Skip to content

Holistic AI EndLayer Guardian Agents for AI.

One agent on every device. It finds the AI your company runs and stops unsafe prompts and secrets before they leave the machine.

one agent · one laptop reporting in a minute

surfaces ·monitoring ·governance ·
pass ·warn ·serious ·fail ·
what you get

Find the AI nobody signed off on, see the risk it carries, and enforce your policy where it runs.

01 · Surface

Shadow AI, found

Every AI app, coding agent, MCP server, local model and AI website on every laptop, including the ones IT never approved. The list builds itself in fifteen minutes.

02 · Monitor

Risk you can point to

Personal logins on work tools, API keys left in files, agents allowed to act on their own. Each one comes with a person, a machine and what it costs.

03 · Govern

Policy that holds

Write your rules once and every device is checked against them. Unsafe prompts and secrets are blocked before they leave the laptop, and every failure gets an owner.

why

Your people already use AI. Nobody can tell you what it reaches.

Each tool arrived on one laptop, and nobody wrote it down.

your AI inventory, todaynot zero, just unknown
shadow AI
AI tools running across the fleetunknown
MCP servers carrying credentialsunknown
risk
Work happening on personal accountsunknown
Spend on tokens last monthunknown
policy
Which tools were ever approvedno record
Evidence you could hand an auditorno record
how it works

One agent on the device. Nothing on your network.

21signals on every device

Including whether a coding agent may act unattended. All 21 →

15minutes between snapshots

A tool installed at 9:00 is in the inventory by 9:15.

7platforms, one agent

Mac, Windows, Linux, iOS, Android, servers and cloud.

0admin rights needed

It runs as the user and never elevates.

layer by layer

Control your AI, layer by layer.

Each layer works on its own. One agent feeds all six.

01

Discover

no integration

Know what is actually running.

read from files on the disk, never executed

  • Apps, coding agents, MCP servers and local models
  • Accounts and API keys, including the key in a dotfile
  • Found without an integration to install first
87 tools
what one scan returns
02

Inventory

one record

Turn every report into one record.

macOS, Windows, Linux, servers and cloud

  • One row per tool, with its version and autonomy level
  • Sanctioned, undecided or unsanctioned, per tool
  • Machines that go quiet are surfaced, not assumed healthy
1,231 machines
the fleet, as it reports
03

Access

blast radius

See what each one can reach.

declared, never dialled

  • Every MCP server, and whether it carries a credential
  • Repositories and projects inside an agent’s scope
  • Whose account each tool runs on, work or personal
312 MCP servers
one agent’s reach
04

Spend

attributed

Know what it costs before the invoice.

by tool, person and project

  • Token usage attributed to the team that caused it
  • Which tools the money is actually going to
  • Priced from a versioned table, so every figure can be traced
$18.4k / 30d
spend by project
05

Guardrails

real time

Act at the moment it happens.

inside the agent, on the device

  • Prompts scored before they run
  • Secrets and personal data redacted on the way out
  • The matched text never leaves the machine
warn · redact · block
the prompt path
06

Govern

the record

Grade it, and keep the proof.

every publish is a version

  • Nineteen rules, graded on every device within fifteen minutes
  • A failure gets an owner, a state and a date it closed
  • An exportable record for SOC 2, EU AI Act, ISO/IEC 42001, NIST AI RMF
9 of 19 rules on
policy v4

Surface · Monitor · Govern

what it finds

Every kind of AI on the machine.

Pick one to see what the agent reads.

Coding agents

They write and run code on the machine, sometimes without being watched.

what is invisible

The permission mode nobody reviewed, the MCP servers it can reach, and which repositories are in its scope. None of it crosses a gateway.

what it reads

The agent's own configuration, in the user's home directory.

settings file · permission mode · MCP clients · repo scope
laptop-01 · claude-coderead 09:15
how it runs
permission modeacceptEditsunattended
last active4 min ago
what it reaches
MCP servers42 carry creds
repositories in scope11
fleet · Claude Code 412 devices · Cursor 388 · GitHub Copilot 244

Desktop AI apps

The chat window that never goes through your network.

what is invisible

Which account it is signed in on. Corporate work runs through somebody's personal ChatGPT and Claude login, over TLS to a domain you already allow.

what it reads

Installed applications, and the account each one is signed in as.

.app / .exe · signed in account · last active
laptop-04 · ChatGPT Desktopread 09:15
identity
signed in account@gmail.compersonal
corporate SSOnot used
standing
graded against policyv4unsanctioned
last activetoday
fleet · ChatGPT Desktop 261 devices · Claude Desktop 173

MCP servers

The connectors that hand an agent your credentials.

what is invisible

They are declared in a client's config file and carry tokens off the device, and no CASB has a connector for them.

what it reads

The client config files that declare them. Declared, never dialled.

server name · transport · credentials
laptop-01 · 4 servers declaredread 09:15
transport, across the fleet
stdio, on device271
http, off device41
credentials
carries a credential41 of 312leaves the device
URLs and env valuesnever recorded
fleet · 312 declared · Cursor 134 · Claude Code 96 · VS Code 44

Local models

A model running on the laptop. No invoice, no log, no gateway.

what is invisible

It runs entirely on the device, so nothing you bill against will ever show that it existed. And nothing in the path can see it.

what it reads

The runner on disk, the models it has pulled, and the port it listens on.

runner · pulled models · listen address
laptop-07 · ollamaread 09:15
on disk
models pulled7 · 41 GB
listening127.0.0.1:11434
cost
tokens counted2.1M
invoicenoneunpriced
fleet · Ollama and LM Studio 96 devices · none of it invoiced

Browser AI

The extension and the side panel that read the page you are on.

what is invisible

Extensions install per browser profile, ask for permission once, and are never inventoried again.

what it reads

Extension manifests, per profile, and what each one declares it can see.

extension · profile · declared host access
laptop-02 · Chrome, profile 2read 09:15
extensions
AI extensions3
can read page contents2broad
scope
profilepersonalsigned in
declared host accessall sites
fleet · AI extensions on 188 devices · 61 read page contents

Keys and accounts

A provider key in a file git is not ignoring.

what is invisible

Keys sit in project .env files and in shell profiles. One of them is one push away from public.

what it reads

Presence and location only. The value is discarded before evidence is built.

file path · exposure · never the value
fleet · keys found in filesread 09:15
where they are
project .env38
shell profile21
exposure
visible in the repo24one push from public
store the tool managesnever opened
fleet · 64 machines carry a key in a file · 40 local only
all seventeen, recognised by nameno connector for any of them
Claude CodeCursorGitHub CopilotCodex CLIWindsurfAiderClineContinueOpenCodeAmpGooseGemini CLIOpenClawChatGPT DesktopClaude DesktopOllamaLM Studio
at any size

One laptop, or fifty thousand.

How you start depends on how big you are. What you get does not.

Just me · Download it and run it
Installing it
Download it and run it.
Switching it on
Click Connect this device, then accept it yourself.
What you look at
One device, and everything on it.
Installing it
Everyone downloads it, or you send them a link.
Switching it on
Each person clicks Connect. You accept them.
What you look at
A list short enough to read top to bottom.
Installing it
Push it out with the tools you already use for laptops.
Switching it on
One shared secret. Nobody has to click anything.
What you look at
What needs fixing, rather than everything that exists.
Installing it
The same push, released in waves.
Switching it on
The same secret and the same settings, for every wave.
What you look at
What changed since yesterday.

no minimum number of people · no charge per tool connected · nothing in the path of your traffic

how to get it

Three ways in.

01hosted

Log in and use it now.

Sign up, install the agent, and the first device reports in a minute.

Get started →
02your infrastructure

Or run it on your own servers.

Nothing about your devices leaves your network.

How that works →
03open source

A small free tool.

What AI ran on one machine, and what it cost. Not the platform.

Open source ↗
the first minute

Sixty seconds, then it is reporting.

laptop-01 · zsh
$ endlayer enroll
enrolment code 4F2K-9QX1
waiting for an organisation to accept…
accepted · credential stored 0600 · org set by the approver
$ endlayer doctor
config /etc/endlayer/endlayer.toml
ignored none
delivery reachable · next scan in 847s
$ first snapshot delivered
21 signals · 3 pass · 2 warn · 3 fail · 13 info

that was one laptop · the same thing runs on five thousand

common questions

The seven we are asked first.

What is EndLayer?

EndLayer is Guardian Agents for AI. One agent, the Layer 1 Agent, runs on every device with no admin rights and no proxy or gateway. It finds shadow AI (every tool, coding agent, model, MCP server, account and API key in use), shows the risk each one carries and what it costs, and checks all of it against the policy you publish. Guardrails in the agent warn, redact or block as it happens. Surface, Monitor and Govern are the three modules, and EndLayer is a product of Holistic AI.

Does it read our conversations?

Yes, for PII leaking into a prompt, and for tools being used in ways nobody authorised. It is not on by default, and turning it on records who enabled it and the reason why. Your admin can narrow what is collected at any time, and the agent cannot widen it.

Do we have to put a proxy or gateway in the path?

No. Nothing changes on your network. Everything is read from files already on the disk, which is also why desktop apps, coding agents and local models show up at all. none of them go through a gateway.

Does the agent need admin rights?

No. It runs as the person using the machine and reads only what that account can already read. It never elevates, and it never executes any of the AI tools it finds.

What if we use a tool that is not on your list?

Seventeen are recognised by name. Anything else still surfaces as an unidentified AI process with the account and the machine attached, and naming it properly takes a signature, not an integration, so there is no work per tool for you either way.

How quickly does something new appear?

Within fifteen minutes. Every device sends a snapshot every fifteen minutes, so a tool installed at 9:00 is in the inventory by 9:15.

Can it block anything, or does it only watch?

Both. Every signal is measured against your policy version, and what fails gets an owner, a state and a date it closed. Guardrails inside the agent act on the device in real time: prompts are scored before they run, and secrets and personal data are warned on, redacted or blocked on the way out. Removing an installed app is the one action that waits for a person: an administrator approves the request before anything is uninstalled. Every action is recorded.

start with EndLayer

Take control of the AI already in your company.

It is already installed on the laptops. You can see all of it by this afternoon.

activity4h slices
30d ago22d15d7dnow