One signed policy across every endpoint.

AI Traffic Control Enterprise signs one policy, distributes it to the fleet and records what every endpoint enforces.

Policy v13 · signed 0 of 5 endpoints
EndpointHarnessStatus
eng-laptop-0142 Claude Code v13 queued
eng-laptop-0217 Codex v13 queued
ci-runner-07 Claude Code v13 queued
eng-laptop-0388 Claude Desktop v13 queued
build-agent-02 Claude Code v13 queued

Community and Enterprise.

Community is free for individual use. Enterprise adds central control across the organization.

CommunityEnterprise
Checks every prompt and tool call inline
Regulated data stays on the machine
Rule packs and local dashboard
One signed policy for the organization
Fleet-wide distribution
Record of what every endpoint enforces

AI-TC Enterprise puts the fleet on the record.

  1. Every finding, fleet-wide

    A credential caught on one laptop is a fleet problem, not a laptop problem.

    Read the Credential Exposure transcript

    Demo for AKA AI Traffic Control, or AI-TC for short. First, AI-TC is a solution you can deploy in your environment. While the harness plugin is open source, the Enterprise version is something that you can license from AKA. Once you've installed AI-TC in your environment, you'll be able to monitor deployment health and push the AI-TC plugin to all endpoints. Once on your endpoints, you'll be able to monitor what is being done with AI in your environment. First, it takes inventory of everything you have. It looks across the harnesses and by type. That includes all projects running on the endpoints, including correlation and deduplication of shared projects, skills, MCP servers and other configurations. Finally, credentials. Credential exposure looks for cases where a credential may be in the shell, on disk or in the transcript. Credentials exposed in a transcript or through another mechanism to an external party or LLM before AI-TC was installed are brought up as findings. In the overview, you can see which credentials may be at risk and which ones you want to change and rotate. AI-TC also tracks how long credentials have been in use and whether more than one team or project uses them. These could be signals that you need to rotate or split apart the credential at the source. In inventory, you can refine by type and look for potentially risky MCP servers. MCP servers that you haven't approved may be reviewed, then verified or blocked. If blocked, AI-TC prevents the harness on the endpoint from using the MCP server, so the user is unable to send data to it. That's it for this highlight. More highlights follow.

  2. Where the data actually goes

    Knowing which models the agents talk to is not the same as knowing what they send.

    Read the Data Shares transcript

    AKA AI Traffic Control, or AI-TC for short, is open source. You can use the plugin directly in your harness to improve local security. You can also deploy it as a licensed tool in an Enterprise environment. Once licensed and set up, AKA AI-TC can be deployed to endpoints where people use Claude Code, Cursor, Codex or another harness. A browser plugin can check calls made through the browser to any of the LLMs. Once installed, it takes a full inventory of the harnesses on the endpoints, as well as projects, skills, MCP servers and other information. It also checks what data is being shared externally, both in code and through other harnesses. AI-TC determines whether you're sharing data with an endpoint that isn't an authorized provider and what kind of data is being sent. This provides central visibility into code that intentionally sends data out and harnesses that may be sending data externally. With this view, you can understand what developers or other people using AI in local coding work are sending to. You can flag it. To explore an individual case, open it to see where the call is going and what data is being sent. This gives you visibility into what is going to those endpoints. If you want to block an endpoint used by a specific harness, you can. If you want to change something in code, ask the developer to use their development tools to modify it. At least the visibility is there. That's an overview of how AI-TC checks data sharing.

  3. Deployed, signed, attested

    An endpoint that cannot prove what it is running is not enforcing.

    Read the MDM Deployment transcript

    For AKA AI Traffic Control, AI-TC, this demo reviews how AI-TC works with mobile device management. The harness plugin for AI-TC is available as open source. Pushing it to every endpoint requires a connector. After AI-TC Enterprise is deployed, its self-hosted environment connects devices through integrations. Add a directory such as Fleet, Microsoft Intune or Jamf. Connected endpoints appear automatically in the endpoints interface, along with a full inventory of connections. Applications connected through the SDK appear as well and do not have to go through MDM. Each endpoint shows whether its attestation is verified, confirming that the AKA AI-TC plugin is installed and working. The AI-TC CLI provides the base for Claude Code, GitHub Copilot, Codex and browser plugins. Those tools connect automatically and report to the Enterprise server. Configuration remains available through Fleet or another MDM. That is it for today. Another demo follows.

Build Your Own Security