Endpoint AI Security · EPAIS

Govern every AI on every endpoint.

Statefold is a two-tier platform that discovers every AI tool your people use, enforces policy on the endpoint, decides which agents and privileges are allowed to run — and remembers all of it in a deterministic Hive Mind you can simply ask.

  • No LLM dependency
  • On-box enforcement
  • Offline-safe
Two executables. One light endpoint sensor, one management console. · 72-hour agent grants · Nothing leaves the box · Windows-first
The gap

Shadow AI is already inside your perimeter.

Copilots, chat tabs, IDE assistants, MCP servers and autonomous agents arrive faster than security can review them. The old stack was built for files and networks — not for prompts, tokens, and agents that act.

Unseen usage

You can't name the AI tools running on your endpoints, who runs them, or with what privilege. Discovery stops at the network edge.

Ungoverned agents

Anyone can spin up an agent and hand it credentials. Nothing stops a malformed prompt, an over-privileged tool, or a quiet exfiltration.

No memory

Prompts, answers, code, MCP calls, tokens and spend evaporate. When an incident lands, there's nothing to ask.

The platform

A light sensor on the endpoint. A console in command.

The agent enforces locally and keeps protecting even when disconnected. The console gives operators fleet-wide discovery, policy, governance and the Hive Mind.

StatefoldAgent.exe

Endpoint sensor

Observes every AI surface — proxy, browser, IDE, MCP, Bedrock, clipboard — classifies content with a pure-Python engine, and enforces on box.

StatefoldConsole.exe

Management console

Fleet telemetry, central policy, AI agent governance, discovery, coverage, and the Hive Mind — served behind one API with an embedded store.

Discovery

Every device, identity and AI touchpoint — agents, models, APIs and MCP servers — drillable to one endpoint.

Detections & DLP

Inline classification of prompts and responses across surfaces, with allow / alert / redact / block — before send.

AI Agent Governance

No agent runs until approved. The agent and its privilege are two separate decisions, each on a 72-hour grant that auto-expires.

Hive Mind

A deterministic memory of all AI usage — and a chatbot over it. Ask it anything; no model required.

Coverage & Posture

See exactly what's protected where, per surface, per group — and where the gaps are.

Security Validation

A red-team catalog and campaigns to prove the controls hold against prompt injection and exfiltration.

The Hive Mind

An enterprise memory that contains all.

Every prompt and question. Every answer, code generation and MCP query. Token usage, AI billing and license consumption. Snapshots, alerts and audit logs. It builds continuously from every touchpoint — and then you build a chatbot over it.

  • Deterministic fact graph — no LLM, stable and explainable
  • Live wiring: it learns as the fleet works
  • Nothing leaves the box — your memory stays yours
PromptsAnswersCodeMCP queries TokensBillingLicensesAlerts LogsSnapshots
Ask the Hive Mind
I remember every AI touchpoint across the fleet. Ask me about usage, billing, licenses, prompts, code, MCP, alerts — or who runs what.
Deterministic demo · no LLM · nothing leaves the box
Built to be trusted

Powerful by design. Quiet by default.

No LLM dependency

Classification, policy and governance are rule-based and deterministic. A local model can sit on top later — never an external API.

On-box enforcement

The endpoint blocks, redacts and halts locally. The verdict is a literal halt, not a dashboard note.

Offline-safe

Fleet sync is additive. Disconnect the endpoint and protection continues — never a dependency for safety.

Agent & privilege kill

An agent runs only if it and the privilege it seeks are both approved. Otherwise it's halted and killed.

72-hour grants

Approvals auto-expire. The request and the agent both die down — no standing access by accident.

Your data stays yours

The Hive Mind is local. Prompts, tokens and spend never leave the perimeter.

How it works

Four moves to AI under control.

  1. 01

    Enroll

    Drop the light agent on endpoints; it self-registers to the console with a scoped token.

  2. 02

    Observe

    Every AI surface is discovered and classified, attributed to a user, endpoint and privilege.

  3. 03

    Govern

    Approve agents and privileges separately; policy and grants enforce at the endpoint.

  4. 04

    Ask

    The Hive Mind remembers it all. Ask in plain language; get a deterministic answer.

Compared to the big boys

Built for the AI layer the others bolt on.

Purview and Defender govern files and email. EDR watches processes. SSE / CASB guard the network. Statefold governs the AI itself, on the endpoint, with a memory.

Capability Statefold Purview / Defender EDR (CrowdStrike · S1) SSE / CASB / Prompt-FW
Endpoint-native AI enforcement
Prompt / response DLP, pre-send
AI agent + privilege governance
Works offline / on-box
Deterministic memory of all AI usage
Token / billing / license visibility
No LLM dependency
● full◐ partial○ none

Bring your AI under control.

See Statefold discover, govern and remember the AI already running across your fleet.