Pillar 4
Fleet
Deploy, monitor and enforce policy centrally across your entire engineering org through your existing MDM — without touching each machine individually.
Deployment
Signed packages distributed through Jamf, Kandji or Intune. MDM configuration profiles handle the system extension allowlist, network extension activation and CA trust installation in one push. Nothing requires individual engineer interaction. The discovery sensor deploys separately to a network tap or ingests from your existing SASE pipeline — no agent on endpoints for the discovery layer.
| Platform | Status | Notes |
|---|---|---|
| macOS (Apple silicon) | Available | Full discovery, endpoint protection, sandbox and fleet. Boot time under 2s. |
| macOS (Intel) | Confirm | Founders: verify and state |
| Linux | Confirm | Founders: state a target quarter |
| Windows | Confirm | Founders: state a target quarter |
Policy management
Policy is a TOML file committed to source control. A change is a commit and a push — the fleet picks it up without a reinstall and without a device touch. Approval for allowlist changes can be delegated to engineering leads rather than routed through security for every entry.
Discovery findings feed directly into policy: after two weeks of monitor mode you have a real allowlist derived from what your agents actually reached, not a guessed one. You approve it, it deploys.
Posture progression
Posture moves from monitor to warn to block centrally, without reinstall. Start with nothing blocked — observe what your AI workforce actually does, build confidence in the allowlist, then enforce.
- Monitor — record every connection and action. Nothing is blocked. Use this to build your allowlist from observed behaviour.
- Warn — out-of-policy connections are logged and surfaced to the team but not blocked. Gives engineers visibility before enforcement lands.
- Block — out-of-policy connections are refused. DLP rules fire as blocks, not alerts. The posture the security team controls.
Observatory
A local dashboard shows live sandboxes, connections with their verdicts, token spend per model per turn, DLP verdicts and egress anomalies against the learned baseline. Every event is attributed to user and device.
One-click egress block: the Observatory can cut a sandbox's network access live, from the dashboard, without a policy push.
Audit and export
Per-session and per-connection audit records export into your existing SIEM pipeline as a signed, tamper-evident event stream. The record is produced at the kernel level, independently of what the agent logs — it cannot be modified by the agent or the application after the fact.
Named detections (SENSITIVE-ACCESS, EXFIL, REVSHELL and others) are tagged with rule IDs and map to OWASP agentic risk categories, so the output maps to a taxonomy your assessors already recognise.
Deploy through your existing MDM in days, not months
No engineer action needed on each machine. Policy follows from your source control.
Deployed via Jamf, Kandji or Intune.