Skip to content
the surface layer

See the AI running across your devices.

endlayer Surfaces is the device layer of the endlayer control plane for AI. It finds the AI tools, agents, models and connections on every device, and gives the rest of the platform one inventory to work from.

Get startedBook a demoSee what it finds ↓three devices free · reporting in a minute
endlayer|SurfacesOverview
Devices
200
reporting now
AI installs
1,571
apps, agents and models
MCP links
453
declared on devices
Gone quiet
65
no report in 24 h

Live device intake

lon-mbp-218Claude · 4 MCPnow
nyc-win-377Copilotnow
blr-imac-587Cursor · key found1 min
All devices

AI installs by kind

Desktop apps1,102
Coding agents312
Local models157
Inventory

Reporting health

200 reporting65 gone quiet
Reports in the last 15 min184
Map

the Surfaces overview · example devices, not live data

endlayer, in three
Surfaces finds what is on each machine.you are here
Monitoring counts it across the fleet.
Governance decides what is allowed.
why

Your network tools cannot see the laptop.

AI now runs in desktop apps, coding agents, MCP servers and local models. Most of it never crosses the controls you already have.

why you need Surfaces

AI arrives through people, not procurement.

Someone installs a coding agent, points it at a repository and gives it a credential. No inventory, licence report or purchase order shows it.

  • Desktop apps, coding agents, local models, MCP servers
  • None of it crosses your gateway
  • Nothing lists what can act on its own
why the endlayer platform

It answers from the device, and grades honestly.

A small unprivileged agent reports what AI is installed. Surfaces finds it, Monitoring counts it, Governance grades it against your rule.

  • The device reports. Your policy decides
  • Unknown is never counted as a pass
  • Every publish is a version you can export
why we built it

Nothing was looking where the AI runs.

Governance tools document intent. Gateways see traffic. The AI that matters moved onto laptops: coding agents, local models, MCP servers.

  • We are an AI governance company
  • Customers could not say what AI ran on their machines
  • So we built a control plane for the device
AI gateway

Sees calls that route through it. A coding agent on a laptop does not.

sees routed traffic
CASB

Has a connector per sanctioned SaaS app. There is no connector for MCP.

sees connected apps
Device management

Inventories installed software. It cannot tell you an agent runs unattended.

sees installed software
SSO

Show corporate logins. The work happening on a personal account is absent.

sees corporate logins
how it works

Connect a device. The inventory builds itself.

Install one small agent. Surface reads a fixed set of device facts, organises what it finds and keeps the inventory up to date.

01

Connect your devices

Start with one laptop or deploy the agent through device management.

about one minute to first report
02

Read the device facts

The agent checks approved signals for AI tools, agents, models and connections.

no secret values or work content
03

Build the AI inventory

Surface connects every discovery to the device that reported it.

no seed list or per-tool connector
04

Keep it current

New reports add findings, update access and show devices that have gone quiet.

one current view of every device
start with surfaces

Find out what is on your devices before anyone has to ask.

Connect three devices free and see the first inventory in a minute. No list to give it, no integration to build.

what you get

Device reports become one AI inventory.

Once connected, Surface shows devices, shadow AI, agents and external access in one place. Open any finding to see the evidence behind it.

01

Laptops and devices

Know which devices are reporting and which have gone quiet.

200devices reporting now
macOS142 active
Windows46 active
Linux12 active
Stopped reporting65 devices
02

AI tools, websites and local models

Find sanctioned and shadow AI without asking people to maintain a list.

Desktop AI87
Coding tools61
Browser AI48
Local models28
03

AI agents and autonomy

See the agents present and whether they are allowed to act unattended.

Claude Code42 devices
Codex CLI11 devices
Cursor agentunattended
04

MCP servers and cloud access

Map the services a device can reach and whether credentials are present.

deviceGitHub API · keyFigma MCPAWS · credential
05

New activity and changes

Track when a device reports, a tool appears, access changes or coverage disappears.

see it working

One inventory for all your devices.

Devices, MCP servers and reporting coverage in one console. Every view starts from the same device snapshot.

endlayer/Surfaces · Devices
inventory
DevicePlatformStatusPassingFailingUnevaluatedAgentLast report
lon-mbp-900d3d3d3d36769…macOS 26.5.2active7000.0.95 hours ago
blr-imac-587d3d3d3d3d437…macOS 26.4.1active5200.1.05 hours ago
nyc-imac-534d3d3d3d373f0…macOS 26.4.1active4110.1.05 hours ago
nyc-win-377d3d3d3d35b57…Windows 10.0.19045active5100.1.05 hours ago
osl-mba-312d3d3d3d369e5…macOS 26.5.2active7000.1.15 hours ago

1–5 of 200 · the device name is a hash, because no user identity exists in the product

External MCP hosts
3
reachable from devices
With credentials
3
can act as the user
Connections
453
across all devices
HostFleet reachCredentialedTransport
api.figma.com154 devices154 holding a credentialhttp
api.github.com153 devices153 holding a credentialhttp
sentry.io146 devices146 holding a credentialhttp

local stdio servers are left out on purpose · the off-device ones are the exfiltration surface · declared, never dialled

Reporting regions
15
time-zone level only
Largest region
UTC+3
31 devices
Quiet regions
1
no recent report
UTC+331 quiet
UTC+427 devices
UTC+719 devices
UTC−422 devices
UTC−514 devices
UTC+512 devices
UTC−69 devices
+8 more66 devices
counts only · no coordinate finer than a time zone
one device

Open a device and see what it can reach.

Each row connects the machine to its AI tools, accounts and MCP servers. Every action keeps its reason and its limit.

lon-mbp-900 · macOS 26.5.2 · agent 0.0.9
Controls passing7 of 7
Last report5 hours ago
Projects seen11 repositories
MCP servers reachable4 · 2 credentialed
Web AI usagecollector off
Identityhashed · no user record
Approve device
Only on a device that is still pending. An unapproved machine reports nothing.
Pause collection
Needs a duration and a written reason — and the reason is shown to the person using the device.
Remove device
Destructive, needs a reason, and says so plainly: revoking is not the same as releasing the machine.

“collector off” is a different answer from “no sites” · the console never conflates the two

the device agent

It reads the facts, not the work.

Twenty-one small signals describe the AI running on each device. The agent never runs a tool, reads a secret or changes the network.

collected
  • +Which AI tools and coding agents are installed, and whether they can act unattended
  • +Which MCP servers a machine can reach, and whether they hold a credential
  • +Whether a provider key sits in a file — that it exists, and where
  • +Corporate versus personal account, token usage and cost
  • +Encryption, screen lock, firewall and patch level on the same machine
never collected
  • The value of any key or secret. Presence and location only.
  • Application payloads. Metadata, not content.
  • Prompts and transcripts, unless an admin turns them on with a reason.
  • Any location finer than a time zone. The fleet map is counts, never coordinates.
  • Anything requiring elevated privileges. It runs as the person using the machine.
21
signals read on every device
3.0MB
the whole agent
3
platforms, one binary
0
changes to your network
how to get it

Start with one laptop, then deploy everywhere.

Install the same small agent on macOS, Windows and Linux. No proxy, new network route or elevated access.

Read the install guidefirst device reporting in about a minute
Agent size3.0 MB
PlatformsmacOS · Windows · Linux
Privilegessigned-in user
one signed package
3.0 MB

The Surface device agent

One small package, configured once and deployed through the tools you already use.

choose a platformjoins the same inventory
MAC

macOS

Universal signed package

reporting
WIN

Windows

x64 and arm64 devices

reporting
LNX

Linux

Debian and RPM packages

reporting
MDM

Managed rollout

Push through Microsoft Intune

same setup
No network changes requiredNo gateway in the traffic pathNo elevated access on the device

Connect beyond the device

Add cloud and application sources when you need a wider view.

Cloud accounts

Amazon Web ServicesMicrosoft AzureGoogle Cloud
same inventory →

Application runtimes

PythonNodeRustGo
same inventory →
how it connects to Monitoring and Governance

Surfaces starts the platform.

Three questions, answered in order. Surfaces measures. Monitoring counts. Governance decides.

01 · surfaces

Surfaces

What is on this machine?

One row per device. Finds the AI tools, agents, models and keys on each one.

02 · monitoring

Monitoring

What is out there, across all of them?

One row per tool across the fleet: who has it, what it reaches, whether it is approved, what it costs.

Read about Monitoring →
03 · governance

Governance

What should be allowed?

The rules every device is graded against, with a version on every decision.

Read about Governance →
One machineSurfaces finds Codex CLI on a laptop.
The fleetMonitoring shows it on 24 devices, undecided.
A decisionGovernance publishes v14: Codex CLI disallowed.
The regrade24 devices fail on their next report. Events lists them.
The proofHistory has v14, who and when. The pack cites it.
common questions

Common questions.

We already have an AI gateway.

Then you can see everything that goes through it. A coding agent on a laptop, a desktop app, an MCP server and a local model do not — they never touch the gateway. Surfaces reads them off the disk instead, so the two do not overlap.

Our endpoint tool already inventories software.

It can tell you Cursor is installed. It cannot tell you whether Cursor is allowed to act unattended, which MCP servers it can reach, or whether one of them holds a credential. Autonomy and reach are the facts that matter, and they live in config files, not in an app list.

Is this employee surveillance?

No, and the product is built so you do not have to take our word for it. Devices are hashed and there is no user record. Location stops at the time zone. Key values are discarded. Prompts are off unless an admin turns them on with a written reason — and pausing a device shows that reason to the person using it.

Could we not do this in a spreadsheet?

Only if someone already knew what to look for, on every machine, every week. The point is the opposite: it finds what nobody wrote down, and it is a day old at most rather than a quarter old.

Will installing it disrupt people?

It is a 3 MB unprivileged binary that reads files the signed-in user can already open, and it never executes anything it finds. Nothing changes on your network — no proxy, no gateway, no route.

What if we use a tool you do not recognise?

It still appears, as an unidentified AI process with the machine and the account attached. Naming it properly is a signature, not an integration — so there is no per-tool work for you either way.

start with endlayer

Take control of the AI already in your company.

It is already installed on the laptops. You can see all of it by this afternoon.

activity4h slices
30d ago22d15d7dnow