Surface · Monitor · Govern

The control plane for AIon every device you run.

Endlayer surfaces every AI tool, agent, model and MCP server your people actually use, monitors what each one reaches and costs, and governs all of it against a versioned policy. One agent on the device. No proxy, no gateway, no connector per tool.

Runs on macOS, Windows, Linux and cloud · reporting within fifteen minutes of install

One agent · three modulessurfacegovern01what exists02how it behaves03is it allowedSurface21 signalsMonitor15 minGovern19 rulesOne binary reads the disk. Three views of what it finds.filled = graded · dashed = not yet graded · no proxy, no gatewayThree modules · one plane
21
signals per device
15 min
snapshot cadence
3 MB
agent, no dependencies
19
governance rules
5
frameworks mapped
The problem

Your people already use AI. Nobody knows what it can reach, or what it does.

Every tool arrived the same way: one person, one laptop, one Tuesday. Nothing was recorded, so nothing can be seen, attributed or proved — and none of it crosses the network controls you already own.

01 — INVISIBLE

You cannot see what is there

Desktop apps, coding agents and local models run on the machine and never touch the gateway. Provider keys sit in shell profiles and in .env files git is not ignoring. MCP servers carry credentials off the device, and no CASB has a connector for them.

So the AI inventory does not exist.
02 — UNTRACKED

So you cannot see what it does

Agents act unattended, in permission modes nobody reviewed. Corporate work runs through somebody's personal ChatGPT and Claude logins. Tokens are spent on the laptop; the invoice arrives monthly and aggregated.

So none of it can be attributed.
03 — UNPROVABLE

So you cannot answer for it

The EU AI Act, ISO/IEC 42001, NIST AI RMF and SOC 2 all ask the same first question: which AI systems do you operate, and who owns each one. A spreadsheet assembled by hand is out of date the day it is signed.

So the evidence is an assertion, not a record.
What Endlayer is

Endlayer surfaces every AI running on your machines, monitors what it touches, and governs it against your policy.

One unprivileged agent on the device feeds all three modules. There is no connector to build, no proxy in the path and no gateway to route through. Everything is read from files already on the disk.

How it works

Live in days — four steps from install to evidence

The same four steps whether you are one laptop or fifty thousand.

1

Connect

A local, unprivileged agent installs through the fleet tooling you already run. It reads what the device user can already read, and never elevates.

Intune · Jamf · SCCM
2

Surface

Every AI app, coding agent, local model, MCP server, account, credential and AI site appears on its own — without anyone being asked to declare it.

macOS · Windows · Linux · cloud
3

Monitor

What each tool reaches, whose account it runs on, which repositories it sees, how far it can act alone, and what it costs — by tool, model, project and person.

21 signals · every 15 minutes
4

Govern

Every signal graded against an immutable policy version. What fails gets an owner, a state and a close date, and the verdict is kept beside the rule that made it.

policies · remediations · history
No proxy in the path
No gateway to route through
No connector per tool
The agent never executes the AI tools it finds
The platform

Three modules, one agent, one record

Surface, Monitor and Govern are the same data at three depths — an inventory, a behaviour picture, and a graded record you can hand to an auditor.

01 — SURFACE

Every AI tool, agent and MCP server on your devices

A searchable inventory of what is actually installed: AI apps, coding agents, local models, accounts, credentials and the MCP servers your fleet can reach. Shadow AI discovery without asking anyone.

DevicesMapMCP serversCloud APIsDevice detail
One machineclaim code
Fleet installone org secret
AWS · Azure · GCP · SDKsconnect an account
Read from files already on the disk
02 — MONITOR

What each one does, who runs it, and what it costs

Not a static asset list. Which tools are sanctioned, undecided or unsanctioned; which agents act unattended; what they reach; what they cost — by tool, model, project, person and machine.

OverviewAppsAgentsCost by deviceToken costActivity log
New integration needednone
Cost attributed totool, project, person, machine
Unpriced modelsshown, never folded in
One row per tool, across the fleet
03 — GOVERN

Graded against your rules, and the frameworks you report on

Nineteen rules, each with a switch: which tools are approved, what an agent may do alone, which MCP hosts it may reach, and what may leave in a prompt. Publish, and every device is re-graded within fifteen minutes.

PoliciesRegulationsRemediationsHistory
Policy versionsimmutable
Unevaluated controlsnever a pass
What failsowner and a close date
Guardrails in the agent act in real time
The agent

One agent, three weights — deployed to the devices that need them

Every tier runs on the device and none of them runs a language model. Sensor is deterministic; Decoder and Guardian add classifiers and act in the path on the machine itself. Nothing decrypted ever leaves the device.

Sensor

3 MB
Every device
Finds what a network never will.

One binary. No runtime, no dependencies, no model. It inventories every AI tool, local model, agent, extension and MCP server on the machine, and the AI sites it reaches, then grades all of it against deterministic policy.

  • Complete local AI inventory
  • Shadow AI discovery
  • MCP server detection
  • Deterministic policy, offline

Decoder

30 MB
Devices sending AI traffic
The encrypted stream, readable on the machine that made it.

A local gateway, not a network one. Decoder terminates TLS on the device, so a prompt is readable at the moment it is sent, and re-encrypts it before it goes anywhere. That is what makes a real-time block possible.

  • Local TLS gateway
  • Blocks a request in real time
  • Decrypted text stays on the device
  • Everything in Sensor

Guardian

300 MB
Devices running agents
It watches agents talk to each other.

Guardian sits where agents meet. It sees one agent call another, an agent reach an MCP server, or a tool ask for a permission it was never granted — and it blocks the request and applies the rule on the device, as it happens.

  • Agent-to-agent detection
  • Blocks a request as it happens
  • MCP call inspection
  • Versioned decision record
Guardrails in the agent warn, redact or block in real time
Removing an installed app waits for an administrator to approve it
What it reads

Twenty-one signals, read on every device, every fifteen minutes

The same list drives the inventory, the monitoring rows and the governance grade. A tool installed at 09:00 is in the inventory by 09:15.

Tools & agents
What AI is installed, and whether it can act alone.
  • Tools and agents ai_tooling
  • Autonomy ai_autonomy
Apps & web
The wider software picture, and AI reached through a browser.
  • AI web usage ai_web_usage
  • Installed software installed_software
MCP & access
What the tools can reach, and what they hold to reach it.
  • MCP servers mcp_servers
  • Credentials ai_credentials
Accounts & spend
Whose account it runs on, and what it is costing.
  • Accounts ai_accounts
  • Usage and spend ai_usage
Projects & data
Which repositories and data files the tools have touched.
  • Projects and data ai_projects
The device
What the machine is, and whether anybody manages it.
  • Device facts device_facts
  • Fleet enrolment mdm_enrollment
  • Automatic updates auto_updates
  • Patch level os_patch_level
Security posture
The controls a security team already asks about — verified, never modified.
  • Disk encryption disk_encryption
  • Screen lock screen_lock
  • Firewall firewall
  • Endpoint protection edr_present
  • Network posture network_posture
  • Browser policy browser_policy
  • Password policy password_policy
  • Admin accounts admin_accounts
Evidence

Governance becomes infrastructure, not a bottleneck

Each rule is mapped to the clauses it satisfies, so the record you already produce is the record an assessor asks for.

EU AI Act
Article 4 & 26 obligations on the device layer
ISO/IEC 42001
AI management system controls
NIST AI RMF
Govern and Map functions
SOC 2
Change and access evidence
GDPR
Data paths and personal data in prompts
Immutable versions
Publishing a change inserts v+1 and re-grades the whole fleet. A verdict is always readable against the rule that produced it.
Nothing unevaluated passes
A control that was never measured is reported as unevaluated, never as a pass.
An owner and a close date
What fails is assigned, tracked through its states, and every transition is retained.
Exportable record
The grade, the rule version, the device and the timestamp — handed over as evidence, not as an assertion.
Deployment

One laptop, or fifty thousand

How you start depends on how big you are. What you get does not.

01 Pilot

Start with a pilot group

Install on a handful of machines and see what comes back within the hour.

Get started →
02 Your infrastructure

Or run it on your own servers

Nothing about your devices leaves your network.

Talk to us →
03 Fleet rollout

Push it out in waves

One shared secret and the same settings for every wave, through Intune, Jamf or SCCM. Nobody has to click anything.

See a rollout →
Questions

What buyers ask first

Do we have to put a proxy or gateway in the path?
No. Nothing changes on your network. Everything is read from files already on the disk, which is also why desktop apps, coding agents and local models show up at all — none of them go through a gateway.
Does the agent need admin rights?
No. It runs as the person using the machine and reads only what that account can already read. It never elevates, and it never executes any of the AI tools it finds.
Does it read our conversations?
Only for personal data leaking into a prompt, and for tools being used in ways nobody authorised. Where Decoder terminates TLS, it does so on the device and the decrypted text never leaves the machine.
Can it block anything, or does it only watch?
Both. Every signal is measured against your policy version, and what fails gets an owner, a state and a date it closed. Guardrails inside the agent act on the device as it happens: prompts are scored before they run, and secrets and personal data are warned on, redacted or blocked on the way out. Removing an installed application waits for an administrator to approve it.
What if we use a tool that is not on your list?
Seventeen are recognised by name. Anything else still surfaces as an unidentified AI process with the account and the machine attached, and naming it properly takes a signature, not an integration.
How quickly does something new appear?
Within fifteen minutes. Every device sends a snapshot every fifteen minutes, so a tool installed at 09:00 is in the inventory by 09:15.
Book a demo

See what AI is running in your organisation

Thirty minutes, your own questions, and a walk through the console on a live demo fleet. Bring the device population you care about and we will show you what Endlayer finds on it.

  • A walkthrough of Surface, Monitor and Govern
  • The 21 signals, and exactly what each one reads
  • How the nineteen rules map to your frameworks
  • A rollout plan for your fleet tooling