Every AI surface.
Governed from one place.

MCP clients, AI API proxies, browser-based AI services, vibe-coding platforms, SaaS admin APIs, identity providers, SIEM destinations. No agent code changes. Here's the full map.

11MCP clients
6AI API proxies
12Browser services
7Vibe-coding platforms
30AI platforms discoverable
4SIEM connectors

// mcp proxy · inline governance

MCP Clients

11 enrolled

Agents point their MCP config at the Behavry proxy. Every tool call — identity, DLP, policy, audit — governed before execution. No agent code changes.

Claude Desktop
Streamable HTTP
Claude Code
Streamable HTTP
Cursor
Streamable HTTP
Windsurf
Streamable HTTP
Zed
Streamable HTTP
VS Code / Copilot
Streamable HTTP
JetBrains IDEs
Streamable HTTP
Warp Terminal
Streamable HTTP
Cline
Streamable HTTP
Continue
Streamable HTTP
Open Interpreter
stdio · critical risk tier

Plus fingerprints for Google Antigravity, OpenAI Codex CLI, and Amazon Kiro. Any MCP client supporting Streamable HTTP or stdio works — the proxy is protocol-agnostic.

// api proxy · model-level governance

AI API Proxies

6 models

Transparent reverse proxies for major AI model APIs. Identity, DLP, policy, and audit applied to every API call. Token extraction for cost attribution across all 6.

OpenAI
GPT-4o, o1, o3
Anthropic
Claude 4, Sonnet, Haiku
Google Gemini
Gemini 2.5
Ollama
Local models
NemoClaw
NVIDIA NIM
OpenShell
Open-source models

Cost attribution with 14 seeded model prices + tenant-configurable overrides. Aggregation API with CSV export.

// browser extension · manifest v3

Browser Extension

12 services

DLP scanning on browser-based AI interactions. 26 patterns in real time. Shadow AI detection for unenrolled services.

ChatGPT
Claude
Gemini
Perplexity
DeepSeek
Copilot
Poe
HuggingChat
You.com
Phind
Mistral Le Chat
GitHub Copilot Chat

// citizen coder governance

Vibe-Coding Platforms

7 platforms

DOM fingerprinting + platform API connectors discover and govern apps built by non-developers. 7-signal risk scoring. OPA policy enforcement. Full story →

Replit
DOM + GraphQL API
Lovable
DOM + deploy detection
Bolt
DOM + deploy detection
v0 / Vercel
DOM + REST API
Cursor
IDE domain matching
Windsurf
IDE domain matching
Copilot Workspace
IDE domain matching

// ai asset discovery · 30 platforms

AI Surface Discovery

30 platforms · 8 SaaS · 3 IdP

Four-state model: Licensed → Enabled → Active → Governed. Cross-references IdP apps, SaaS admin APIs, and browser fingerprints.

Identity Provider Connectors

Okta
Read-only app list
Azure AD / Entra ID
Read-only app list
Google Workspace
Read-only app list

SaaS Admin API Connectors

Microsoft 365
Copilot SKU + usage
GitHub
Copilot billing + seats
Slack
AI feature flags
Google Workspace
Gemini per-OU
Salesforce
Einstein enablement
Atlassian
AI feature status
ServiceNow
Now Assist
Zendesk
AI feature status

30 AI-capable SaaS platforms in the fingerprint DB. Browser extension adds 10 passive DOM fingerprint rules for admin page detection. Credentials encrypted via AES-256-GCM.

// siem · 4 native connectors

SIEM & Security Operations

4 connectors

Structured, identity-attributed audit events in your existing SIEM. Better data in the glass you already have.

Splunk
HEC (HTTP Event Collector)
Microsoft Sentinel
Data Collector API
Google Chronicle
Ingestion API
IBM QRadar
LEEF 2.0

Plus webhook delivery to Slack, PagerDuty, or any custom endpoint. Configurable severity filtering. Signed payloads with retry and dead-letter queue.

// data protection · 26 patterns · byok

Data Protection

26 DLP patterns · BYOK encryption

Four-stage pipeline: classification, redaction with pseudonymization, BYOK envelope encryption (AES-256-GCM + AWS KMS), and retention purge with decryption audit trail.

AWS Keys
GitHub Tokens
Private Keys
SSNs
Credit Cards
OAuth Tokens
API Keys
Email Addresses
Phone Numbers
IP Addresses

26 patterns total. Luhn validation, SSN structure checks, cross-session fragment reassembly detection. Critical-severity patterns auto-block before OPA evaluation. DB-managed with hot-reload — add custom patterns without restart.

// compliance

Frameworks

6 mapped

SOC 2

CC6.1 · CC6.7 · CC7.2 · CC7.3 · CC7.4

ISO 27001

A.12.4.1 · A.12.4.2 · A.9.4.1

EU AI Act

Art. 9 · Art. 13 · Art. 14

NIST AI RMF

GOVERN · MAP · MEASURE · MANAGE

GDPR

Art. 32 · Technical measures

HIPAA

§164.312 · Technical safeguards

OWASP ASI mapping + PDF export. Full framework-to-control mapping in dashboard.

// deployment

Models

4 deployment modes

Full SaaS

Behavry manages everything. Fastest start.

Hybrid

Control plane SaaS. Data plane in your VPC.

BYOC

Full stack in your cloud. Helm + Terraform.

Self-Hosted

Air-gapped. No external dependencies.

All models share a single data plane image. Identical governance capabilities regardless of deployment.

// works with everything you have

Zero agent code changes. Deploys in a day.

Agents point at the proxy. Policy enforced from day one. Your SIEM gets better data. Your compliance team gets an audit artifact.

Request Early Access