Agent and runtime sources
Local collectors and provider APIs contribute declared configuration, access references, usage signals, timestamps, and source health.
See supported Codex, Claude Code, and Cursor signals, which links are causal or correlated, and where evidence is missing — with local-first, signed evidence and no secret values.
Local-first evidence for supported AI-agent sessions and actions — causal, inferred, or missing, never blurred.
Local-first. No secret values. Causal, inferred, or missing — never blurred.

Example audit snapshot · macOS (first endpoint wedge)
kubectl against production using a privileged context — and can you prove it?Finding an installed agent is only the first step. BeProof preserves the strongest supported links, labels inference and ambiguity, and creates a coverage gap wherever the chain cannot be established.
Inspect the Action ChainSupported local history can identify sessions and automation events.
Explicit-scan process ancestry for supported CLI tools; not continuous coverage.
Metadata references can be discovered, but per-action lineage is not universal.
Repository, project or configured endpoint context where the source exposes it.
Allow, deny or remediation is shown only when the enforcing product reports it.
Current boundary: direct CLI process evidence is explicit-scan sampling on macOS. The continuous observer remains gated, so BeProof does not claim automatic or historical process coverage.
BeProof turns endpoint-level AI signals into structured evidence your team can review, approve, export, and verify.
Action Chain is captured from the live macOS product using local Codex automation history evidence. It does not represent continuous process observation; synthetic external-control data remains labelled separately in the sample incident bundle below.
Endpoint controls can block. Identity controls can restrict. Admin APIs show their own slice.BeProof preserves independent, verifiable evidence across those gaps.
No single endpoint, identity, or agent platform sees the whole chain. BeProof reconciles the evidence available from those sources, leaves unsupported inputs visible, and never presents a risk finding as proof that an action was blocked.
Local collectors and provider APIs contribute declared configuration, access references, usage signals, timestamps, and source health.
Endpoint, identity, and vendor-native controls remain responsible for allow, warn, deny, and remediation decisions.
BeProof preserves source attribution, confidence, coverage gaps, review decisions, and independently verifiable evidence exports.
Start with concrete evidence available in the current pilot. Every source-dependent, sampling-only, or unsupported link keeps its boundary instead of being presented as a stronger claim.
Discover supported Codex, Claude Code, Cursor, and MCP configuration surfaces on macOS with source and collection metadata.
Preserve history-backed sessions where supported sources expose them. Cursor activity remains explicitly correlation-backed.
Classify supported CLI activity during an explicit scan window without claiming continuous or historical process observation.
Export a redacted evidence package whose payload, manifest, and Ed25519 signature can be verified offline.
Windows endpoint attribution and production external-control adapters are roadmap scope, not capabilities included in the current macOS pilot.
A pilot should end with evidence your security and compliance teams can actually use.
BeProof turns scattered AI-agent signals into evidence your team can review, explain, export, and verify.
Which agents, assistants, automations, and MCP servers were found on employee workstations.
Which grants, credential references, connected systems, and permission paths need review.
Which usage events, run histories, or activity signals were available for verification.
Which sources were missing, unavailable, partial, stale, or consent-gated.
Which findings were approved, rejected, assigned for remediation, or accepted as risk.
Which evidence package can be shared with security, compliance, or audit reviewers.
Inspect the deeper multi-source causal fixture, then run offline verification on a separately signed, redacted demo bundle. Both use synthetic example data — never live customer telemetry.
beproof verify-incident-bundle --artifact ./incident-evidence-bundle-signed-demo.json --public-key ./beproof-demo-signing-key.jsonThe signed demo returns status: verified and detects payload, manifest, or signature tampering. It uses a public deterministic demo key, so it proves integrity mechanics — not customer or device identity.
Trust boundary: the multi-source causal fixture demonstrates attribution structure and intentionally keeps placeholder signature values. The signed demo is cryptographically valid but synthetic and signed by a documented demo key. A real customer bundle must be produced by beproof export-incident-bundleand verified against that endpoint's trusted public key.
BeProof does not silently pass incomplete audits. It separates presence, access, observed activity, and missing evidence into a workflow security teams can review.
Missing evidence does not become a clean report. BeProof separates verified facts from correlations, review decisions, planned external-control outcomes, and coverage gaps.
AI agents have moved from chat to action. Employees now connect AI tools to files, browsers, SaaS apps, local workflows, credentials, APIs, and automation systems. But most security stacks still track users, devices, SaaS seats, and network events — not which AI agents exist, what they can access, what was used, and where evidence is missing.
Agents no longer just answer questions. They summarize work data, operate across apps, trigger workflows, and connect to internal systems.
Credentials, OAuth grants, MCP servers, browser sessions, SaaS permissions, files, APIs, and local automations create access paths that are hard to review together.
Admin consoles show seats and settings. They rarely prove what exists locally, what was granted, what was used, or where the audit cannot make a clean claim.
BeProof gives security, compliance, IT, and risk teams a shared evidence layer instead of fragmented screenshots, policy attestations, and incomplete SaaS admin exports.
Reconcile available endpoint and provider evidence without treating any single source as complete truth or claiming unconnected identity and security controls are covered.
Review credential references, cloud grants, connected systems, and permission paths.
Produce reviewable evidence packages for security reviews, SOC 2 readiness, ISO readiness, and internal audits.
BeProof is designed for security-led rollout on employee workstations — from a focused pilot group to MDM-managed fleet deployment, with provider-neutral evidence adapters added only when their source and privacy boundaries are verified.
First endpoint wedge: macOS evidence for local AI agents, MCP servers, credential references, and automation workflows — not the product boundary.
BeProof collects local AI-agent surfaces, MCP configs, credential references, and usage evidence on employee endpoints. macOS is the first verified collection surface.
EDR, DLP, identity, and vendor-native products remain responsible for enforcement. BeProof records their outcomes only when attributable source evidence is available.
Shared reports and fleet summaries include findings, review status, and coverage gaps — not raw secrets from endpoints.
Deploy focused pilots through existing device management, then review fleet posture and verification metadata without pulling full endpoint dumps into the cloud.
When auditors or internal reviewers ask how your company governs AI-agent usage, BeProof gives your team a repeatable evidence package: inventory, access review, findings, exceptions, coverage gaps, and signed exports.
BeProof complements SOC 2, ISO 27001, and internal security programs. It does not replace GRC, IAM, EDR, DLP, MDM, or SaaS administration.
Security, compliance, IT, and risk teams at companies where employees use AI agents, assistants, MCP servers, and automations across workstations, SaaS tools, and local workflows — especially when audit evidence is fragmented across SaaS admin, policy attestations, and endpoint blind spots.
Start with a 30-day pilot on a focused endpoint group (macOS available today). Install the BeProof app on workstations or roll out via MDM for managed fleets. The admin console supports fleet enrollment, review workflows, and signed summary ingest.
No. BeProof complements SOC 2, ISO 27001, and internal security programs. It adds AI-agent-specific evidence across the gaps that GRC, IAM, EDR, DLP, MDM, and SaaS administration do not fully cover.
No. BeProof is an independent evidence and assurance layer, not an endpoint enforcement product. As external-control adapters become available, their allow, warning, denial, or remediation results will be preserved with source attribution. A finding alone is never presented as proof that an action was blocked.
By default, sensitive collection stays local. Shared exports and fleet summaries use metadata, findings, review decisions, coverage gaps, and verification manifests — not raw secret values.
Workstation scanning, AI-agent inventory review, access path review, findings triage, coverage gap reporting, exception workflow, and a signed evidence export your security and compliance teams can review.
Scan a focused workstation group, review AI-agent presence and access paths, identify coverage gaps, and export an evidence pack for security and compliance review.
At the end of the pilot, your team receives an AI-agent inventory, access review summary, findings review, source-attributed coverage gap register, exception log, and independently verifiable evidence package.
Scan a small group of managed workstations
Review agents, automations, access paths, and coverage gaps
Map findings to internal security controls
Export an evidence pack for security and compliance review