SVALIN AI Governance Platform
Anatomy of an audit

The four layers underneath every event you'll show your auditor.

What happens between the moment a developer asks Cursor a question and the moment a compliance officer signs off on the quarter — captured, in order, in your tenant.

Phase 01

Local context interception.

Svalin deploys silently via corporate MDM. The lightweight background daemon hooks process execution loops at the system layer, identifying active LLM tools without adding millisecond performance overhead or interrupting engineering speed.

local agent · overview
Local agent overview — running, v0.5.0-prod, detected Claude Desktop, Claude CLI, Gemini CLI and Cursor
Phase 02

Cryptographic execution reconstruction.

Every tool use, spawned sub-agent and terminal mutation is reconstructed sequentially. Svalin creates a real-time, chronological trace ledger of precisely what actions an agent requested and exactly what it touched.

platform · conversation timeline
Conversation timeline with session starts, LLM token usages and shell exec blocks across milliseconds
Phase 03

Automatic incident creation.

When the trace ledger detects a policy break — profile tampering, an unsanctioned MCP server, a credential read — Svalin opens an incident, links the triggering telemetry event, and assigns an owner. If the device self-heals (a tampered shell profile reverts, an unknown MCP server disconnects) the incident closes itself with the resolution trail intact. No false-positive triage queues.

platform · incident detail
Profile tampering incident — severity high, dismissed status, with the triggering profile_tampered telemetry event linked and the full JSON payload showing the affected governed variable
Phase 04

Centralized security log analysis.

Telemetry data structures map instantly to a centralized ledger. Every process lifecycle event is structured as a cryptographically validated JSON payload, providing the raw foundational evidence your GRC and security engineering teams need to satisfy DORA and ISO risk tracking mandates on demand.

platform · agent events
Log explorer — agent events with event volume bar chart and validation chain marked valid
How it works

From MDM rollout to audit, in four moves.

Most security teams have the registry populated within their first week. Most cut their first compliance evidence pack inside the first quarter — without ever touching an engineer's laptop.

Step 01

Ship the agent through MDM.

Push the Svalin agent to every developer device in the same wave as your other endpoint software — Jamf, Kandji, Intune, or any tool that can drop a signed pkg. Engineers see nothing. The agent enrolls itself, identifies the AI coding tools on the machine, and starts capturing.

▸ MDM · svalin-agent-2.4.1.pkg
deployment · Jamf Pro
policy Svalin / All-Macs
scope: 247 devices
package: svalin-agent-2.4.1.pkg
deploying… 233 / 247 enrolled
active · reporting to eu-central-1
Step 02

The registry fills itself.

Within hours, the platform knows every governed device, every AI coding agent installed on it, and every MCP server those agents reach for. No survey. No questionnaire. No engineer told to log anything.

▸ Registry · devices · agents · MCP servers
registry · live
Governed devices233 / 247 Cursor181 devices Claude Code142 devices GitHub Copilot198 devices Windsurf24 devices MCP servers seen31 unique Coverage● 94.3%
Step 03

Incidents, not log floods.

PII reads, credential leaks, policy violations and unknown MCP servers all surface as incidents — triaged, assigned, and resolved in the platform. The rest of the firehose stays in the timeline, searchable when you need it.

▸ Incidents · PII · credentials · policy
incidents · last 7d
SVL-118credential.readclaude on MBP-A1742● open
SVL-117pii.emailcursor on MBP-3318● review
SVL-116mcp.unknownclaude on MBP-Q221● review
SVL-115credential.readcopilot on MBP-0048● resolved
SVL-114pii.addresscursor on MBP-7711● resolved
Step 04

Audit — already done.

When the auditor asks, hand them a signed, timestamped report mapping every relevant event to your SOC 2 / ISO 27001 / EU AI Act controls. Generated in seconds. Delivered as a PDF, a JSONL bundle, or both. The compliance work was a side effect of running the platform.

▸ Evidence pack · SOC 2 · CC7.2
evidence pack · 2026-Q1
FrameworkSOC 2 Type II Period2026-01-01 → 2026-03-31 Devices in scope233 Tool calls captured52,634,118 Incidents resolved14 (all closed) Signed bysvalin.evidence.v2 Hash0xa1c8…f24e Status● ready to export

See what AI coding agents accessed yesterday.
Without asking a single engineer.

Request a demo