Skip to content
Now taking design partners.Roadmap →

AI-agent & MCP governance

See every AI agent on every host, and what it could reach.

Sekeye pairs Drig, the thin read-only agent, with a blast-radius profiler, an exposure engine, a fleet console, and a remediation layer. Laptops and servers are one fleet on one catalog, because that is how an attacker sees them. Discovery, blast radius, prioritisation, and remediation ship today; governing what an agent may do, and catching one when it turns, are the next two phases.

Who this is for

100 – 2,000 hosts running AI agents? The pilot fits.

Laptops and servers both. If three of these four sound like your fleet, we should talk.

Fleet

100 – 2,000 hosts

Laptops and servers, counted as one fleet. Too big for scripts, too small for enterprise SKUs.

Surface

Running AI agents

MCP servers, coding agents and CLIs, agent skills, local models. Then packages, extensions, brew and winget underneath.

Exposure

Agents hold real credentials

Cloud keys, deploy tokens, a shell, and network egress, on developer machines and on production hosts nobody is watching.

Deployment

SaaS · self-host · air-gap

One console you run yourself, or ours, or fully air-gapped behind an offline licence. Data stays where your regulator says. CERT-In, DPDP, SEBI CSCRF, NIS2 and DORA evidence maps to clauses if you need it.