Why Unveilr
Find the AI agents you don't know about, then govern what they do — without slowing the teams that ship them.
Unveilr is the control plane for AI-agent actions: Discover → Guard → Govern → Prove. It turns AI tools, agents, MCP servers, prompts, and model usage into inventory, policy, and evidence your security and platform teams can act on — while keeping developers in a fast, familiar loop.
The problem it solves
| Reality today | What breaks |
|---|---|
| Copilot / Cursor / Claude write production code | Secrets, insecure patterns, and hallucinated deps land in PRs at LLM speed |
| Agents call MCP tools with broad scopes | One prompt injection or rug-pulled tool definition becomes data exfil |
| Shadow AI spreads repo by repo | No inventory, no owner, no audit trail when the board or auditor asks |
| Scanners pile up alerts | Security still can't prove what was allowed, blocked, or knowingly accepted |
Unveilr closes that gap: a map of your AI estate plus a gate that decides whether a change or a live tool call is still allowed to execute.
Value by outcome
For developers — stay fast, stay local
- One command:
unveilr scan— offline, deterministic, no account required. - Same findings in the terminal, IDE Problems panel, and PR annotations.
- Monitor Mode first: observe everywhere, enforce only when you're ready.
- Tenant-bound service-token login (
unveilr login --token …) when you want to upload results to the company control plane.
→ See Developer experience.
For AppSec / platform — one control plane
- Org-wide AI-BOM (CycloneDX export) across every connected repo.
- Diff-aware PR gates: judge only what the change introduces.
- Ingest Semgrep / CodeQL / garak into the same triage, blast-radius, and evidence model.
- Runtime Agent Gateway: allow · deny · approve · sanitize · rate-limit · agent tool scope — with hash-chained audit.
→ See Integrating within your company.
For CISOs / compliance — prove control
- Tamper-evident evidence ledger (verify + export).
- Coverage against 11 frameworks, with human attestation per control (automation never silently “passes” a control).
- Shadow-AI visibility and agent ownership as first-class artifacts.
→ See Prove.
Why this is more than “another AI scanner”
Scanner-only tools Unveilr
───────────────────── ───── ────────────────────────────
Find issues in a repo → Discover the AI-BOM across the estate
Fail a CI job → Guard at PR + Govern at every tool call
Export a PDF → Prove with a hash-chained evidence ledger
An AI-BOM describes. Unveilr also licenses the gate — at commit time and at runtime — and emits proof of what happened.
Console path: / (Overview)
Capture: KPI strip (repos, findings, agents, shadow AI), risk trend, recent
high-severity items.
Story it tells: “We can see AI risk across the company in one place.”