In development
One machine answers for itself.
Pro answers for all of them.
Fleet attestation, credential exposure across every developer, history that outlives a rotated transcript, and policy you can prove held. Built with design partners rather than guessed at — nothing on this page ships yet.
Cross-vendor · separate install · hosted first, your own cloud later
BINARY ATTESTATION 33 genuine 1 unsigned ← alerts nathan-mbp claude-code no signature EXPOSURE 4 critical credentials, fleet-wide Stripe key 31 days shared by 3 people AWS key 4 days 1 person POLICY no critical credential > 24h FAILING since 2026-07-24 evidence ↗
Illustrative. Nothing here is a real fleet.
The gap
The free tool is complete for one developer and structurally incapable of these three. That is precisely what Pro is.
Whose agents did that?
A credential in your own history is a personal problem. The same credential in four developers’ histories is an incident, and the cost of rotating it lands on someone else. One machine cannot tell those two apart, because it can only ever see one of them.
Is this getting worse?
Transcripts rotate and get deleted, so the evidence expires before anyone asks the question. Trend, regression and time-to-rotation need storage that outlives the transcript — which the free tool deliberately does not have.
Can you prove it held?
A read-only tool reports what it found today. It cannot assert that a rule was in force for a quarter, and it cannot hand an auditor, a customer or a board the evidence that it was.
Planned
Every capability is the fleet version of something free
Nothing is removed from the free tool and nothing is held back to sell Pro. Each row is one capability: what a single machine can already do, and what the fleet adds on top of it.
Is every agent genuine?
FreeVerifies the agent binaries on this machine against their publisher’s signature.
ProEvery enrolled machine, continuously. Alerts on unsigned, wrong publisher, invalid signature or a version below the floor you set — and exports as evidence.
What credentials reached the model?
FreeCredentials in your own command history, grouped by fingerprint and ranked for rotation.
ProThe same across every machine, deduplicated so one shared key is one incident, not twelve — plus the rotation lifecycle a local tool cannot see, because rotation happens somewhere else.
Did the rule actually hold?
FreeReporting only. A read-only tool can describe a machine; it cannot assert a rule over one.
ProWrite it once — no critical credential in agent context for more than 24 hours — then show the interval it held, the moment it broke, and the evidence for both.
Can the agent audit itself?
FreeYour agent queries your own history in-session over stdio. Free permanently — it is not a trial.
ProThe same interface, answering across the fleet. The agent can ask whether the command it is about to run resembles one already flagged on another machine — and get an answer before it runs it, not after.
Is the trend improving?
FreeWhatever is still on disk. Deleted or rotated transcripts are simply gone.
ProRetained past rotation, so trend, regression and time-to-rotation become numbers you can hold a team to rather than an impression.
Who finds out, and when?
FreeA native notification on the machine that found it, once per credential.
ProWebhook, Slack or SIEM, deduplicated fleet-wide — twelve developers with the same leaked key raise one alert, routed to whoever owns the key.
Enterprise
What larger organisations add
The same product, with the controls a stratified organisation needs. Not a separate build.
Hosted is built first and is the default. Bring-your-own-cloud is the enterprise tier. Air-gapped hardware is out of scope.
- SSO, SAML, SCIM
- Directory-driven enrolment and deprovisioning, so leavers stop reporting the day they leave.
- RBAC
- An engineer sees their own. A lead sees their team. Security sees all. The default matters as much as the mechanism.
- Audit log and export
- Who looked at what, itself exportable. Signed, timestamped reports for auditors.
- Your own cloud
- The data plane runs in your AWS, GCP or Azure account. Your records never transit our infrastructure.
Commitments
Four things Pro will not do
- Make the free tool worse. Nothing free today moves behind the paywall — not now, not later. Pro adds what a single machine cannot do; it never removes what a single machine already did.
- Sell better detection. Same detectors, same rules, same accuracy. Selling better detection would mean the free version is knowingly worse than it could be.
- Change the free tool. Pro is a separate install. The free CLI gains no network code and no awareness Pro exists, so it can keep an absolute promise rather than a qualified one.
- Sit in the execution path. It cannot block a command or change a result. Read-only cannot break your workflow, and that guarantee is worth more than the convenience.
Questions we get
Before you ask
What does it cost?
What leaves the machine?
Do I have to install something new?
When?
Can it rotate credentials for me?
Design partners
Tell us what you actually need
A small number of teams are shaping this. If any of it is a problem you have, we would rather hear it now than ship the wrong thing.
- How many developers, running which agents?
- Is the driver cost, credential exposure, or an audit you have to pass?
- Hosted, or must it run in your own cloud account?
No newsletter, no drip sequence. A reply from a person.