SVALIN AI Governance Platform

How Svalin works under the hood.

Ultra-light endpoint engine

Zero workflow alteration

Engineers keep using Cursor, Claude Code, Gemini CLI, or custom MCP servers without switching tools or changing their terminal habits.

Account-agnostic governance

Developers switch between personal and corporate AI accounts constantly. Svalin governs at the process and device layer: regardless of which account or API key is active, it sees corporate code touched by AI on the device — whether or not the developer is signed into a corporate account.

5-minute MDM deployment

Deploys silently: macOS via Jamf, Kandji, or Intune; Linux via Intune or your existing configuration management. An ultra-light daemon with near-zero CPU and memory overhead.

local agent · org policy
SVALINLocal Agent
Overview
Servers
Skills
Policy
Logs
⟳ Refresh from Platform
Org policy
Org IDec68712c-ff36-… Versionf7e85384938fe… Updated04/08/2026, 15:22

Forensic Speed

Repository & file-bound filtering

Instantly filter sessions that touched a specific Git repository, branch, or critical file path. Pinpoint the exact AI conversation, tool call, or prompt that introduced a security flaw or caused a production outage.

Process-tree reconstruction

Svalin uses process lineage and PID tracking to automatically reconstruct the full conversation chain — no endless manual log stitching.

platform · log explorer
acme/crm-sync
e.g. .env or *.csv
Last 30d
Governed Degraded Ungoverned Vendor-limited
1 conversation
ConversationAgentDeviceOS user
aca734f5-2521-4c…Claude Codepriya-mbppriya

Real-time analysis

Beyond passive log dumps

Logs aren't stored just for an end-of-year security audit. Svalin analyzes tool calls, terminal commands, and file access in real time to highlight risky agent behavior as it happens.

Causal session reconstruction

Automatically links raw file reads, bash execution, and HTTP requests back to the specific session, prompt, and skill file that initiated them.

platform · conversation timeline
Session startfilesystem · initialize
LLMclaude-opus-4-20250514 — 7.1K tokens, tool_use
Tool callfilesystem/write_file
LLMclaude-opus-4-20250514 — 6.6K tokens, end_turn

Accountability

Who made the call?

A clear separation between human developer actions, explicit slash commands, background agent loops, and auto-invoked MCP skills.

Skill & prompt provenance

Tracks the exact chain of execution — from prompt input to tool output — giving security teams a verifiable, audit-ready trail.

platform · incident detail
Risky activity detected on b16ee71f…
High Open Device: priya-mbp
2 conversations impacted
cvn_0c6a9586-927a-4437-a848-69530180c2951 event · 03/08/2026, 14:39:46
cvn_d3331372-4325-4c29-a99a-218df8da2d961 event · 02/08/2026, 18:06:21
2 events
Tool callbuilt-in-filesystem/edit_file · index.html
Tool callbuilt-in-shell/shell_exec

Shadow AI & tool registry

Automatic discovery

Inventories every AI CLI agent, IDE extension, and MCP server running across your developer fleet.

Inline guardrails

Block unapproved tool calls, prevent credential leakage, and enforce local boundaries before destructive commands or unauthorized API requests hit the network.

AI coding agents across the fleet · 8 clients
CLIENTVERSIONSDEVICES
Claude Codeclaude-cli
(v2.1.119, v2.1.139, v2.1.140, v2.1.185, v2.1.187, v2.1.221)
6
Claude Desktopclaude-desktop
(v1.22209.3, v1.24012.9)
5
Gemini CLIgemini-cli
(v0.26.0, v0.50.0)
5
Codex CLIcodexNOT GOVERNED
2
GitHub CopilotcopilotNOT GOVERNED
2
JetBrains JuniejunieNOT GOVERNED
2
OpenCodeopencode
(v1.14.48, v1.18.11)
2
Google AntigravityantigravityNOT GOVERNED
1

If policy verification fails, Svalin fails closed.

The Svalin data flow.

How raw endpoint actions become evidence.

Developer device
Cursor / Claude Code Local MCP servers Local policy engine · 0 latency
Svalin engine
In-flight causal telemetry PID-based session reconstruction
Dashboard
Real-time risk alerts Incident forensics & audits
Capture

The ultra-light local daemon captures tool invocations and file modifications directly on the device — independently of developer account context.

Analyze

Telemetry is correlated into causal session graphs and process hierarchies, identifying intent, repository impact, and risk scores.

Govern & investigate

Block violations inline, query repository-level incidents in seconds, and automatically export audit-ready evidence.

What Svalin doesn't touch.

The part a security review — or a works council — checks first: what the agent reads, what leaves the device, and what happens to a prompt when capture is off.

01

Detects everything, reads only what it governs

Svalin inventories which AI tools are installed and running, and reads configuration and activity only from the agents it governs. Never your source code, personal files, or any other file on the machine.

02

Prompt capture is opt-in

Prompt content is captured only when your policy turns it on. With it off, the words in a prompt never leave the device — Svalin still records what a session did (tool calls, files touched, timing), just not what was typed.

03

Encrypted, with controlled decryption

When capture is on, prompt content is encrypted at rest. Decryption is gated by policy and reason-logged, with employee notification — no one reads a prompt silently.

See Svalin running on your local stack.
Test our 5-minute deployment in a risk-free 3-month design partner pilot.

Apply for Design Partner Program