Platform
How RayShield works
RayShield secures the AI workforce already running on your endpoints — Claude Code, Cursor, Cowork, and the agents your teams build — and discovers what else is running. Four controls. None of them depend on the agent cooperating.
Pillar 1
Discovery
Passive sensor — TLS SNI/JA3 fingerprints from a network tap, or 14 SASE and MDM log formats forwarded from your existing pipeline. 215-service catalog, per-user attribution, agentic burst detection, change detection. Results from the first log ingest.
How discovery works →Pillar 2
Endpoint protection
NETransparentProxyProvider system extension transparently intercepts AI app traffic. AI-scoped name-constrained CA — cryptographically incapable of MITMing non-AI TLS. Content DLP (credit card Luhn, SSN, secret prefixes, custom regex), connector write blocking via bigram taint, credential sentinel injection.
How endpoint protection works →Pillar 3
Sandbox
Each agentic session boots its own Linux microVM on Apple Hypervisor.framework (libkrun) in under two seconds and is destroyed on exit. Deny-all egress enforced at the hypervisor via TSI — unbypassable by static binaries. Binary attestation, seccomp USER_NOTIF kernel audit, eight named behavioural detections.
How the sandbox works →Pillar 4
Fleet
Signed packages deployed through Jamf, Kandji or Intune — MDM profiles handle the system extension allowlist, NE activation and CA trust in one push. Policy is a TOML file in source control. Posture progresses from monitor → warn → block centrally without a reinstall.
How fleet management works →Data residency
Audit data stays on the device or in your own infrastructure. RayShield does not require agent data to transit our cloud. Content is inspected in memory and never persisted.
Platform support
macOS on Apple silicon is the current production platform. The rest of this table is published as it stands rather than as a promise.
| Platform | Status | Notes |
|---|---|---|
| macOS (Apple silicon) | Available | Full discovery, endpoint protection, sandbox and fleet. Deployed via Jamf or Kandji. Boot time under 2s. |
| macOS (Intel) | Confirm | Founders: verify and state |
| Linux | Confirm | Founders: state a target quarter |
| Windows | Confirm | Founders: state a target quarter |
| CI/CD runners | Confirm | Founders: have a written position before launch |
Where a quarter cannot yet be committed, publish "on the roadmap, not yet scheduled" rather than "coming soon".
Common questions
What happens when a destination is blocked?
The connection returns an explicit error the agent can read and surface to the developer. The session continues; it does not hang or fail silently. The denial is logged with the destination and the task context that produced it, so the reviewer sees why the agent wanted it.
How long does a policy change take?
Policy is a TOML file in source control. A change is a commit and a push — the fleet picks it up without a reinstall and without a device touch. Approval can be delegated to engineering leads rather than routed through security for every entry.
Does the sandbox slow the agent down?
The microVM boots in under two seconds on Apple silicon, once per session rather than per command. Syscall interception adds overhead at process-execution and connection points, not to compute inside the sandbox. Ask us for the current benchmark on your hardware profile during the pilot.
What happens if RayShield itself fails?
Attestation and policy enforcement fail closed — a session that cannot verify its manifest does not run. Posture is configurable per deployment stage, so during monitor mode a failure degrades to recording rather than blocking. We will walk through the specific failure modes with your team rather than summarising them here.
What data leaves the device?
Audit data stays on the device or in your own infrastructure. Agent data is not required to transit our cloud. Inspected content is held in memory only and is never persisted.
Protect your AI workforce and find what else is running
Endpoint DLP activated from day one. Discovery results within hours of first ingest.