Discover
no integrationKnow what is actually running.
read from files on the disk, never executed
- Apps, coding agents, MCP servers and local models
- Accounts and API keys, including the key in a dotfile
- Found without an integration to install first
One agent on every device. It finds the AI your company runs and stops unsafe prompts and secrets before they leave the machine.
one agent · one laptop reporting in a minute
Every AI app, coding agent, MCP server, local model and AI website on every laptop, including the ones IT never approved. The list builds itself in fifteen minutes.
Personal logins on work tools, API keys left in files, agents allowed to act on their own. Each one comes with a person, a machine and what it costs.
Write your rules once and every device is checked against them. Unsafe prompts and secrets are blocked before they leave the laptop, and every failure gets an owner.
Each tool arrived on one laptop, and nobody wrote it down.
Including whether a coding agent may act unattended. All 21 →
A tool installed at 9:00 is in the inventory by 9:15.
Mac, Windows, Linux, iOS, Android, servers and cloud.
It runs as the user and never elevates.
Each layer works on its own. One agent feeds all six.
Know what is actually running.
read from files on the disk, never executed
Turn every report into one record.
macOS, Windows, Linux, servers and cloud
See what each one can reach.
declared, never dialled
Know what it costs before the invoice.
by tool, person and project
Act at the moment it happens.
inside the agent, on the device
Grade it, and keep the proof.
every publish is a version
Pick one to see what the agent reads.
They write and run code on the machine, sometimes without being watched.
The permission mode nobody reviewed, the MCP servers it can reach, and which repositories are in its scope. None of it crosses a gateway.
The agent's own configuration, in the user's home directory.
The chat window that never goes through your network.
Which account it is signed in on. Corporate work runs through somebody's personal ChatGPT and Claude login, over TLS to a domain you already allow.
Installed applications, and the account each one is signed in as.
The connectors that hand an agent your credentials.
They are declared in a client's config file and carry tokens off the device, and no CASB has a connector for them.
The client config files that declare them. Declared, never dialled.
A model running on the laptop. No invoice, no log, no gateway.
It runs entirely on the device, so nothing you bill against will ever show that it existed. And nothing in the path can see it.
The runner on disk, the models it has pulled, and the port it listens on.
The extension and the side panel that read the page you are on.
Extensions install per browser profile, ask for permission once, and are never inventoried again.
Extension manifests, per profile, and what each one declares it can see.
A provider key in a file git is not ignoring.
Keys sit in project .env files and in shell profiles. One of them is one push away from public.
Presence and location only. The value is discarded before evidence is built.
How you start depends on how big you are. What you get does not.
no minimum number of people · no charge per tool connected · nothing in the path of your traffic
Sign up, install the agent, and the first device reports in a minute.
Nothing about your devices leaves your network.
What AI ran on one machine, and what it cost. Not the platform.
$ endlayer enrollenrolment code 4F2K-9QX1waiting for an organisation to accept…accepted · credential stored 0600 · org set by the approver$ endlayer doctorconfig /etc/endlayer/endlayer.tomlignored nonedelivery reachable · next scan in 847s$ first snapshot delivered21 signals · 3 pass · 2 warn · 3 fail · 13 info
that was one laptop · the same thing runs on five thousand
EndLayer is Guardian Agents for AI. One agent, the Layer 1 Agent, runs on every device with no admin rights and no proxy or gateway. It finds shadow AI (every tool, coding agent, model, MCP server, account and API key in use), shows the risk each one carries and what it costs, and checks all of it against the policy you publish. Guardrails in the agent warn, redact or block as it happens. Surface, Monitor and Govern are the three modules, and EndLayer is a product of Holistic AI.
Yes, for PII leaking into a prompt, and for tools being used in ways nobody authorised. It is not on by default, and turning it on records who enabled it and the reason why. Your admin can narrow what is collected at any time, and the agent cannot widen it.
No. Nothing changes on your network. Everything is read from files already on the disk, which is also why desktop apps, coding agents and local models show up at all. none of them go through a gateway.
No. It runs as the person using the machine and reads only what that account can already read. It never elevates, and it never executes any of the AI tools it finds.
Seventeen are recognised by name. Anything else still surfaces as an unidentified AI process with the account and the machine attached, and naming it properly takes a signature, not an integration, so there is no work per tool for you either way.
Within fifteen minutes. Every device sends a snapshot every fifteen minutes, so a tool installed at 9:00 is in the inventory by 9:15.
Both. Every signal is measured against your policy version, and what fails gets an owner, a state and a date it closed. Guardrails inside the agent act on the device in real time: prompts are scored before they run, and secrets and personal data are warned on, redacted or blocked on the way out. Removing an installed app is the one action that waits for a person: an administrator approves the request before anything is uninstalled. Every action is recorded.
It is already installed on the laptops. You can see all of it by this afternoon.