INTEGRATIONS
Coding agents, workspaces, browsers, your SIEM and your identity provider — governed through one chokepoint.
coding agents
One config change per tool: the gateway finds the MCP clients already configured on the machine and policy runs on every tool call through it. Codex is governed through agent hooks instead — same policies, same record. An enrolled device signs what it sends; where it cannot, the event is recorded as unsigned rather than counted as proven.
workspace connectors
Read-only OAuth into Google Workspace or Microsoft 365. Nothing installed on anyone's machine.
browser extensions
Published on the Chrome Web Store and Edge Add-ons. Pushed org-wide by MDM, or installed per person.
browser AI
Prompt capture runs on 166 assistant sites, before the request leaves the browser — the four below are the ones most teams start with. Providers outside that set are discovered and priced from workspace OAuth and network signals, without prompt capture.
siem & log forwarding
Every captured event can be forwarded to the tooling your security team already watches.
identity & sso
SSO through WorkOS covers Okta, Azure AD, Google Workspace and any SAML or OIDC provider.
enterprise deployment
Push the extension and the gateway through the management tooling you already run.
get started
Start with the workspace connector. It needs read-only OAuth and gives you the inventory before anything is installed.