Four Pillars. One Agent. Zero Blind Spots.
Kraitos AIDR deploys as a single lightweight agent covering AI governance, data protection, threat detection, and asset management - under 50 MB of memory and less than 1% CPU.
One Install, Four Problem Domains
Each pillar is a full surface in the product, not a marketing grouping. Follow any of them into its own page for the capability-level detail.
Monitor
Real-time visibility into every AI tool, every session, every token, every dollar across your fleet.
- AI Tool Discovery
- Session Intelligence
- Cost & Usage Analytics
- Live Floor
- Data Egress
- Local AI Detection
Protect
Enforce policies, detect secrets, scan for threats, and produce audit-ready compliance evidence.
- Policy Engine
- Secret & DLP Detection
- Threat Detection
- Compliance Automation
- AI Profiles
Respond
Automated and human-gated response actions with SOAR-lite playbooks for AI-related incidents.
- Isolate / Kill / Expire
- Playbook Builder
- Quarantine Manager
- Approval Workflows
Assets
Complete endpoint inventory: hardware, software, browser extensions, and AI tool configurations.
- Device Inventory
- Software & Hardware
- Browser Extensions
- Repository Discovery
- Dependency Audit

See Every AI Tool, Session, Token, and Dollar
Five detection layers find the tools, deep telemetry reconstructs the sessions, and every AI-related outbound connection is classified.
| Discovery | Filesystem scanning for config directories, VS Code and JetBrains extensions, and process names - 14 AI tools detected by name |
| Network | Connection monitoring identifies 25+ cloud LLM APIs and 7 local inference servers by destination |
| Behavioral | Behavioral heuristics recognize how AI tools act - catching unknown and custom tools no signature list has heard of |
| Telemetry | Deep session telemetry for Claude Code - full conversation replay, token tracking, MCP visibility |
| Dependency | Dependency monitoring across 9 package formats, with known vulnerabilities flagged automatically |
Enforce Policy, Detect Secrets, Stop Threats
Seven detection engines ship in the same agent as AI governance. Every engine keeps itself current and feeds the unified device compliance score.
| Engine | Function | Method |
|---|---|---|
| AI Tool Discovery | Find every AI coding tool on every endpoint | Filesystem, network, behavioral, and deep telemetry layers |
| Secret Scanner | Detect credentials and sensitive data in AI conversations | 37+ patterns plus entropy analysis for secrets no pattern knows about |
| Native Malware Scanner | Detect malicious binaries and files | 6.5M+ malware signatures, refreshed automatically every four hours |
| YARA Scanner | Scan for malware signatures and suspicious binaries | Industry-standard YARA rules, built in with nothing extra to install |
| IOC Matcher | Match against curated threat intelligence | File, domain, and IP indicators from continuously updated threat feeds |
| Sigma Behavioral | Detect suspicious endpoint behavior | Behavioral rules with full MITRE ATT&CK mapping |
| File Integrity Monitor | Detect modification of critical system files | Tamper baselines with real-time change alerts |
Contain Automatically or Behind an Approval Gate
Response actions with a full lifecycle and audit trail, bound to trigger patterns by SOAR-lite playbooks. Sensitive actions can require a second human, and the requester can never approve their own request.
| Action | Effect |
|---|---|
| Isolate device | Cut the endpoint off from the network while you investigate |
| Release isolation | Return the endpoint to normal operation |
| Kill process | Terminate a specific process |
| Expire credential | Kill a leaked credential server-side - no device required |
Inventory That Collects Itself
Hardware and software every six hours, browser extensions every two, plus repository discovery and dependency audit across nine package formats.
| Surface | Cadence | Detail |
|---|---|---|
| Hardware & software | Every 6 hours | CPU, RAM, disk, serial, OS, and network interfaces, plus every installed application and package |
| Browser extensions | Every 2 hours | Chrome, Edge, Brave, Arc, Firefox - risk-classified by permission surface |
| Repositories | Continuous | Git repos mapped to remotes for per-repo AI attribution and profiles |
| Dependencies | On every change | 9 package formats with automatic known-vulnerability checks |
Everything Else in the Same Agent
No second install, no bolt-on console, no per-module pricing.
AI Profiles
Group Policy for AI. Define CLAUDE.md, .cursorrules, Copilot instructions, and MCP allowlists centrally, then push them to every managed repo on every machine.
- Template library
- Discover & assign
- Drift detection
- Hierarchical merge
Policy Engine
Watch or block - rules cover tools, models, data, spend, and dependencies. Policies stream to agents in under a second and evaluate locally in sub-millisecond time.
- Monitor & enforce modes
- 4 scope levels
- 23+ templates
- Audited exceptions
Compliance Automation
53 controls across 7 frameworks, with evidence generated continuously as developers work - not assembled the week before an audit.
- Signed evidence bundles
- Drift detection
- Control attestation
- One-click export
Endpoint Protection
Seven detection engines ship in the same agent: AI discovery, secret scanning, native malware, YARA, IOC matching, Sigma behavioral, and file integrity monitoring.
- 6.5M+ malware signatures
- MITRE ATT&CK mapping
- Posture checks
- Compliance scoring
Response & Playbooks
Isolate a device, kill a process, or expire a leaked credential - automatically or behind a human approval gate, with a full audit trail on every action.
- One-click containment
- SOAR-lite playbooks
- Approval workflows
- Encrypted quarantine
Cost & Usage Analytics
Per-developer, per-team, per-model token and cost tracking with 30-day trends, budget alerts, and chargeback-ready exports for finance.
- Model-aware pricing
- Budget thresholds
- Adoption metrics
- Finance exports
How It Is Built
Zero-trust posture with no insecure modes, no plaintext options, and no shortcuts.
A single self-contained agent
One lightweight install for macOS, Linux, and Windows that registers as a native service - no runtime dependencies, nothing else to deploy or patch.
- < 50 MB memory
- < 1% CPU
- Signed releases
- Atomic auto-update
Encrypted, authenticated transport
Streaming telemetry over mutual TLS 1.3 with per-device certificates, local buffering, and replay on reconnect. No insecure fallback exists.
- Mandatory TLS 1.3
- Per-device certs
- Offline buffering
- Replay on reconnect
Local-first evaluation
Policies stream to agents in under a second and evaluate on the endpoint in sub-millisecond time - no cloud round-trip in the developer's path.
- Sub-ms evaluation
- Works offline
- Monitor & enforce
- 4 scope levels
Multi-tenant by construction
Isolation enforced at four independent layers, down to the database row, so MSSPs and MSPs manage many clients with guaranteed boundaries.
- Row-level isolation
- Layered validation
- 5 RBAC roles
- Append-only audit log
- Memory
- < 50 MB
- CPU
- < 1%
- Platforms
- macOS · Linux · Windows
- Updates
- Automatic
53 Controls Across Seven Frameworks
Evidence generates continuously as developers work, resolving each control to proven, partial, or unproven from live fleet data.
- SOC 2
- ISO 27001
- NIST 800-53
- PCI DSS 4.1
- HIPAA
- NIST AI RMF
- EU AI Act
- SOC 2 CC6.1
- Logical access controls - AI tool access logs, policy enforcement records, MCP allowlist enforcement
- SOC 2 CC7.2
- System monitoring - real-time alerts on policy violations via Slack, email, and webhook
- ISO A.8.16
- Monitoring activities - real-time AI conversation telemetry across every endpoint
- ISO A.8.28
- Secure coding - per-repo AI config enforcement via managed CLAUDE.md and .cursorrules
- NIST SI-4
- System monitoring - continuous behavioral and network monitoring with MITRE ATT&CK mapping
- NIST CM-8
- System component inventory - full hardware, software, extension, and AI tool inventory
- PCI 5.2
- Malicious software prevention - native malware scanner, YARA, IOC matching, quarantine
- HIPAA §312
- Technical safeguards - access control, disk encryption checks, audit trails, FIM, network monitoring
60-Second Deployment. Zero Developer Friction.
No infrastructure to manage, no reboot, no developer interaction.
- Step 01
Create an enrollment token
Set OS restrictions, CIDR allowlists, team auto-assignment, single- or multi-use, and an expiry window.
- Step 02
Deploy it
Push the installer through your existing MDM or endpoint management tooling, or hand the token to the person setting the machine up. No reboot, no imaging, no developer interaction.
- Step 03
Devices report instantly
AI tools, sessions, posture, and inventory flow into the dashboard within seconds of the agent starting.
All Three Categories in One Agent, at EDR Pricing
EDR sees malware but not AI. AI security platforms see the model layer but ship no endpoint agent. Compliance automation sees neither.
AI Governance + Endpoint Security
The only platform combining full AI session visibility, data loss prevention, and EDR-class endpoint protection in a single agent. No bolt-ons, no integrations, no second install.
- One agent
- Seven detection engines
- Under 50 MB
- No second console
Local-First Policy Enforcement
Policies evaluate on the endpoint in sub-millisecond time - no cloud round-trip, no latency, no single point of failure. Developers do not experience a slowdown.
- Sub-ms evaluation
- Policy push under 1s
- Works offline
- Monitor & enforce modes
Full Conversation Intelligence
Not just prompts - every tool call, file access, shell command, MCP connection, and subagent relationship, with per-turn token counts and cost.
- Session replay
- Shell command log
- MCP destinations
- Cost attribution
AI Profiles - Group Policy for AI
Centrally manage CLAUDE.md, .cursorrules, MCP allowlists, and memory packs across every repo on every machine, with drift detection and reconciliation.
- Template library
- Fleet-wide push
- Drift alerts
- Hierarchical merge
See Kraitos AIDR in Action
Deploy in 60 seconds. Get answers in 24 hours. Stop guessing what your AI-augmented organization is doing.
[email protected]kraitos.io