Security for every AI agent your company runs.
See every agent. Govern every action. Prove what it did. GIRD is the control plane for the AI agents running across your company, on every laptop, server, cloud, and browser. One place to see them, one policy to govern them, and a tamper-proof record of everything they do.
There's a gap between what you believe is governed and what your agents can actually do.
On paper, AI agents follow your policies. In practice, they hold real reach, into source code, credentials, customer data, and systems of record, and most of that reach has no owner watching it. That distance between belief and reality is the Agent Authority Gap. GIRD is built to close it.
Agents stay inside the rules.
Policies, approvals and good intentions suggest every AI agent does only what it's supposed to, exactly as designed.
Agents can reach far more.
An agent inherits the access of whatever runs it, and can read, send, or act far beyond what anyone signed off on, quietly.
Belief meets enforcement.
GIRD enforces the real limits and records the result, so what you believe is governed is what actually is.
One control plane for every AI agent.
GIRD connects to where your agents already run and brings them under one roof, so security finally has a single place to see them, govern them, and prove what they did.
Every agent, every surface.
A live inventory of every AI agent across the company, known and shadow, each tied to a real person and team.
One policy per agent.
Decide what each agent can use, who it can talk to, how far it can delegate, and which skills it can inherit.
A record you can defend.
Every action lands in a tamper-proof audit trail, built for incident response, compliance, and liability.
| Agent | Surface | Owner · Team | Policy |
|---|---|---|---|
| code-assistant-07 | Mac · laptop | P. Nair · Platform Eng | Governed |
| support-copilot | Cloud · us-east | Support · Tier-1 | Governed |
| data-analyst-bot | Servers · finance | A. Rao · Analytics | Review |
| unknown-agent · browser | Browser · unmanaged | No owner, quarantined | Blocked |
One policy per agent, written as four plain-English rules.
Every agent gets a single master policy that says exactly what it's allowed to do. You set the rules once; GIRD enforces them on every laptop, server, cloud, and browser the agent touches, and blocks everything else by default.
Where it may go
Define the systems, services, and destinations an agent is allowed to reach. If it tries to go somewhere off the list, a credentials file, an unapproved endpoint, it simply can't.
What tools it may use
Approve the actions and tool-servers an agent is permitted to call. Everything else is denied by default, so a single poisoned input can't turn it loose on your systems.
Who it may talk to
Decide which agents may hand work off to which, and exactly how far that delegation can travel. No agent quietly recruits another to do what it can't.
Which skills it may inherit
Control the capabilities an agent can pick up over time. No silent privilege creep, an agent never gains powers you didn't grant it.
A preview of the capabilities that make up the platform.
Modular capabilities that work together, so you're not stitching point tools across your stack. Here are six of the nine, see them all on the Products page.
Agent Registry
See every AI agent in your company, known and shadow, each with a real owner and team.
Tamper-Proof Audit
A record of every agent action you can prove, built for liability and compliance.
Identity Sync
Connect Okta, Microsoft Entra ID, or Google Workspace. Every agent inherits your teams and policies.
MCP Registry
Approve the tool-servers your agents may use. Block everything else by default.
PII Protection
Catch sensitive data before an agent can send it anywhere it shouldn't.
Browser Guard
On the roadmap: stop unauthorized AI agents in the browser, and redact what they try to take.
Wherever your agents run.
Your own infrastructure, any cloud, every laptop, and the browser, all reporting to one control plane. Nothing locked to a single vendor or operating system. See each surface in depth.
Mac
Windows
Servers
Any cloud
Browser
Deploy on self-managed infrastructure, in your own cloud account, or as a managed service, your data stays in your environment.
Every agent gets a real owner, and your existing policies.
Connect the identity provider you already use. Every AI agent is automatically tied to a person and a team, and inherits the access policies you already trust. No orphaned agents. No shadow AI.
When an agent acts, your audit trail shows the agent did it, and who owns it. Not just “the user deleted the file.”
Built for the way agents actually spread.
Proof you can defend
A tamper-proof audit trail of every agent action, something no other platform offers. Built for the day you have to prove exactly what happened.
One policy, every surface
The same per-agent policy, tools, peers, delegation, skills, enforced on the laptop, the server, the cloud, and the browser. Not five disconnected tools.
Vendor-neutral
Works across your whole stack, every OS, every cloud, your own infrastructure. Never locked to one vendor's ecosystem.
Stage-honest. No badges we haven't earned.
We're early, and we say so. Here's exactly where we stand, how we handle your data, how we prove what happened, and what you can ask of us.
Your data stays yours
GIRD deploys into your own environment. We never see your prompts, your data, or your agents' work, only the policy decisions and audit records you choose to keep.
Coordinated disclosure
Found a security flaw in GIRD's own software or this site? See our responsible disclosure policy. We acknowledge within 2 business days, fix high-severity issues within 30, and credit good-faith researchers.
Compliance roadmap
We don't hold SOC 2 yet, and we won't claim it until we do. We'll publish certifications as we earn them, and handle your procurement intake (CAIQ / SIG / yours) during onboarding.
What is GIRD?
GIRD is the control plane for the AI agents running across your company, on every laptop, server, cloud, and browser. It gives security one place to see every agent, one policy to govern what each one can do, and a tamper-proof record that proves what they did.
What is Argus?
Argus is GIRD for the Mac. It gives security a live inventory of every AI coding assistant on your team's laptops, each tied to an owner, keeps credentials and sensitive files out of reach, catches sensitive data before it leaves, and keeps a tamper-proof record, deployed through your MDM with nothing for developers to install.
Which platforms does GIRD support?
Macs today, through Argus, with Windows on the roadmap, plus servers, any cloud (AWS, Azure, or Google Cloud), and the browser. Every surface reports to one control plane under one per-agent policy.
How is Argus deployed?
Argus deploys through the MDM you already run, Jamf, Microsoft Intune, Kandji, or Workspace ONE, with nothing for developers to install or change. It reports into the GIRD control plane alongside your servers, cloud, and browser.
Is Argus free?
Argus starts free for an individual and scales to team and enterprise tiers, which add a fleet-wide console, identity sync, and compliance support. You can download it for Mac today.
Where does our data live?
In your environment. GIRD deploys into infrastructure you control, and your data stays there. You decide which decisions and records to retain, and where they're stored, we don't pull your code, prompts, or customer data out to us.
What can GIRD see?
Only the decisions and records you choose to keep, for example, that an agent asked to take an action and whether it was allowed. We don't see the contents of your code, your prompts, or your customer data. The sensitive material stays inside your environment.
How do you prove what an agent did?
Every agent action is written to a record that's tamper-proof by design: entries can't be quietly altered or removed after the fact. Each action is tied to a real owner, so when an auditor or incident responder asks "who did this, and was it allowed?", you have evidence that holds up rather than a guess.
Are you SOC 2 certified?
Not yet, and we won't claim it until we are. We haven't begun a SOC 2 audit yet; when we do, we'll publish the report here the moment it's earned. In the meantime we're glad to share our current security posture and controls under NDA, and to complete your own security questionnaire during onboarding.
How do agents map to the people in my company?
In your company, every agent is tied to a real owner, a person and team from your own identity provider, and gets only the access it needs to do its job. So accountability is built in: an agent's actions trace back to an accountable human, and "the system did it" is never the end of the answer.
See GIRD on your own agents.
Bring the AI agents already running across your company under one control plane, and see, govern, and prove every one of them. Tell us what you're running and we'll tailor the walkthrough.
Thanks, we've got it.
We'll be in touch within one business day to set up your walkthrough.