SVALIN AI Governance Platform
Coverage

Coverage, tool by tool.

What Svalin sees, what it can block, and where the limits are. Every vendor exposes a different surface — some hand us the signed-in account, some expose nothing at all. This page says which is which.

Platform support

Which operating systems the Svalin agent runs on.

macOS
Fully supported

Running in design-partner pilots today.

Linux
Fully supported

Running in design-partner pilots today.

Windows
On design partner demand

No committed date; prioritised by design partner demand.

PromptsThe text a developer typed. Captured only when your policy turns it on.
ActionsTool calls, shell commands, file access.
IdentityWhich account authorized the session.
BlockSvalin stops the action before it runs.
RedactSvalin strips sensitive content before it reaches the model.

Governed

Svalin captures, attributes, and enforces.

ToolPromptsActionsIdentityBlockRedact
Cursor IDETranscriptYesEmail + entry pointYesYes
Cursor CLITranscriptYesEmail + entry pointYesYes
Claude CodeLLM proxyYesOrg, account, emailYesMCP traffic only
Claude Code in Claude DesktopTranscriptYesAccount UUIDYesMCP traffic only
Claude Desktop chatTranscriptYesAccount UUIDYesYes
Gemini CLILLM proxyYesGoogle account + domainYesYes
opencodePlugin hooksYesProvider + modelTool calls onlyYes

Claude Code — Anthropic's hook API supports block and log, not redaction. Redaction applies to traffic through wrapped MCP servers.

opencode — bring-your-own-key across 75+ providers. An API key carries no account identity, so there is no signed-in user to resolve. Svalin records which provider, model, and endpoint received the code — the question that actually matters for data governance. opencode also exposes no pre-inference hook, so Svalin blocks tool execution rather than the prompt itself.

Partial

Cowork sits outside every audit trail Anthropic offers.

Cowork runs inside Claude Desktop with no separate installation. Verified August 2026: it exposes no hooks and bypasses local proxy interception, so Svalin cannot govern it on the device today.

It is also excluded from Anthropic's Audit Logs, Compliance API, and data exports — on every plan tier, including Enterprise. Conversation history stays on the user's laptop.

The one visibility path is OpenTelemetry. It's admin-configured, Team and Enterprise only, and needs a collector your network allowlists for outbound access from the Cowork sandbox. On Pro and Max there is no path at all.

Enterprise defaults Cowork off. Team defaults it on and requires an admin to disable it. The setting is organization-wide, so it can't be scoped to a single team — you enable it for everyone or nobody.

Svalin can ingest your Cowork OpenTelemetry stream. Available on request for design partners.

Detected, not governed

Svalin inventories these across your fleet.

ToolStatus
Codex CLIFull support on roadmapNo committed date; prioritised by design partner demand.
GitHub CopilotFull support on roadmapNo committed date; prioritised by design partner demand.
AntigravityFull support on roadmapNo committed date; prioritised by design partner demand.
WindsurfDetection only
JetBrains JunieDetection only — no local governance surface exists
Meta Muse CodeDetection only — no built-in compliance surface, so no further plans for now
CoworkOTel ingestion on request — no on-device governance available

Don't see your tool?

Coverage tracks what each vendor exposes. If your team runs something not listed, tell us.