AI-agent security

See and control what AI agents do across model APIs, MCP servers and endpoints.

Coding agents read source code, run shell commands and call tools on your endpoints every day. Spectis records each action, attributes it to a named user, and blocks the actions your policy prohibits — with no proxy and nothing in your network path.

Request access See the platform
Agent Runtime  ·  Codex CLI session, r.holt  ·  mac-eng-41 Example
17:09:53Readallowsrc/app.py0.5 ms
17:11:04Bashallowgit commit -m 'wip'2.9 ms
17:11:19Bashdenygit push — blocked by policy shell.git-push3.4 ms
17:11:42Bashwarncat customers.csv — customer data in tool output4.1 ms
The gap

No existing security tool can follow an AI agent across all three planes.

A single agent action crosses the model API, the network and the endpoint. Each category of tool observes one segment and cannot correlate the others, so no system in place today can establish which user was responsible or what data was reached.

Model APIMCP & networkEndpointNames the personIn your traffic path
SASE / SSEPartial——NoYes
MCP gateway—Partial—NoYes
EDR / XDR——PartialNoAgent
AI-SPM / CSPMPartial——NoNo
SpectisFullFullFullYesNo
Platform

A complete inventory of AI agents, activity and risk across your organisation.

01

Agent inventory and ownership

Every configured agent across every connected source — Copilot Studio agents, custom GPTs, Bedrock and Vertex agents, and the agent and skill files held in repositories and on endpoints — with its owner, model and reach, including the agents that have no assigned owner.

Agent InventoryAgents across every source, with owner and risk
Spectis agent inventory listing configured agents across sources with owner, model and risk level.
02

Risk analysis with stated reasoning

Spectis analyses the instruction files your agents load and reports which of them present a risk, with a written rationale a reviewer can act on rather than a rule identifier and a score.

AI ToolingInstruction files, with a verdict and a reason
Spectis AI tooling view showing scanned instruction files with a verdict and rationale for each.
03

Verified endpoint coverage

Upload the device list you already maintain. Spectis reconciles it against the endpoints that have reported and categorises every gap: machines without a scanner, machines that have stopped reporting, and machines absent from your inventory.

Endpoint CoverageYour device list against what reported
Spectis endpoint coverage reconciling an uploaded device list against machines that have reported.
04

AI spend by team and provider

Adoption and cost reported per user, team and provider, each in that provider’s own unit and never blended into a single figure.

Usage & SpendAdoption and cost, per team and provider
Spectis usage and spend view showing AI adoption and cost broken down by provider and team.

Connected sources

MicrosoftCopilot · Studio · Power Platform
OpenAIChatGPT · Codex
AnthropicClaude · Claude Code
GitHubCopilot · repositories
AWSBedrock
GoogleVertex · Gemini
MCPServers · allowlist
EndpointsMachines · tooling

Screens show example data from a demonstration tenant.

Control

Policy enforced at the agent, before the action executes.

Coding agents request permission before each tool call, and Spectis answers that request. Write a rule, scope it to a user, group or department, and publish it. The decision is then made on the endpoint itself, in milliseconds, whether or not it can reach us.

A rule, as your team writes it
deny   git push
on     every coding agent
except group "Cyber Team"

Every rule is tested before publication and signed per user, so an endpoint only applies policy it can prove originated with you.

4ms

p95 added to each tool call, against a 10 ms budget.

0

network calls on the decision path. It works offline.

3planes

correlated to a single user and timeline.

20+

AI clients discovered and inventoried on each endpoint.

Coding agent sessionsEvery hooked tool call, attributed to a user
Spectis coding agent sessions showing 138 sessions and 978 tool calls with 48 denied, broken down by agent, and a session table listing user, model and repository.

Ask Spectis

Coming soon

Ask in plain language: who is using which agent, which MCP servers turned up this week, what was flagged malicious and why. You get an answer with the evidence behind it, scoped to what your role is allowed to see.

Exposure graph

Coming soon

One view of the full path: user, endpoint, agent, the MCP servers it can reach, the models behind them and the data involved — so exposure that arises from a combination of individually acceptable conditions is visible in a single place.

Trust

What Spectis collects, and what it never does.

Out of the traffic path

No proxy, no interception, no certificate to install. An interruption to Spectis does not interrupt engineering work.

Prompts are not captured

Spectis records that an agent ran a command and the verdict it received, not what anyone typed. Conversation content is reachable by Compliance alone, and every read is audited.

Secrets never travel

Environment variable names, never values. No raw command lines. Credentials found during a scan are reported by type and masked, never carried in the clear.

Analysis retains nothing

Where an instruction file requires closer analysis it is examined and discarded. Spectis retains the verdict, not the file, and will run the analysis inside your own cloud account.

Administrators see no usage data

The people who operate the platform cannot read who used which AI service. That separation is built into the data model rather than configured as a setting.

Your SIEM remains the system of record

Audit events stream to Splunk, Sentinel, syslog or a webhook. Spectis is a source of evidence, not another console to staff.

Full data-handling documentation, the access-control contract and our security questionnaire responses are available for review during evaluation.

Deployment

Deployed in a dedicated tenant, or entirely on your own infrastructure.

Managed single-tenant

A dedicated instance with its own orchestrator, dashboard and database. Encrypted at rest, TLS 1.3 in transit, with no shared data plane between customers.

Self-hosted

Docker Compose or Helm, in your cloud or on-premises. Identical to the hosted build, with no features reserved for the managed edition.

Identity-aware

SCIM provisioning with your directory groups mapped to roles.

Role-scoped by design

Five roles with a written access contract and an audit trail over every privileged read.

Signed control plane

Every instruction sent to an endpoint is signed and verified before it acts.

Request access

Start with a single engineering team.

Install the scanner on one team’s endpoints, connect the providers you already pay for, and we will review the results with you. Nothing is introduced into your traffic path, and nothing needs to be unpicked if you decide against it.

hello@spectis.io We will scope a pilot with one team and review the results with your engineers.