Discovered tools become sanctioned routes
Discovery is AI Security Runtime™ running on the fleet. Every AI interaction it sees crosses the same four functions on the way to the model.
| THE REAL INVENTORY | AI destinations observed from live traffic on managed macOS and Windows devices, including AI tools the enterprise does not own or host |
| A DECISION PER TOOL | Approve with policy, constrain with rules, or redirect to the Secure Enterprise AI Workspace, without losing capabilities |
| ENFORCED AT THE MOMENT OF USE | Endpoint Security acts at the endpoint, applying allow, warn, block, or redirect before the prompt reaches the model's API |
| ADOPTION, UNSHADOWED | People keep the speed, security keeps the visibility, and the move from shadow tools to approved routes shows up in the console over time |
Watch shadow AI become approved use
Discovery is the start. From there, approved routes gain ground, and your security team can answer for AI use.
Common questions
How does discovery work?
Endpoint Security observes connections to AI services at the operating-system layer on macOS and Windows, using a macOS System Extension and the Windows Filtering Platform, and checks them against a curated directory of AI destinations that is continuously updated. Coverage comes from the connection, not the application, so browser AI, desktop apps, and IDE assistants surface the same way. Destinations specific to your organization can be added.
Do we need a proxy, VPN, or network changes?
No. The agent acts at the endpoint, so discovery holds on or off the corporate network, and it deploys through the MDM your team already runs. It is built to run alongside your EDR and device management stack, and before any rollout our engineers walk your endpoint team through the interception path and coexistence with what you already run. Coverage in days, no new infrastructure, no network changes.
We found it all. Then what?
Every destination gets a decision. Approve it with policy, constrain it with rules, or redirect it. Someone reaching a blocked tool sees where the approved route is, typically the Secure Enterprise AI Workspace, so enforcement also drives adoption. From there the console tracks sanctioned use gaining ground, and every enforcement decision is recorded as sealed, metadata-only evidence.