Start with what is already happening
endlayer discovers the AI people and agents already use. No survey and no self-reporting are needed to build the first picture.
endlayer is the control plane for AI.
It finds the AI tools, agents, accounts and MCP connections running on your work devices, managed or not, then links each one to a policy, an owner and a record that holds up. The device layer today; cloud and SDK layers planned.
Decisions stay until taken · events from the last 7 days
A gateway only sees traffic you send through it. Desktop apps, coding agents, local models and MCP connections never are — so endlayer starts on the machine.
17 tools recognised: claude code, claude desktop, codex cli, chatgpt desktop, opencode, openclaw, cursor, windsurf, github copilot, aider, goose, gemini cli, amp, cline, continue, ollama, lm studio.
Seventeen tools. Nothing configured. No connector to build, no list to maintain.
Connect your devices once. Surfaces finds what is on them, Monitoring watches what they do, Governance decides what is allowed.
One app on each work device — downloaded, or pushed through Intune, Jamf or SCCM. It finds every AI tool, agent, local model and MCP server on them — you never give it a list to look for.
Which tools are approved, which nobody has decided on, and which nobody approved at all. Who runs them, what they can reach, and what they cost.
Graded against your own policy and against SOC 2, the EU AI Act, ISO/IEC 42001, NIST AI RMF and GDPR. Unapproved tools are flagged, given an owner and tracked to closed, with a record of who decided and when. Guardrails in the agent block in real time; removing an app waits for an administrator.
Three modules, one agent and one snapshot behind all of them. Adding the second and third costs no new integration — they read what the first already collected.
A searchable inventory of what is actually installed — AI apps, coding agents, local models, accounts, credentials and the MCP servers your fleet can reach . Read from files already on the disk.
Not a static asset list. Which tools are sanctioned, undecided or unsanctioned; which agents act unattended; what they reach; what they cost — by tool, model, project, person and machine.
Fifteen kinds of rule, from snapshot cadence to allowed MCP hosts. One immutable policy version per organisation — editing publishes v+1 and re-grades the whole fleet , so a verdict is always readable against the rule that made it.
One agent. One snapshot. Three modules. Monitoring and Governance do not collect anything of their own — they read what Surfaces already found, which is why the second and third modules cost nothing to switch on.
Device evidence becomes inventory, monitoring, policy decisions and an audit-ready record. Nothing sits in the path of your network traffic, and no AI tool is ever executed to inspect it.
AI activity at the source
A lightweight agent reads local signals without executing the AI it discovers.
inventory.graphcontext.timelinepolicy.evaluate()Decisions with proof
endlayer discovers the AI people and agents already use. No survey and no self-reporting are needed to build the first picture.
The same findings power Surfaces, Monitoring and Governance. Switch modules on without collecting everything again.
Every verdict stays linked to the evidence and policy version behind it, so a reviewer can see what happened and why.
Choose how much runs where — from deterministic discovery on every device to classifiers that read a prompt and stop it on the machine that sent it. Every tier follows the same bounded, outbound-only signal path.
Checks on your cadence, jittered so a fleet never arrives in one wave.
Reads approved signals without launching or executing the AI it finds.
Applies the active tier’s capability on the machine or in your environment.
Produces versioned, redacted evidence — facts and decisions with provenance.
Lands on disk first, then leaves through one encrypted outbound route.
Inventories AI tools, local models and MCP servers. Applies deterministic rules the same way every time.
Reads the encrypted stream on the machine that made it. Terminates TLS locally and re-encrypts before anything leaves, so a request can be stopped on the wire. The cleartext never goes anywhere.
Watches agents call each other, and refuses what policy forbids. Blocks the request and applies the rule on the device, against a versioned policy.
That check reports unknown; every other result still completes.
A snapshot stays on disk until every destination accepts it.
endlayer turns the AI and security facts already on a device into one consistent inventory. No vendor API, running tool or network interception is required.
Installed applications, coding agents, local models and browser AI — including whether an agent may act unattended.
Declared servers, their transport, host and reach, and whether a provider key is present — never its value.
Corporate, personal or unknown accounts, and the token and usage records the tools already wrote locally.
Repositories as owner and name, with a bounded data-file inventory — no source code, no prompt content.
Make and OS, management, updates and patch level, encryption, screen lock, firewall, EDR, network, browser and password policy, admin accounts.
The registry keeps growing behind a versioned schema. The categories stay stable, so the inventory does not change shape when support expands.
See all 21 signals →See the open schema →The agent is designed to answer security questions without becoming a surveillance tool. These limits live in the collector, not in an admin setting.
Sensitive values are removed on the endpoint. They never enter endlayer storage.
Credential presence is reported. The value is discarded on the device, before evidence is built.
Repository context is enough. File contents stay untouched.
Prompts, responses and transcripts stay off until an administrator switches them on, and the record says who did, and why.
No proxy, packet capture, payload inspection or gateway.
The agent observes. It never launches what it finds.
No precise location, raw device identity or personal account IDs.
Install on three devices free and the first snapshot lands in a minute. No proxy, no gateway, no connector to build first.
Signals arrive per device. The graph resolves them into entities that exist across devices, accounts, repositories and environments — so a question has one answer, rather than one answer per machine.
Which unmanaged laptops run a coding agent that may act unattended, signed in to a personal account, against a corporate repository?
Enrolment state — not managedby anybody’s MDM.
Default mode and unattended session totals.
Classification — personal, outside the approved domain.
Repository trust — corporate, and the tools that touched it.
Graded, owned and dated. One row a person can be asked about, rather than four dashboards a person has to join by hand.
Every client-facing function resolves the organisation from the verified identity, never from an argument — one function taking an org id as a parameter is a cross-tenant read. A generated test walks the whole API and asserts every function refuses one.
A query is a subscription. A device that reports at 09:15 changes the fleet view at 09:15, with no refresh button, no polling loop and no socket layer written by hand.
endlayer evaluates device evidence against the versioned AI policy in force at that moment. Evidence, policy and verdict stay linked—creating a reproducible AI risk decision and a compliance-ready audit trail.
Coding agents need a named approver before running unattended against corporate repositories.
Graded against policy v4
Owner: platform engineering
State: open
The backend grader is a pure function of evidence and policy. It does not read the clock, database or another device.
If the device cannot measure something, endlayer reports unknown instead of inventing a pass or fail.
If no policy applies, the result is ungraded—never pass. Policy enforcement starts from an explicit rule.
colour + symbol + word · never colour alone
Measured and meets policy.
Measured and breaks policy.
Allowed, but needs attention.
A fact with no judgement.
The device could not measure it.
The control does not exist here.
Current state is a row that gets overwritten. History is a row that is written only when something actually changed — which is why two years of a fleet is a table you can query rather than an archive you have to restore.
One row per device and signal holds what is true now. A history row is appended only when the verdict actually changes. "Which devices fail this control" is one index read, not a scan of everything ever collected.
A verdict points at the policy version it was graded against. Changing a rule creates a new version and never rewrites an old finding — so tightening a policy today cannot retroactively make last quarter look worse, or better.
Yesterday’s evidence is projected and exported to object storage every night. The deployment is the serving layer, not the archive, so long retention lives where long retention is cheap and the live product stays fast.
Retention is a number of days you set, and it is enforced by deletion rather than by filtering: one job expires blobs and metadata past the window, and a separate one erases an organisation that asked to be erased — erasure, not expiry. Every job that could outgrow a single transaction is paginated and self-rescheduling, so a run that dies resumes rather than starts again.
Home, then the devices — Surfaces, Monitoring, Events, Governance — then what feeds it and where its findings go. Every view is a live subscription rather than a refresh button. Two of these sections exist mostly to tell you what is not built yet, and they say so in every row.
Activity and cost across the fleet over time. The first screen after signing in, and the only one that is a summary rather than a list.
Four states exist before any data does — not signed in, no organisation, an organisation not yet provisioned, and the wrong role. The last is rendered as a stated refusal naming the capability, because a blank page reads as a bug and generates a support ticket.
Every device as tables you can filter, sort and export. Every row came from a file on a disk — nothing here was declared by anybody.
Cloud APIs is in the column today and reports no rows, because there is no cloud ingest route yet. It says that, rather than rendering as a company that happens to have no cloud in it.
Not what exists, but what it is up to — which agents are active, whose account they run on, what they can reach, what they cost, and which machines have gone quiet.
Spend is priced when it is read, from a price table refreshed daily — so re-pricing history is a read-time concern rather than a migration.
The one section that answers what happened rather than what is true now. Four sources merge into one time-ordered feed: a control falling into warn or fail, an unsanctioned tool seen for the first time, a device silent past 24 hours with no pause recorded, and a quarantined snapshot.
Coverage is reported per layer, and only the device layer is true. Blocked actions are the guardrails firing on devices: a prompt stopped before it ran, a secret redacted on the way out. Cloud and SDK layers will report here when they ship.
Policies and their versions, the framework controls they roll up to, the remediations somebody owns, and the history of both.
A policy version is immutable and a finding names the one it was graded against, so the page can answer what the rule said in March without anybody keeping a copy of March .
Every source that measures your devices, in one catalogue — the device agent that ships, and the cloud and SDK layers that do not.
This section was called Integrations, alongside another section also called Connections. Two synonyms carried the entire distinction between measuring the devices and receiving findings from it , so a reader hunting for Slack had no way to reason about where to look. The old paths still resolve.
The other direction: chat, ticketing, SIEM and warehouses. None of it is built. Every row in the grid says so, with what it will carry when it is.
A page of greyed logos is a promise. A page of rows that each state their status is a roadmap, and it is the one somebody can plan against.
A dialog over whichever page you were on, rather than a place you navigate to and have to navigate back from.
Three roles, written as a chain so “an admin can do anything a member can” is structurally true rather than separately maintained. Conversation prose stops at admin, and three further gates stand behind that.
Choose a connection, install the agent and see your first signals in sixty seconds. Start with a claim code or enrol a fleet with one organisation secret. No proxy or network gateway is required.
Start with one path. Every connection joins the same inventory, and you can add the rest later.
The agent prints a code and polls. Somebody signed in to the console claims it. No secret has to be distributed to get a first device reporting, which is what makes a sixty-second first device possible.
Unattended enrolment against a fleet secret you ship with the package. Each device exchanges it once for its own credential, written at 0600 and rotated automatically, with encrypted rotation receipts.
We run the console for you by default. If that is not allowed where you work, run the same build on your own servers — your hosts, your database, your keys. Nothing about your devices reaches us.
Banking, health, defence and public sector, where a processor has to be named and approved.
Records that must stay in one country, on hardware you can point at.
Networks with no route to the internet at all, by design.
When the answer to "who else can see this?" has to be nobody.
Reads the device off the disk and posts a snapshot every fifteen minutes — to your console, not to ours.
The same containers we run in the hosted version. Grading, ownership and history all happen on your hosts.
Inventory, verdicts, policy versions and the full audit trail, in a database your own DBAs administer.
nothing crosses that line — no device data, no telemetry, and nothing calling home to ask permission
A small free tool — what AI ran on one machine, and what it cost — under Apache 2.0. Read what it collects, what it keeps and how before the platform’s agent goes anywhere near your fleet. It is not the platform.
This page has said “planned” in a dozen places. Here is all of it in one place, so nobody has to keep count while reading, and nobody finds out during a demo.
| capability | layer | status | what that means today |
|---|---|---|---|
| Device collection | devices | built | 21 signals, one agent on mac, Windows, Linux, iOS, Android, servers and cloud, every fifteen minutes, unelevated. |
| Ingest, dedupe and redaction | plane | built | Authenticated, idempotent, redacted before storage, one transaction per snapshot. |
| The normalised graph | plane | built | Devices, tools, agents, MCP servers, accounts, credentials, repositories, usage — tenant-isolated, and live rather than polled. |
| Grading and policy versions | plane | built | Immutable versions; every verdict names the one it was graded against. Unknown and ungraded never become pass. |
| Enforcement | devices | built | Allow, warn, redact, block and require approval, applied where the AI runs. Guardrails in the agent act in real time on every device; removing an installed app waits for an administrator. Every action is recorded against the policy version that caused it. |
| History and evidence export | plane | built | Transition-only history, retention enforced by deletion, and a nightly evidence projection to object storage. |
| The console | plane | built | Home, Surfaces, Monitoring, Events, Governance, Instruments, Integrations — with the unbuilt rows saying so. |
| Fleet deployment | devices | built | Native packages, claim codes and fleet secrets, per-device credentials, managed configuration and a pause. |
| Cloud connectors | cloud | planned | Read-only discovery across AI Foundry, Azure endpoints, Bedrock and SageMaker — inventory, exposure, safety configuration, usage and cost. No ingest route exists yet, and the console says so. The same rules and the same enforcement apply to this layer the day it ships. |
| SDK ingestion | apps | planned | Python, TypeScript, Rust and Go — model calls, agent runs, tool and MCP calls, with prompts and responses excluded unless explicitly allowlisted. Graded and enforced by the same rules as the device layer from the first call. |
| Outbound integrations | plane | planned | Chat, ticketing, SIEM and warehouses. The catalogue exists in the console and every row states its status. |
| Self-hosting | plane | on request | The wire protocol is documented with no vendor in it, so the agent can talk to your server. Running the whole product across your company is arranged with us, not a download. |
All three layers were designed into one model from the start, which is the reason a rule written today will apply to a Bedrock endpoint without being rewritten. Showing only the device layer would hide the reason the device layer looks the way it does.
Everything you can see in the console today came off a disk in the last fifteen minutes. Judge it on the device layer — that is the part that ships, and it is the part a pilot will actually exercise.
It is already installed on the laptops. You can see all of it by this afternoon.