Is the sensor read-only? Could it be weaponised?
Yes — the discovery sensor inspects; it never edits files, installs software, or changes settings, and it has no inbound command or remote-execution channel. Beyond discovery, the shipped controls are a server-side content-DLP policy engine and remote-pause of a sensor’s collection — both operator-authorised, never the sensor acting on its own. Deeper enforcement (host/agent blocking, inline browser DLP) is on the roadmap and will run through that same separate, opt-in channel — so a read-only sensor and a real response path stay separate without contradiction. You can review exactly what the agent does before it is ever deployed.
What does the sensor collect — and what does it never touch?
It collects AI-usage metadata only: AI CLIs/SDKs in use, MCP servers and their package/version/provenance, the presence of provider API keys (masked at the point of collection — never the value), and egress destinations. It never reads file contents, secret values, prompts/responses, keystrokes, screenshots, or the clipboard. Command lines are scrubbed of tokens on the endpoint before anything is sent.
What's the performance footprint?
One static binary, ~6.5 MB, no runtime or dependencies. In our measurements it uses roughly ~12 MB of memory and a fraction of a second of CPU per scan cycle, collecting on an interval (60 seconds by default). It is built to sit quietly in the background of a working laptop.
Which operating systems and kernels are supported?
Windows, macOS and Linux, from a single signed binary per OS. Real-time exec/connect tracing via eBPF runs on Linux; macOS and Windows use scheduled collection of the same surfaces. The portable collectors (AI CLIs, keys, MCP configs, apps, extensions, SDKs, skills, network egress) run on all three.
How is it deployed?
Push the signed binary through your existing MDM/config management — Jamf, Intune, Kandji, or Ansible/SCCM — as a background service. No user interaction, no reboot. A typical first fleet scan returns findings within minutes.
How do I uninstall or roll it back?
Removal is a single MDM action that stops the service and deletes the binary and its small identity file — nothing is left behind, and it touches no other software on the machine. Updates are versioned and pinned, so a specific version can be rolled back the same way you rolled it out.
Does it phone home? Can it run air-gapped or in-VPC?
The sensor reports masked findings over TLS to a collector you control. For regulated or zero-egress environments, the whole platform can run in your own VPC — 100% of data stays in your cloud account, no external sub-processors. Air-gapped deployment is available for the Enterprise tier.
What about false positives?
Findings are risk-scored by a deterministic engine — inventory (an app on disk) is banded separately from active risk (a live key or a running agent), so you act on what matters, not a flat wall of MEDIUM. An optional AI reasoning layer adds advisory context and triages ambiguous cases; it never changes the deterministic score.
How is this different from my EDR or CNAPP?
Your EDR hunts malware and your CNAPP checks cloud posture — neither inventories the AI your people actually adopted on their laptops. We build a live AI Bill of Materials (agents, SDKs, MCP servers, keys, egress) attributed to a machine and a person, and map it to the EU AI Act, NIST AI RMF and ISO 42001. We run alongside your EDR/CNAPP, not instead of them — more on that here.
How does pricing work — and what counts as an endpoint?
Priced per endpoint per year, billed annually, with volume tiers. An endpoint is any managed device running the sensor — laptop, desktop, server or VM. Each edition has an annual platform floor (you pay the greater of the floor or endpoints × rate). Start with a free assessment of up to 25 endpoints — see pricing or book a scoping call.
What about employee privacy and works councils?
The sensor is built for AI governance, not employee surveillance. It collects AI-usage metadata only — never file contents, prompts and responses, keystrokes, screenshots or the clipboard — so it shows that an unsanctioned AI tool is in use, and on which machine and account, not what anyone typed. That data-minimisation is deliberately what a Data Protection Impact Assessment (DPIA) or a works council needs to see. We support role-scoped access, a DPIA-friendly data map (what is collected, why, and the lawful basis), and — where employee-monitoring rules require it, such as an EU works council / Betriebsrat — we provide documentation to support consultation before rollout. Full detail is on the Security page.