Reads what you run. Reports where you work.
Every connection on the way in is read-only. On the way out, each finding arrives with its evidence in the tools your team already watches.
Reads from
Read-only, every one.
Code hosts
Repositories, where agents, tools, prompts and MCP servers are defined.
- GitHub
- GitLab
- Bitbucket
- Azure DevOps
Clouds
Cloud accounts, through read-only roles: the models, endpoints and agents deployed there.
- AWS
- Azure
- Google Cloud
- Oracle Cloud
Model platforms
The model providers your agents call.
- OpenAI
- Anthropic
- Google Gemini
- Vertex AI
- Azure OpenAI
- Amazon Bedrock
- Mistral
- Cohere
- Hugging Face
- Ollama
Agent platforms
The agents inside the platforms you buy, through their admin and audit APIs.
- Copilot Studio
- Microsoft 365 Copilot
- Agentforce
- ServiceNow
- Glean
- ChatGPT Enterprise
Agent frameworks
The frameworks your teams build agents with, found in their code.
- LangChain
- LangGraph
- CrewAI
- AutoGen
- OpenAI Agents SDK
- Bedrock AgentCore
- LlamaIndex
- Semantic Kernel
- Vercel AI SDK
- n8n
- Zapier
- Make
- Dify
- Flowise
- Langflow
Coding agents
The coding agents on your developers’ laptops.
- Claude Code
- Cursor
- GitHub Copilot
- Windsurf
- Kiro
- Amp
- Gemini CLI
- Amazon Q
- Cline
MCP servers
MCP servers, in repositories and on machines.
- Any MCP server
- OpenClaw
Identity
Who each agent acts as, and who owns it.
- Okta
- Microsoft Entra ID
- Google Workspace
- Ping Identity
- OneLogin
- JumpCloud
- Auth0
Laptops, through MDM
Laptops, through a read-only sensor your MDM deploys.
- Jamf
- Intune
- Iru
Secrets
Where agents’ credentials are kept, and which agent holds which.
- HashiCorp Vault
- AWS Secrets Manager
- CyberArk
- 1Password
- Doppler
Data
The data your agents can reach.
- Snowflake
- Databricks
- BigQuery
- PostgreSQL
- Salesforce
- Dynamics 365
And many more, all read-only.
Reports to
Each finding, with its evidence.
Chat
Findings as messages, to the people who need to see them.
- Slack
- Microsoft Teams
Tickets and on-call
Findings as tickets and pages, each with an owner.
- Jira
- ServiceNow
- Linear
- PagerDuty
- Opsgenie
SIEM and observability
Findings and their evidence, as events.
- Splunk
- Microsoft Sentinel
- Google SecOps
- Datadog
- Elastic
- Sumo Logic
- Panther
- Exabeam
EDR and XDR
Findings shared with the tools that watch your devices.
- CrowdStrike
- SentinelOne
- Microsoft Defender
- Cortex XDR
- Trend Micro
Network and SSE
Findings shared with the tools that watch your traffic.
- Zscaler
- Netskope
- Prisma Access
- Cloudflare
- Fortinet
- Cisco
Cloud and app security
Findings beside your cloud and application risk.
- Wiz
- Orca
- Prisma Cloud
- FortiCNAPP
- Tenable
- Qualys
- Rapid7
- Snyk
GRC
Evidence for your audits and frameworks.
- Vanta
- Drata
- OneTrust
- Archer
CI gates
Checks that stop an unsafe agent before it ships.
- GitHub Actions
- GitLab CI
- Jenkins
- CircleCI
And anything else with a webhook.
Missing a tool your team relies on? Tell us about it.
Start free.
Find the agents already running in your company, and who answers for each one.
Free to start. No card.