Enforcement happens where AI is used
The agent inspects prompts, pastes, and uploads as they happen and enforces the decision at the endpoint: allow, redact, block, or hold for human review, before the prompt reaches the model's API.
Coverage includes AI tools the enterprise does not own or host. Chat apps, code assistants, and personal AI sites in the browser, the tools your teams already reached for, are secured and governed on the same policy surface as sanctioned AI.
Deploy Endpoint Security through the MDM your fleet already runs. Coverage in days, with no new infrastructure or network changes.
AI Security Runtime™ runs at the endpoint
The agent is AI Security Runtime™ running at the endpoint: every AI interaction it sees, human or agent, runs the same four functions on the way to the model.
| OBSERVE | Every AI interaction at the endpoint: who or what is acting, what data, which tool |
| DETECT | Threats, sensitive data, and policy violations judged by meaning and intent, in real time |
| ENFORCE | Allow, redact, block, or hold for human review, before the prompt reaches the model's API |
| TRACE | Audit-ready evidence for every decision, streamed to your SIEM |
Observability, enforcement, remediation
Policy is written against named AI services and enforced at the endpoint. Enforcement decisions are recorded as signed receipts that name the decision, what decided it, and the policy revision it ran under.
A fleet-wide inventory of AI in use: the named service, the app that opened the connection, the device, and the acting user. Telemetry is limited to AI activity and enforcement decisions.
Allow, warn, block, and monitor rules, scoped to a named service, a provider, or a department and enforced directly on macOS and Windows. Protected AI flows that cannot be verified fail closed.
A discovered service moves from monitored to warned to blocked, or is sanctioned for a named team. For tools you retire, the Secure Enterprise AI Workspace is the governed alternative.
| ALLOWLIST | Sanction a named AI service for one department or the whole fleet. Allow GitHub Copilot for Engineering is a single rule. |
| BLOCK | Drop the connection at the endpoint, before data reaches a model. Scope it to one named service, a provider, or all unsanctioned AI. |
| WARN | Let the flow proceed with a recorded warning decision. User overrides become part of the evidence trail. |
| MONITOR | Log-only visibility with no user impact. New deployments start here; turning on enforcement is a per-rule decision. |
| DEFAULT | When no rule matches, the tenant default decides: allow, warn, block, or monitor. For unmatched traffic, the posture is yours to set. |
| RECEIPTS | Every enforcement decision is written as a signed receipt carrying the decision, the deciding rule or default, and the policy revision it ran under. Sealed, metadata-only evidence. |
Every endpoint decision lands in the console
Enforcement on devices feeds the console: live security posture, blocked threats, and policy violations. Every decision is recorded as audit-ready evidence for an auditor, the board, or a regulator.