About
Sekeye is a bet on governing AI agents where they run.
A thin, read-only agent on every host, laptop and server. A blast-radius profile for each AI agent and MCP server it finds. A curated exposure catalog, fleet-wide campaign response, and the credential-rotation plan attached. Self-hosted or SaaS. Priced for teams the incumbents ignore.
Beliefs
Four things we believe.
AI agents arrive sideways, with credentials and autonomy.
An engineer installs a coding agent on Tuesday and wires in three MCP servers by Thursday. Nobody filed a ticket. Each one inherits the shell, the filesystem, and whatever credentials the environment already holds, then updates itself without asking. Classic marketplace software arrived the same way; the difference is that this software acts on its own.
Nothing in the stack watches the agent.
Your EDR watches the OS and should keep doing it. Gateways govern the MCP traffic you route through them. SIEM reads logs after the fact. Which agents are installed, what they can reach, and whether they should be here is a different question, and it lives on the host where the agent runs.
The incumbents don't reach the mid-market.
Cortex, SentinelOne, Wiz, and the shadow-AI modules bolted onto them are enterprise-priced, cloud-hosted, and mostly US or Israeli. India GCCs, Gulf regulated buyers, and EU-sovereignty accounts get either a bad fit or no fit.
Independence is the moat.
We coexist with every EDR, we consume its telemetry where it exists and never depend on it. We ship self-hosted and air-gap. We are the posture and governance layer, priced like an add-on, not a platform.
Team
Small on purpose.
A small core team plus a rotating cast of specialist collaborators. Design partners are treated as engineering-adjacent, and every weekly call feeds the backlog. Sekeye is pre-launch and says so. If you're evaluating a pilot, or you're an analyst wanting more context, get in touch.