Skip to content
The Platform

Four Pillars. One Agent. Zero Blind Spots.

Kraitos AIDR deploys as a single lightweight agent covering AI governance, data protection, threat detection, and asset management - under 50 MB of memory and less than 1% CPU.

Monitor

See Every AI Tool, Session, Token, and Dollar

Five detection layers find the tools, deep telemetry reconstructs the sessions, and every AI-related outbound connection is classified.

DiscoveryFilesystem scanning for config directories, VS Code and JetBrains extensions, and process names - 14 AI tools detected by name
NetworkConnection monitoring identifies 25+ cloud LLM APIs and 7 local inference servers by destination
BehavioralBehavioral heuristics recognize how AI tools act - catching unknown and custom tools no signature list has heard of
TelemetryDeep session telemetry for Claude Code - full conversation replay, token tracking, MCP visibility
DependencyDependency monitoring across 9 package formats, with known vulnerabilities flagged automatically
Sanctioned AIApproved provider
Shadow AIUnapproved tool
Cloud StorageFile destination
UnknownAwaiting review
BlockedPolicy-denied
Explore Monitor
Protect

Enforce Policy, Detect Secrets, Stop Threats

Seven detection engines ship in the same agent as AI governance. Every engine keeps itself current and feeds the unified device compliance score.

Detection engines
EngineFunctionMethod
AI Tool DiscoveryFind every AI coding tool on every endpointFilesystem, network, behavioral, and deep telemetry layers
Secret ScannerDetect credentials and sensitive data in AI conversations37+ patterns plus entropy analysis for secrets no pattern knows about
Native Malware ScannerDetect malicious binaries and files6.5M+ malware signatures, refreshed automatically every four hours
YARA ScannerScan for malware signatures and suspicious binariesIndustry-standard YARA rules, built in with nothing extra to install
IOC MatcherMatch against curated threat intelligenceFile, domain, and IP indicators from continuously updated threat feeds
Sigma BehavioralDetect suspicious endpoint behaviorBehavioral rules with full MITRE ATT&CK mapping
File Integrity MonitorDetect modification of critical system filesTamper baselines with real-time change alerts
Explore Protect
Respond

Contain Automatically or Behind an Approval Gate

Response actions with a full lifecycle and audit trail, bound to trigger patterns by SOAR-lite playbooks. Sensitive actions can require a second human, and the requester can never approve their own request.

Response actions
ActionEffect
Isolate deviceCut the endpoint off from the network while you investigate
Release isolationReturn the endpoint to normal operation
Kill processTerminate a specific process
Expire credentialKill a leaked credential server-side - no device required
Explore Respond
Assets

Inventory That Collects Itself

Hardware and software every six hours, browser extensions every two, plus repository discovery and dependency audit across nine package formats.

Asset inventory
SurfaceCadenceDetail
Hardware & softwareEvery 6 hoursCPU, RAM, disk, serial, OS, and network interfaces, plus every installed application and package
Browser extensionsEvery 2 hoursChrome, Edge, Brave, Arc, Firefox - risk-classified by permission surface
RepositoriesContinuousGit repos mapped to remotes for per-repo AI attribution and profiles
DependenciesOn every change9 package formats with automatic known-vulnerability checks
Explore Assets
Capabilities

Everything Else in the Same Agent

No second install, no bolt-on console, no per-module pricing.

AI Profiles

Group Policy for AI. Define CLAUDE.md, .cursorrules, Copilot instructions, and MCP allowlists centrally, then push them to every managed repo on every machine.

  • Template library
  • Discover & assign
  • Drift detection
  • Hierarchical merge
Learn more

Policy Engine

Watch or block - rules cover tools, models, data, spend, and dependencies. Policies stream to agents in under a second and evaluate locally in sub-millisecond time.

  • Monitor & enforce modes
  • 4 scope levels
  • 23+ templates
  • Audited exceptions
Learn more

Compliance Automation

53 controls across 7 frameworks, with evidence generated continuously as developers work - not assembled the week before an audit.

  • Signed evidence bundles
  • Drift detection
  • Control attestation
  • One-click export
Learn more

Endpoint Protection

Seven detection engines ship in the same agent: AI discovery, secret scanning, native malware, YARA, IOC matching, Sigma behavioral, and file integrity monitoring.

  • 6.5M+ malware signatures
  • MITRE ATT&CK mapping
  • Posture checks
  • Compliance scoring
Learn more

Response & Playbooks

Isolate a device, kill a process, or expire a leaked credential - automatically or behind a human approval gate, with a full audit trail on every action.

  • One-click containment
  • SOAR-lite playbooks
  • Approval workflows
  • Encrypted quarantine
Learn more

Cost & Usage Analytics

Per-developer, per-team, per-model token and cost tracking with 30-day trends, budget alerts, and chargeback-ready exports for finance.

  • Model-aware pricing
  • Budget thresholds
  • Adoption metrics
  • Finance exports
Learn more
Architecture

How It Is Built

Zero-trust posture with no insecure modes, no plaintext options, and no shortcuts.

A single self-contained agent

One lightweight install for macOS, Linux, and Windows that registers as a native service - no runtime dependencies, nothing else to deploy or patch.

  • < 50 MB memory
  • < 1% CPU
  • Signed releases
  • Atomic auto-update

Encrypted, authenticated transport

Streaming telemetry over mutual TLS 1.3 with per-device certificates, local buffering, and replay on reconnect. No insecure fallback exists.

  • Mandatory TLS 1.3
  • Per-device certs
  • Offline buffering
  • Replay on reconnect

Local-first evaluation

Policies stream to agents in under a second and evaluate on the endpoint in sub-millisecond time - no cloud round-trip in the developer's path.

  • Sub-ms evaluation
  • Works offline
  • Monitor & enforce
  • 4 scope levels

Multi-tenant by construction

Isolation enforced at four independent layers, down to the database row, so MSSPs and MSPs manage many clients with guaranteed boundaries.

  • Row-level isolation
  • Layered validation
  • 5 RBAC roles
  • Append-only audit log
Memory
< 50 MB
CPU
< 1%
Platforms
macOS · Linux · Windows
Updates
Automatic
Compliance

53 Controls Across Seven Frameworks

Evidence generates continuously as developers work, resolving each control to proven, partial, or unproven from live fleet data.

  • SOC 2
  • ISO 27001
  • NIST 800-53
  • PCI DSS 4.1
  • HIPAA
  • NIST AI RMF
  • EU AI Act
SOC 2 CC6.1
Logical access controls - AI tool access logs, policy enforcement records, MCP allowlist enforcement
SOC 2 CC7.2
System monitoring - real-time alerts on policy violations via Slack, email, and webhook
ISO A.8.16
Monitoring activities - real-time AI conversation telemetry across every endpoint
ISO A.8.28
Secure coding - per-repo AI config enforcement via managed CLAUDE.md and .cursorrules
NIST SI-4
System monitoring - continuous behavioral and network monitoring with MITRE ATT&CK mapping
NIST CM-8
System component inventory - full hardware, software, extension, and AI tool inventory
PCI 5.2
Malicious software prevention - native malware scanner, YARA, IOC matching, quarantine
HIPAA §312
Technical safeguards - access control, disk encryption checks, audit trails, FIM, network monitoring
Deployment

60-Second Deployment. Zero Developer Friction.

No infrastructure to manage, no reboot, no developer interaction.

  1. Step 01

    Create an enrollment token

    Set OS restrictions, CIDR allowlists, team auto-assignment, single- or multi-use, and an expiry window.

  2. Step 02

    Deploy it

    Push the installer through your existing MDM or endpoint management tooling, or hand the token to the person setting the machine up. No reboot, no imaging, no developer interaction.

  3. Step 03

    Devices report instantly

    AI tools, sessions, posture, and inventory flow into the dashboard within seconds of the agent starting.

Why Kraitos

All Three Categories in One Agent, at EDR Pricing

EDR sees malware but not AI. AI security platforms see the model layer but ship no endpoint agent. Compliance automation sees neither.

AI Governance + Endpoint Security

The only platform combining full AI session visibility, data loss prevention, and EDR-class endpoint protection in a single agent. No bolt-ons, no integrations, no second install.

  • One agent
  • Seven detection engines
  • Under 50 MB
  • No second console

Local-First Policy Enforcement

Policies evaluate on the endpoint in sub-millisecond time - no cloud round-trip, no latency, no single point of failure. Developers do not experience a slowdown.

  • Sub-ms evaluation
  • Policy push under 1s
  • Works offline
  • Monitor & enforce modes

Full Conversation Intelligence

Not just prompts - every tool call, file access, shell command, MCP connection, and subagent relationship, with per-turn token counts and cost.

  • Session replay
  • Shell command log
  • MCP destinations
  • Cost attribution

AI Profiles - Group Policy for AI

Centrally manage CLAUDE.md, .cursorrules, MCP allowlists, and memory packs across every repo on every machine, with drift detection and reconciliation.

  • Template library
  • Fleet-wide push
  • Drift alerts
  • Hierarchical merge

See Kraitos AIDR in Action

Deploy in 60 seconds. Get answers in 24 hours. Stop guessing what your AI-augmented organization is doing.

[email protected]kraitos.io