Live device intake
See the AI running across your devices.
endlayer Surfaces is the device layer of the endlayer control plane for AI. It finds the AI tools, agents, models and connections on every device, and gives the rest of the platform one inventory to work from.
AI installs by kind
Reporting health
the Surfaces overview · example devices, not live data
Your network tools cannot see the laptop.
AI now runs in desktop apps, coding agents, MCP servers and local models. Most of it never crosses the controls you already have.
AI arrives through people, not procurement.
Someone installs a coding agent, points it at a repository and gives it a credential. No inventory, licence report or purchase order shows it.
- Desktop apps, coding agents, local models, MCP servers
- None of it crosses your gateway
- Nothing lists what can act on its own
It answers from the device, and grades honestly.
A small unprivileged agent reports what AI is installed. Surfaces finds it, Monitoring counts it, Governance grades it against your rule.
- The device reports. Your policy decides
- Unknown is never counted as a pass
- Every publish is a version you can export
Nothing was looking where the AI runs.
Governance tools document intent. Gateways see traffic. The AI that matters moved onto laptops: coding agents, local models, MCP servers.
- We are an AI governance company
- Customers could not say what AI ran on their machines
- So we built a control plane for the device
Sees calls that route through it. A coding agent on a laptop does not.
Has a connector per sanctioned SaaS app. There is no connector for MCP.
Inventories installed software. It cannot tell you an agent runs unattended.
Show corporate logins. The work happening on a personal account is absent.
Connect a device. The inventory builds itself.
Install one small agent. Surface reads a fixed set of device facts, organises what it finds and keeps the inventory up to date.
Connect your devices
Start with one laptop or deploy the agent through device management.
about one minute to first reportRead the device facts
The agent checks approved signals for AI tools, agents, models and connections.
no secret values or work contentBuild the AI inventory
Surface connects every discovery to the device that reported it.
no seed list or per-tool connectorKeep it current
New reports add findings, update access and show devices that have gone quiet.
one current view of every deviceFind out what is on your devices before anyone has to ask.
Connect three devices free and see the first inventory in a minute. No list to give it, no integration to build.
Device reports become one AI inventory.
Once connected, Surface shows devices, shadow AI, agents and external access in one place. Open any finding to see the evidence behind it.
Laptops and devices
Know which devices are reporting and which have gone quiet.
AI tools, websites and local models
Find sanctioned and shadow AI without asking people to maintain a list.
AI agents and autonomy
See the agents present and whether they are allowed to act unattended.
MCP servers and cloud access
Map the services a device can reach and whether credentials are present.
New activity and changes
Track when a device reports, a tool appears, access changes or coverage disappears.
One inventory for all your devices.
Devices, MCP servers and reporting coverage in one console. Every view starts from the same device snapshot.
| Device | Platform | Status | Passing | Failing | Unevaluated | Agent | Last report |
|---|---|---|---|---|---|---|---|
| lon-mbp-900d3d3d3d36769… | macOS 26.5.2 | active | 7 | 0 | 0 | 0.0.9 | 5 hours ago |
| blr-imac-587d3d3d3d3d437… | macOS 26.4.1 | active | 5 | 2 | 0 | 0.1.0 | 5 hours ago |
| nyc-imac-534d3d3d3d373f0… | macOS 26.4.1 | active | 4 | 1 | 1 | 0.1.0 | 5 hours ago |
| nyc-win-377d3d3d3d35b57… | Windows 10.0.19045 | active | 5 | 1 | 0 | 0.1.0 | 5 hours ago |
| osl-mba-312d3d3d3d369e5… | macOS 26.5.2 | active | 7 | 0 | 0 | 0.1.1 | 5 hours ago |
1–5 of 200 · the device name is a hash, because no user identity exists in the product
| Host | Fleet reach | Credentialed | Transport |
|---|---|---|---|
| api.figma.com | 154 devices | 154 holding a credential | http |
| api.github.com | 153 devices | 153 holding a credential | http |
| sentry.io | 146 devices | 146 holding a credential | http |
local stdio servers are left out on purpose · the off-device ones are the exfiltration surface · declared, never dialled
Open a device and see what it can reach.
Each row connects the machine to its AI tools, accounts and MCP servers. Every action keeps its reason and its limit.
“collector off” is a different answer from “no sites” · the console never conflates the two
It reads the facts, not the work.
Twenty-one small signals describe the AI running on each device. The agent never runs a tool, reads a secret or changes the network.
- +Which AI tools and coding agents are installed, and whether they can act unattended
- +Which MCP servers a machine can reach, and whether they hold a credential
- +Whether a provider key sits in a file — that it exists, and where
- +Corporate versus personal account, token usage and cost
- +Encryption, screen lock, firewall and patch level on the same machine
- −The value of any key or secret. Presence and location only.
- −Application payloads. Metadata, not content.
- −Prompts and transcripts, unless an admin turns them on with a reason.
- −Any location finer than a time zone. The fleet map is counts, never coordinates.
- −Anything requiring elevated privileges. It runs as the person using the machine.
Start with one laptop, then deploy everywhere.
Install the same small agent on macOS, Windows and Linux. No proxy, new network route or elevated access.
The Surface device agent
One small package, configured once and deployed through the tools you already use.
macOS
Universal signed package
Windows
x64 and arm64 devices
Linux
Debian and RPM packages
Managed rollout
Push through Microsoft Intune
Connect beyond the device
Add cloud and application sources when you need a wider view.
Cloud accounts
Application runtimes
Surfaces starts the platform.
Three questions, answered in order. Surfaces measures. Monitoring counts. Governance decides.
Surfaces
One row per device. Finds the AI tools, agents, models and keys on each one.
Monitoring
One row per tool across the fleet: who has it, what it reaches, whether it is approved, what it costs.
Read about Monitoring →Governance
The rules every device is graded against, with a version on every decision.
Read about Governance →Common questions.
We already have an AI gateway.
Then you can see everything that goes through it. A coding agent on a laptop, a desktop app, an MCP server and a local model do not — they never touch the gateway. Surfaces reads them off the disk instead, so the two do not overlap.
Our endpoint tool already inventories software.
It can tell you Cursor is installed. It cannot tell you whether Cursor is allowed to act unattended, which MCP servers it can reach, or whether one of them holds a credential. Autonomy and reach are the facts that matter, and they live in config files, not in an app list.
Is this employee surveillance?
No, and the product is built so you do not have to take our word for it. Devices are hashed and there is no user record. Location stops at the time zone. Key values are discarded. Prompts are off unless an admin turns them on with a written reason — and pausing a device shows that reason to the person using it.
Could we not do this in a spreadsheet?
Only if someone already knew what to look for, on every machine, every week. The point is the opposite: it finds what nobody wrote down, and it is a day old at most rather than a quarter old.
Will installing it disrupt people?
It is a 3 MB unprivileged binary that reads files the signed-in user can already open, and it never executes anything it finds. Nothing changes on your network — no proxy, no gateway, no route.
What if we use a tool you do not recognise?
It still appears, as an unidentified AI process with the machine and the account attached. Naming it properly is a signature, not an integration — so there is no per-tool work for you either way.
Take control of the AI already in your company.
It is already installed on the laptops. You can see all of it by this afternoon.