctioned
162
Token cost · 30d
£20,341
claude_code339 devices checking
cursor281 devices checking
openai_codex179 devices checking
opencode162 devices checking
spend over time · by tool
priced when it is read1 model unpriced · shown, not folded in
03 · Governance
AI governance · EU AI Act · ISO/IEC 42001 · NIST AI RMF · SOC 2 · GDPR

Graded against your rules, and against the frameworks you report on.

Fifteen kinds of rule, from snapshot cadence to allowed MCP hosts. One immutable policy version per organisation — editing publishes v+1 and re-grades the whole fleet , so a verdict is always readable against the rule that made it.

PoliciesRegulationsRemediationsHistory
how the evidence is built
Policy versionsimmutable
Unevaluated controlsnever a pass
Assignment and due datesnot yet
console / governance / policiespolicy v1
Rules enforced
2/15
Controls failing
2,079
Never a pass
979
SOC 21/19
EU AI Act3/12
ISO/IEC 420013/15
NIST AI RMF3/11
GDPR4/10
what the re-grade turned up
Os patch level393
Mcp servers251
Ai autonomy168
editing publishes v2 and re-grades the fleetin effect

One agent. One snapshot. Three modules. Monitoring and Governance do not collect anything of their own — they read what Surfaces already found, which is why the second and third modules cost nothing to switch on.

One agent
~3 MB · every 15 min
One snapshot
21 signals, versioned
Three modules
no second integration
signal architecture

One signal path. A complete control plane.

Device evidence becomes inventory, monitoring, policy decisions and an audit-ready record. Nothing sits in the path of your network traffic, and no AI tool is ever executed to inspect it.

endlayer / signal architectureoutbound data · return decisions
device layer

AI activity at the source

A lightweight agent reads local signals without executing the AI it discovers.

macOS
Windows
Linux
TLS
bounded snapshot
endlayer control planeprocessing
SurfacesNormalises tools, models, agents and keys.inventory.graph
MonitoringResolves activity, access, owners and spend.context.timeline
GovernanceGrades every finding against policy versions.policy.evaluate()
versioned evidence modeldeduplicated · encrypted · tenant scoped
policy
decisions
outputs

Decisions with proof

  • Live console and alerts
  • Warn, redact or block · approve removals
  • Framework coverage
  • Nightly evidence export
  • Immutable decision history
01 no network interception02 no discovered tool is executed03 offline queue survives interruption04 policy versions remain traceable

Start with what is already happening

endlayer discovers the AI people and agents already use. No survey and no self-reporting are needed to build the first picture.

Turn visibility into decisions

The same findings power Surfaces, Monitoring and Governance. Switch modules on without collecting everything again.

Keep the reason, not just the result

Every verdict stays linked to the evidence and policy version behind it, so a reviewer can see what happened and why.

the agents

One agent, three tiers. From 3 MB to 300 MB.

Choose how much runs where — from deterministic discovery on every device to classifiers that read a prompt and stop it on the machine that sent it. Every tier follows the same bounded, outbound-only signal path.

schedule

Checks on your cadence, jittered so a fleet never arrives in one wave.

collect

Reads approved signals without launching or executing the AI it finds.

reason locally

Applies the active tier’s capability on the machine or in your environment.

snapshot

Produces versioned, redacted evidence — facts and decisions with provenance.

spool · sink

Lands on disk first, then leaves through one encrypted outbound route.

Capability steps up with footprint.

deterministic rules → trained classifiers → on-device enforcement
01 · Sensor3 MB
every device · no model

Inventories AI tools, local models and MCP servers. Applies deterministic rules the same way every time.

agent CLI · run · scan · enroll
02 · Decoder30 MB
every device · local TLS gateway

Reads the encrypted stream on the machine that made it. Terminates TLS locally and re-encrypts before anything leaves, so a request can be stopped on the wire. The cleartext never goes anywhere.

endlayer-core · on-device gateway
03 · Guardian300 MB
devices running agents · classifiers

Watches agents call each other, and refuses what policy forbids. Blocks the request and applies the rule on the device, against a versioned policy.

endlayer-core · trained classifiers

Reliability guarantees

01

One failed check never stops a scan.

That check reports unknown; every other result still completes.

02

Evidence is saved, then sent through one route.

A snapshot stays on disk until every destination accepts it.

what it reads

Broad coverage. One small snapshot.

endlayer turns the AI and security facts already on a device into one consistent inventory. No vendor API, running tool or network interception is required.

AI across all devices
4

AI tools, agents and web usage

Installed applications, coding agents, local models and browser AI — including whether an agent may act unattended.

ClaudeCodexCursorCopilotOllamaand more
connections
2

MCP servers and credentials

Declared servers, their transport, host and reach, and whether a provider key is present — never its value.

localremotecredentialed
identity and spend
2

Accounts and usage

Corporate, personal or unknown accounts, and the token and usage records the tools already wrote locally.

account typetoken spend
work context
1

Projects and data

Repositories as owner and name, with a bounded data-file inventory — no source code, no prompt content.

repositoriesdata files
device context
12

Device and security posture

Make and OS, management, updates and patch level, encryption, screen lock, firewall, EDR, network, browser and password policy, admin accounts.

macWindowsLinuxiOSAndroid
21 signals · seven groups

The registry keeps growing behind a versioned schema. The categories stay stable, so the inventory does not change shape when support expands.

See all 21 signals →See the open schema →
built-in boundaries

We collect evidence. Not your work.

The agent is designed to answer security questions without becoming a surveillance tool. These limits live in the collector, not in an admin setting.

the promise is enforced before upload
Sensitive values are removed on the endpoint. They never enter endlayer storage.
redacted on devicebefore storage

We do not read secrets

Credential presence is reported. The value is discarded on the device, before evidence is built.

We do not read source code

Repository context is enough. File contents stay untouched.

We do not collect conversations by default

Prompts, responses and transcripts stay off until an administrator switches them on, and the record says who did, and why.

We do not inspect traffic

No proxy, packet capture, payload inspection or gateway.

We do not run discovered tools

The agent observes. It never launches what it finds.

We do not track people

No precise location, raw device identity or personal account IDs.

administrator control · narrow collection onlythe collector refuses requests outside these boundaries
see it on your own machines

Twenty-one signals, nothing else. See them on a laptop you own.

Install on three devices free and the first snapshot lands in a minute. No proxy, no gateway, no connector to build first.

how it connects

Four signals, one answer.

Signals arrive per device. The graph resolves them into entities that exist across devices, accounts, repositories and environments — so a question has one answer, rather than one answer per machine.

deviceOwner, platform, posture, enrolment, last seen, whether it has gone quiet
toolA product across the fleet, not an install — sanctioned, tolerated or unknown
agentConfigured mode, whether it may act unattended, what it was pre-approved for
mcp_serverClient, scope, transport, host, capabilities, whether it carries credentials
accountOrganisation or personal, plan, email domain, approved-domain result
credentialProvider, source, repository, exposure — and whether git was ignoring it
repositoryCorporate or personal, owner, languages, data files, which tools touched it
usageTokens by day, tool, model, project and session — priced when it is read
policy_versionImmutable. The rule as it stood on the day, not as it stands now
findingState, owner, opened, closed — the thing somebody is actually answerable for
controlThe framework control a finding rolls up to, and its coverage
eventA transition with a time on it: what changed, when, and from what
one question · four signals · one rowno single collector can answer this

Which unmanaged laptops run a coding agent that may act unattended, signed in to a personal account, against a corporate repository?

mdm_enrollment

Enrolment state — not managedby anybody’s MDM.

ai_autonomy

Default mode and unattended session totals.

ai_accounts

Classification — personal, outside the approved domain.

ai_projects

Repository trust — corporate, and the tools that touched it.

one finding

Graded, owned and dated. One row a person can be asked about, rather than four dashboards a person has to join by hand.

One tenant, structurally

Every client-facing function resolves the organisation from the verified identity, never from an argument — one function taking an org id as a parameter is a cross-tenant read. A generated test walks the whole API and asserts every function refuses one.

Live, not polled

A query is a subscription. A device that reports at 09:15 changes the fleet view at 09:15, with no refresh button, no polling loop and no socket layer written by hand.

AI governance policy evaluation

Every verdict keeps the rule that made it.

endlayer evaluates device evidence against the versioned AI policy in force at that moment. Evidence, policy and verdict stay linked—creating a reproducible AI risk decision and a compliance-ready audit trail.

one finding / end to endevidence + policy version = reproducible verdict
01 · device evidence

What happened?

AI toolclaude-code
unattended sessions3
prompt bypassenabled
repositoryacme/billing-api
02 · versioned policy

Which rule applied?

Coding agents need a named approver before running unattended against corporate repositories.

policy v4 · immutable
effective 12 Mar, 09:00
approver: none recorded

03 · verdict

What did the policy engine decide?

fail

Graded against policy v4
Owner: platform engineering
State: open

01 · reproducible

Same inputs, same verdict.

The backend grader is a pure function of evidence and policy. It does not read the clock, database or another device.

02 · no guessing

Missing evidence stays unknown.

If the device cannot measure something, endlayer reports unknown instead of inventing a pass or fail.

03 · no false green

Missing policy stays ungraded.

If no policy applies, the result is ungraded—never pass. Policy enforcement starts from an explicit rule.

Six clear result states

colour + symbol + word · never colour alone

✓ pass

Measured and meets policy.

✕ fail

Measured and breaks policy.

! warn

Allowed, but needs attention.

· info

A fact with no judgement.

— unknown

The device could not measure it.

○ not applicable

The control does not exist here.

Evidence-based AI governance: versioned policies, automated policy evaluation, AI risk management, compliance evidence and a traceable decision history.
the record it keeps

What existed in March, and what the rule said then.

Current state is a row that gets overwritten. History is a row that is written only when something actually changed — which is why two years of a fleet is a table you can query rather than an archive you have to restore.

laptop-01 · ai_autonomy · six months
policy v3
policy v4 — unattended agents need a named approver
pass
unknown
fail
!warn
pass
1 Jan12 Mar18 Mar2 Apr21 Apr
17,280scans
Ninety-six a day, for six months. Every one of them collected, graded and acknowledged.
5rows kept
One per transition. The other 17,275 scans agreed with the row already there, so nothing was written.
2policy versions
The March failure is graded against v4 forever, even though v5 has since replaced it.
01

Transitions, not tallies

One row per device and signal holds what is true now. A history row is appended only when the verdict actually changes. "Which devices fail this control" is one index read, not a scan of everything ever collected.

02

Versions do not move

A verdict points at the policy version it was graded against. Changing a rule creates a new version and never rewrites an old finding — so tightening a policy today cannot retroactively make last quarter look worse, or better.

03

The archive is not the database

Yesterday’s evidence is projected and exported to object storage every night. The deployment is the serving layer, not the archive, so long retention lives where long retention is cheap and the live product stays fast.

Retention is a number of days you set, and it is enforced by deletion rather than by filtering: one job expires blobs and metadata past the window, and a separate one erases an organisation that asked to be erased — erasure, not expiry. Every job that could outgrow a single transaction is paginated and self-rescheduling, so a run that dies resumes rather than starts again.

the console

Every view answers one question.

Home, then the devices — Surfaces, Monitoring, Events, Governance — then what feeds it and where its findings go. Every view is a live subscription rather than a refresh button. Two of these sections exist mostly to tell you what is not built yet, and they say so in every row.

console / surfaces / deviceslive
Platform
Admin
what changed, and what did it cost?

Home

Activity and cost across the fleet over time. The first screen after signing in, and the only one that is a summary rather than a list.

ActivitySpend over timeCoverage

Four states exist before any data does — not signed in, no organisation, an organisation not yet provisioned, and the wrong role. The last is rendered as a stated refusal naming the capability, because a blank page reads as a bug and generates a support ticket.

what is out there?

Surfaces 1 planned

Every device as tables you can filter, sort and export. Every row came from a file on a disk — nothing here was declared by anybody.

DevicesMCP serversAccountsCredentialsCloud APIs · planned

Cloud APIs is in the column today and reports no rows, because there is no cloud ingest route yet. It says that, rather than rendering as a company that happens to have no cloud in it.

what is it doing?

Monitoring

Not what exists, but what it is up to — which agents are active, whose account they run on, what they can reach, what they cost, and which machines have gone quiet.

AppsAgentsUsersSpendControls

Spend is priced when it is read, from a price table refreshed daily — so re-pricing history is a read-time concern rather than a migration.

what happened?

Events

The one section that answers what happened rather than what is true now. Four sources merge into one time-ordered feed: a control falling into warn or fail, an unsanctioned tool seen for the first time, a device silent past 24 hours with no pause recorded, and a quarantined snapshot.

FeedCoverage by layerBlocked actions

Coverage is reported per layer, and only the device layer is true. Blocked actions are the guardrails firing on devices: a prompt stopped before it ran, a secret redacted on the way out. Cloud and SDK layers will report here when they ship.

how is it graded, and who owns it?

Governance

Policies and their versions, the framework controls they roll up to, the remediations somebody owns, and the history of both.

PoliciesFramework controlsRemediationsVersion history

A policy version is immutable and a finding names the one it was graded against, so the page can answer what the rule said in March without anybody keeping a copy of March .

where does the data come from?

Instruments 2 planned

Every source that measures your devices, in one catalogue — the device agent that ships, and the cloud and SDK layers that do not.

Device agentCloud connectors · plannedApplication SDKs · planned

This section was called Integrations, alongside another section also called Connections. Two synonyms carried the entire distinction between measuring the devices and receiving findings from it , so a reader hunting for Slack had no way to reason about where to look. The old paths still resolve.

where do findings go?

Integrations 4 planned

The other direction: chat, ticketing, SIEM and warehouses. None of it is built. Every row in the grid says so, with what it will carry when it is.

Chat · plannedTicketing · plannedSIEM · plannedWarehouses · planned

A page of greyed logos is a promise. A page of rows that each state their status is a roadmap, and it is the one somebody can plan against.

who can see what, and for how long?

Settings

A dialog over whichever page you were on, rather than a place you navigate to and have to navigate back from.

Team and rolesRetentionEnrolmentPlan

Three roles, written as a chain so “an admin can do anything a member can” is structurally true rather than separately maintained. Conversation prose stops at admin, and three further gates stand behind that.

The section’s views are listed in the column, not in a tab row on the page — so what a section contains is legible before you arrive rather than after.Settings is a dialog over whichever page you were on, not an eighth place to be.
get started

One device or your whole fleet.

Choose a connection, install the agent and see your first signals in sixty seconds. Start with a claim code or enrol a fleet with one organisation secret. No proxy or network gateway is required.

Step 1 of 3

What do you want to connect?

Start with one path. Every connection joins the same inventory, and you can add the rest later.

Devicemanaged endpoints
Cloudaccount connections · planned
SDKapplication runtimes · planned
one inventory · add more any timeGet started
one machine, or a pilot

A claim code

The agent prints a code and polls. Somebody signed in to the console claims it. No secret has to be distributed to get a first device reporting, which is what makes a sixty-second first device possible.

$ endlayer enroll
claim code HXQ-4M2
waiting… claimed by security@acme.com
a fleet

An organisation secret

Unattended enrolment against a fleet secret you ship with the package. Each device exchanges it once for its own credential, written at 0600 and rotated automatically, with encrypted rotation receipts.

# shipped in the managed config
ENDLAYER_FLEET_SECRET=••••••••
per-device credential, 0600

Or host every part of it yourself.

We run the console for you by default. If that is not allowed where you work, run the same build on your own servers — your hosts, your database, your keys. Nothing about your devices reaches us.

built for teams who cannot send this to a third party
Regulated industries

Banking, health, defence and public sector, where a processor has to be named and approved.

Data residency

Records that must stay in one country, on hardware you can point at.

Air-gapped networks

Networks with no route to the internet at all, by design.

Security review

When the answer to "who else can see this?" has to be nobody.

your network
on every machine
The agent

Reads the device off the disk and posts a snapshot every fifteen minutes — to your console, not to ours.

your servers
The console and backend

The same containers we run in the hosted version. Grading, ownership and history all happen on your hosts.

your database
Every record

Inventory, verdicts, policy versions and the full audit trail, in a database your own DBAs administer.

your boundary ends hereendlayer

nothing crosses that line — no device data, no telemetry, and nothing calling home to ask permission

what you run
Container images
The console, the API and a worker. Whatever already schedules containers for you can schedule these.
what it needs
Postgres, and object storage
No queue to stand up, no search cluster, and no service mesh to configure.
updates
You pull them
Pinned image tags. Nothing updates itself, and nothing phones out to ask whether it should.
air-gapped
Works with no internet
Images arrive as a file you copy in. The agent only ever needs to reach your console.
Talk about a self-hosted installRead the deployment guidesame build as the hosted console · your keys, your database
open source

Surface is open source.

A small free tool — what AI ran on one machine, and what it cost — under Apache 2.0. Read what it collects, what it keeps and how before the platform’s agent goes anywhere near your fleet. It is not the platform.

View Surface on GitHub
what is true today

What ships today, and what does not.

This page has said “planned” in a dozen places. Here is all of it in one place, so nobody has to keep count while reading, and nobody finds out during a demo.

capabilitylayerstatuswhat that means today
Device collectiondevicesbuilt21 signals, one agent on mac, Windows, Linux, iOS, Android, servers and cloud, every fifteen minutes, unelevated.
Ingest, dedupe and redactionplanebuiltAuthenticated, idempotent, redacted before storage, one transaction per snapshot.
The normalised graphplanebuiltDevices, tools, agents, MCP servers, accounts, credentials, repositories, usage — tenant-isolated, and live rather than polled.
Grading and policy versionsplanebuiltImmutable versions; every verdict names the one it was graded against. Unknown and ungraded never become pass.
EnforcementdevicesbuiltAllow, warn, redact, block and require approval, applied where the AI runs. Guardrails in the agent act in real time on every device; removing an installed app waits for an administrator. Every action is recorded against the policy version that caused it.
History and evidence exportplanebuiltTransition-only history, retention enforced by deletion, and a nightly evidence projection to object storage.
The consoleplanebuiltHome, Surfaces, Monitoring, Events, Governance, Instruments, Integrations — with the unbuilt rows saying so.
Fleet deploymentdevicesbuiltNative packages, claim codes and fleet secrets, per-device credentials, managed configuration and a pause.
Cloud connectorscloudplannedRead-only discovery across AI Foundry, Azure endpoints, Bedrock and SageMaker — inventory, exposure, safety configuration, usage and cost. No ingest route exists yet, and the console says so. The same rules and the same enforcement apply to this layer the day it ships.
SDK ingestionappsplannedPython, TypeScript, Rust and Go — model calls, agent runs, tool and MCP calls, with prompts and responses excluded unless explicitly allowlisted. Graded and enforced by the same rules as the device layer from the first call.
Outbound integrationsplaneplannedChat, ticketing, SIEM and warehouses. The catalogue exists in the console and every row states its status.
Self-hostingplaneon requestThe wire protocol is documented with no vendor in it, so the agent can talk to your server. Running the whole product across your company is arranged with us, not a download.

Why the unbuilt rows are on the page at all

All three layers were designed into one model from the start, which is the reason a rule written today will apply to a Bedrock endpoint without being rewritten. Showing only the device layer would hide the reason the device layer looks the way it does.

What that means for an evaluation

Everything you can see in the console today came off a disk in the last fifteen minutes. Judge it on the device layer — that is the part that ships, and it is the part a pilot will actually exercise.

start with endlayer

Take control of the AI already in your company.

It is already installed on the laptops. You can see all of it by this afternoon.

activity4h slices
30d ago22d15d7dnow