Security and intelligence for AI operators

Security starts with visibility.

People install AI tools, set up agents, move on, and the agents stay. Surwhale finds every one of them on your endpoints and your network, shows what each does, and tells you which ones put data or systems at risk.

01 · What changed

Agents changed what security has to watch.

Your existing tools watch users and servers. An AI agent is neither. It runs with a person's credentials, acts like a service, and nobody signed it in.

1 / 3 Agents act, they don't just answer.

A chat assistant returns text. An agent opens tickets, edits files, calls APIs, sends mail and deletes things. A wrong action costs more than a wrong answer, and it is already done by the time anyone reads the log.

An assistant told to "clean up the staging bucket" deleted 400 objects that were still referenced by production.
2 / 3 Anyone can start an agent.

Starting an agent takes one command on a laptop. No procurement, no ticket, no review. Employees run agents on their own devices with their own accounts, and the organization cannot see them, let alone control what they touch.

An analyst gives a desktop agent access to their mailbox and the shared drive to sort invoices. It runs every morning with their credentials. IT finds out when it emails a supplier.
3 / 3 Nobody switches agents off.

Agents get set up in dev and prod for a project, a trial, a team. The project ends, the person moves on, and the agent stays: still running, still holding credentials, with nobody responsible for it.

A code-review agent still runs six months after the engineer who set it up changed teams, with a write token nobody rotated. After a tool update it stops suggesting and starts committing its own fixes to main. One of them removes an input check in the payment service.
02 · The technology

Powered by two technologies.

Endpoint Observation watches your devices. Network Analysis watches your network. Together they give you one picture of every AI tool and agent in the organization.

Endpoint Observation

Which AI runs on your devices, and is it allowed?

Every laptop is a place where an employee can install an AI desktop app, an IDE assistant or a local model runner in under a minute. Endpoint Observation keeps an inventory of what is installed and used, checks it against your policy, and shows where company data goes.

  • Flag employees using unauthorized tools
  • Assess data security risk from AI usage
  • Enforce policy compliance per device
Endpoint Observation in detail
Finding · endpoint
devicelaptop-042 · finance
observedIDE assistant, approved AI chat, unapproved AI desktop app
usageDesktop app active on 9 of the last 10 workdays
data3 spreadsheets uploaded to an external model API, incl. Q3-close.xlsx
policyFinance devices: approved tools only
riskHigh · financial data leaving the company before disclosure
Details are representative and not tied to a specific customer.
Network Analysis

Which agents talk on your network, and to whom?

Agents leave a trail on the network: who they call, how often, with which credentials. Network Analysis finds every agent from that trail, including the ones set up by people who have since moved on, and shows what each one is doing.

  • Detect and delete rogue and forgotten agents
  • Block unwanted outbound communication
  • Alert on agents targeted by outside attacks
Network Analysis in detail
Timeline · network
mar 04Engineer deploys review-agent for the team, using a personal repo token
may 12Engineer moves to another team. Nobody takes over the agent.
jun – sepAgent keeps reviewing every pull request. Token still valid, calls an external model API.
sep 20First connection to a host nobody on the team recognizes
findingAgent with no owner, credentials of someone who left the team, unexplained outbound traffic
actionOutbound blocked · owner assigned · token replaced with a scoped one
Details are representative and not tied to a specific customer.
03 · How it works

See it, understand it, then decide.

You cannot control what you cannot see. Enterprise builds the picture first, then attaches evidence to every finding so the decision is yours and easy to make.

01 · Discover

An inventory that updates itself

Every AI tool on every device and every agent on the network, found from what actually runs and talks, not from what people remember installing.

02 · Understand

Behavior, not just presence

For each one: who started it, what it touches, where it sends data, which credentials it holds, and whether any of that is in policy.

03 · Decide

Findings ranked, evidence attached

You see the process, the connection, the file. Approve, contain or remove from one place, with a record of who decided what.

04 · Scenarios

What this looks like in practice.

Three patterns we designed Surwhale around. Each one is common, quiet, and invisible to the tools most organizations already run.

Network

The reviewer that outlived its owner

Situation
An engineer set up an AI code reviewer for the team and wired it to the repository with their own token. Six months ago they changed teams.
What visibility showed
The reviewer still ran on every pull request with that token. Two more agents, left behind by people who had since left the company, ran the same way. None had an owner.
Outcome
Owners assigned or agents removed, personal tokens replaced with scoped service credentials, and a standing rule that every agent has a named owner.
Endpoint

Finance and the free tier

Situation
The company approved one AI chat tool. An analyst preferred a free desktop app for spreadsheet questions.
What visibility showed
Quarterly close files uploaded to an external model API from a finance device, in the week before results were announced.
Outcome
Policy applied to finance devices, the analyst moved to the approved tool, and legal got a clear timeline instead of a guess.
Network

The agent with admin

Situation
An ops agent was set up to restart services on alerts. To save time it received an admin token.
What visibility showed
The agent read secrets it never needed and, after a tool update, began contacting a new host on every run.
Outcome
Scope cut to the three services it restarts, the new destination blocked, and an alert set for any change in its behavior.

Details are representative and not tied to a specific customer.

See it yourself · Personal

Want to see it before the demo? Run it on your own computer.

Personal is Surwhale for a single computer, free for personal use. Install it on your own laptop and within minutes you see what it finds: the AI tools, the agents, what they reach, what they send out. The same findings, in the same words, that we show at enterprise scale.

Your device · first run
tools4 AI tools installed · 3 used this week
agents1 background agent · started from a script 23 days ago
data12 files sent to model APIs in the last 7 days
reaches1 tool reading mail and calendar
worth a lookthe agent nobody remembers starting · the files you did not mean to share
Example output. Yours will show your own device.
05 · How we work

Built to be trusted by the people who run things.

Evidence with every finding

An alert shows what we saw: the process, the connection, the file. You decide with the facts in front of you.

Plain language

A finding says what happened, why it matters and what to do. No score theater, no dashboard you need training for.

Built by people who build agents

We research AI security and run agents ourselves. We know where they break, because we have broken them.

A direct line

You talk to the engineers who built the product, before and after you buy it.

Enterprise in detail     About Surwhale

Demo

See what your agents are doing today.

Thirty minutes with an engineer. Bring one environment you are unsure about and we will show you what visibility changes.

Schedule a demo