Fleet
100 – 2,000 hosts
Laptops and servers, counted as one fleet. Too big for scripts, too small for enterprise SKUs.
AI-agent & MCP governance
Sekeye pairs Drig, the thin read-only agent, with a blast-radius profiler, an exposure engine, a fleet console, and a remediation layer. Laptops and servers are one fleet on one catalog, because that is how an attacker sees them. Discovery, blast radius, prioritisation, and remediation ship today; governing what an agent may do, and catching one when it turns, are the next two phases.
01 · Drig agent
A thin Go binary reads the AI layer, MCP servers, coding agents and CLIs, agent skills, local models, alongside the classic base of packages, extensions, and OS package managers. Read-only, pull-only, authenticated over TLS (mTLS lands in a hardening pass before GA), no listening ports, no LLM on the box.
Read more →
02 · Exposure & blast radius
A blast-radius profile per MCP server and agent, filesystem scope, credential names in its environment, shell access, network egress, matched against live threat intel that includes AI-infrastructure CVEs and CISA KEV entries. Semver-aware, explainable, no proprietary score layered on top.
Read more →
03 · Campaigns
One click, live progress bar, exposed-host list. Retro-match re-runs against current inventory with no rescan on the box. Design target: 1,000 hosts, 95% reported in 10 minutes, being validated with pilot data.
Read more →
04 · Remediation
Per-finding removal and upgrade paths, plus ordered credential-rotation playbooks per exposed host. Governing what an agent is allowed to call is the next phase, and it is labelled as such.
Read more →
Who this is for
Laptops and servers both. If three of these four sound like your fleet, we should talk.
Fleet
Laptops and servers, counted as one fleet. Too big for scripts, too small for enterprise SKUs.
Surface
MCP servers, coding agents and CLIs, agent skills, local models. Then packages, extensions, brew and winget underneath.
Exposure
Cloud keys, deploy tokens, a shell, and network egress, on developer machines and on production hosts nobody is watching.
Deployment
One console you run yourself, or ours, or fully air-gapped behind an offline licence. Data stays where your regulator says. CERT-In, DPDP, SEBI CSCRF, NIS2 and DORA evidence maps to clauses if you need it.