Make AI-agent activity provable — not merely visible.

See supported Codex, Claude Code, and Cursor signals, which links are causal or correlated, and where evidence is missing — with local-first, signed evidence and no secret values.

Local-first evidence for supported AI-agent sessions and actions — causal, inferred, or missing, never blurred.

Local-first. No secret values. Causal, inferred, or missing — never blurred.

BeProof · Workstation Audit

BeProof Overview showing readiness, risks, agents detected, and evidence collected
Agents detected5
Access references227
Open findings3

Example audit snapshot · macOS (first endpoint wedge)

The buyer question

Did this agent session invoke kubectl against production using a privileged context — and can you prove it?

Finding an installed agent is only the first step. BeProof preserves the strongest supported links, labels inference and ambiguity, and creates a coverage gap wherever the chain cannot be established.

Inspect the Action Chain
  1. 01
    Agent sessionSource-dependent

    Supported local history can identify sessions and automation events.

  2. 02
    Process / toolSampling

    Explicit-scan process ancestry for supported CLI tools; not continuous coverage.

  3. 03
    Credential contextPartial

    Metadata references can be discovered, but per-action lineage is not universal.

  4. 04
    DestinationPartial

    Repository, project or configured endpoint context where the source exposes it.

  5. 05
    OutcomeExternal source

    Allow, deny or remediation is shown only when the enforcing product reports it.

Current boundary: direct CLI process evidence is explicit-scan sampling on macOS. The continuous observer remains gated, so BeProof does not claim automatic or historical process coverage.

Product proof

From workstation signals to audit-ready evidence.

BeProof turns endpoint-level AI signals into structured evidence your team can review, approve, export, and verify.

Action Chain is captured from the live macOS product using local Codex automation history evidence. It does not represent continuous process observation; synthetic external-control data remains labelled separately in the sample incident bundle below.

Action ChainInspect real Codex automation events, causal links, confidence, separated evidence states, and an explicit enforcement coverage gap.
OverviewSee readiness, active risks, detected agents, collected evidence, and open reviews.
Review QueueTurn unknown agents, MCP servers, credential references, and gaps into auditable decisions.
Access and UsageCorrelate what is configured, what is granted, and what activity can be verified.
Admin ConsoleGive security teams a fleet posture view without sending raw endpoint evidence upstream.

Endpoint controls can block. Identity controls can restrict. Admin APIs show their own slice.BeProof preserves independent, verifiable evidence across those gaps.

Independent assurance

Security controls act. BeProof preserves the proof.

No single endpoint, identity, or agent platform sees the whole chain. BeProof reconciles the evidence available from those sources, leaves unsupported inputs visible, and never presents a risk finding as proof that an action was blocked.

Available / partial

Agent and runtime sources

Local collectors and provider APIs contribute declared configuration, access references, usage signals, timestamps, and source health.

Planned adapters

Identity and security controls

Endpoint, identity, and vendor-native controls remain responsible for allow, warn, deny, and remediation decisions.

Available / expanding

BeProof evidence assurance

BeProof preserves source attribution, confidence, coverage gaps, review decisions, and independently verifiable evidence exports.

Current macOS pilot

What BeProof can prove today.

Start with concrete evidence available in the current pilot. Every source-dependent, sampling-only, or unsupported link keeps its boundary instead of being presented as a stronger claim.

Verified today

Agent and configuration evidence

Discover supported Codex, Claude Code, Cursor, and MCP configuration surfaces on macOS with source and collection metadata.

Source-dependent

Session activity

Preserve history-backed sessions where supported sources expose them. Cursor activity remains explicitly correlation-backed.

Sampling-only

Process and direct CLI activity

Classify supported CLI activity during an explicit scan window without claiming continuous or historical process observation.

Cryptographically verifiable

Signed evidence exports

Export a redacted evidence package whose payload, manifest, and Ed25519 signature can be verified offline.

Windows endpoint attribution and production external-control adapters are roadmap scope, not capabilities included in the current macOS pilot.

Pilot deliverables

Sample evidence pack

A pilot should end with evidence your security and compliance teams can actually use.

What you can prove

BeProof turns scattered AI-agent signals into evidence your team can review, explain, export, and verify.

Discovered AI agents and assistants

Which agents, assistants, automations, and MCP servers were found on employee workstations.

Access paths and credential references

Which grants, credential references, connected systems, and permission paths need review.

Observed usage signals

Which usage events, run histories, or activity signals were available for verification.

Coverage gaps

Which sources were missing, unavailable, partial, stale, or consent-gated.

Review decisions and exceptions

Which findings were approved, rejected, assigned for remediation, or accepted as risk.

Exportable evidence

Which evidence package can be shared with security, compliance, or audit reviewers.

What you receive after a 30-day pilot

AI-agent inventoryA list of discovered agents, assistants, automations, MCP servers, and relevant workstation surfaces.
Access review summaryCredential references, grants, connected systems, and access paths requiring review.
Findings reviewPolicy findings grouped by severity, status, source, and owner.
Coverage gap registerMissing, unavailable, stale, partial, or consent-gated evidence sources.
Exception logApproved exceptions, accepted risks, remediation decisions, and review history.
Signed evidence exportA reviewable package with metadata, findings, coverage status, and verification manifest.

Two demos, two explicit trust levels

Inspect the deeper multi-source causal fixture, then run offline verification on a separately signed, redacted demo bundle. Both use synthetic example data — never live customer telemetry.

Bundle summary

Action events
3
Policy decisions
1
Enforcement events
1
Evidence links
7
Coverage gaps
2

Evidence chain

  • CausalClaude session → MCP tool callShared session invocation metadata
  • CausalMCP action → external deny decisionPolicy decision: deny
  • CausalDeny decision → blocked outcomeenforcedBy: external-control:example-gateway
  • MissingAction → credential lineageCoverageGap: credential_lineage

Offline verification demo

Algorithm
ed25519-v1
Contract
v0.2.7
beproof verify-incident-bundle --artifact ./incident-evidence-bundle-signed-demo.json --public-key ./beproof-demo-signing-key.json

The signed demo returns status: verified and detects payload, manifest, or signature tampering. It uses a public deterministic demo key, so it proves integrity mechanics — not customer or device identity.

Trust boundary: the multi-source causal fixture demonstrates attribution structure and intentionally keeps placeholder signature values. The signed demo is cryptographically valid but synthetic and signed by a documented demo key. A real customer bundle must be produced by beproof export-incident-bundleand verified against that endpoint's trusted public key.

Evidence model

One evidence model for every AI surface.

BeProof does not silently pass incomplete audits. It separates presence, access, observed activity, and missing evidence into a workflow security teams can review.

  1. DeclaredWhat exists or is configured.AI assistant, MCP config, local automation
  2. GrantedWhat access or permissions exist.Credential reference, OAuth grant, SaaS scope
  3. ObservedWhat activity signals can be verified.Usage event, run history, stale workflow
  4. CoverageGapWhat cannot be proven yet.Missing connector, unavailable source, consent needed
FindingReview / ExceptionExternal evidence (planned)Signed Export

Missing evidence does not become a clean report. BeProof separates verified facts from correlations, review decisions, planned external-control outcomes, and coverage gaps.

The gap

AI agents are moving faster than security can audit them.

AI agents have moved from chat to action. Employees now connect AI tools to files, browsers, SaaS apps, local workflows, credentials, APIs, and automation systems. But most security stacks still track users, devices, SaaS seats, and network events — not which AI agents exist, what they can access, what was used, and where evidence is missing.

AI moved from chat to action

Agents no longer just answer questions. They summarize work data, operate across apps, trigger workflows, and connect to internal systems.

Access paths are scattered

Credentials, OAuth grants, MCP servers, browser sessions, SaaS permissions, files, APIs, and local automations create access paths that are hard to review together.

Evidence is incomplete

Admin consoles show seats and settings. They rarely prove what exists locally, what was granted, what was used, or where the audit cannot make a clean claim.

Use cases

Built for security, compliance, IT, and risk teams.

BeProof gives security, compliance, IT, and risk teams a shared evidence layer instead of fragmented screenshots, policy attestations, and incomplete SaaS admin exports.

Independent evidence assurance

Reconcile available endpoint and provider evidence without treating any single source as complete truth or claiming unconnected identity and security controls are covered.

Access review

Review credential references, cloud grants, connected systems, and permission paths.

Audit evidence export

Produce reviewable evidence packages for security reviews, SOC 2 readiness, ISO readiness, and internal audits.

Deployment

Start local. Scale across your fleet.

BeProof is designed for security-led rollout on employee workstations — from a focused pilot group to MDM-managed fleet deployment, with provider-neutral evidence adapters added only when their source and privacy boundaries are verified.

First endpoint wedge: macOS evidence for local AI agents, MCP servers, credential references, and automation workflows — not the product boundary.

Workstation endpoint scans

BeProof collects local AI-agent surfaces, MCP configs, credential references, and usage evidence on employee endpoints. macOS is the first verified collection surface.

Control products remain in control

EDR, DLP, identity, and vendor-native products remain responsible for enforcement. BeProof records their outcomes only when attributable source evidence is available.

Metadata-only upstream

Shared reports and fleet summaries include findings, review status, and coverage gaps — not raw secrets from endpoints.

MDM and admin review

Deploy focused pilots through existing device management, then review fleet posture and verification metadata without pulling full endpoint dumps into the cloud.

Compliance evidence

Close the AI-agent evidence gap in SOC 2 and ISO readiness.

When auditors or internal reviewers ask how your company governs AI-agent usage, BeProof gives your team a repeatable evidence package: inventory, access review, findings, exceptions, coverage gaps, and signed exports.

AI agent inventoryAccess and credential reference reviewCoverage gaps and exceptionsSigned / tamper-evident exports

BeProof complements SOC 2, ISO 27001, and internal security programs. It does not replace GRC, IAM, EDR, DLP, MDM, or SaaS administration.

Designed for sensitive environments

Security proof without raw secrets.

  • Local-first processing
  • Credential metadata, not secret values
  • No raw secrets in reports
  • Consent-gated sensitive sources
  • Coverage gaps instead of false passes
  • Signed / tamper-evident exports
Raw local evidence stays on the endpoint by default. Shared reports include metadata, findings, review decisions, coverage gaps, and verification manifests.
FAQ

Common buyer questions

Who is BeProof for?

Security, compliance, IT, and risk teams at companies where employees use AI agents, assistants, MCP servers, and automations across workstations, SaaS tools, and local workflows — especially when audit evidence is fragmented across SaaS admin, policy attestations, and endpoint blind spots.

How is BeProof deployed?

Start with a 30-day pilot on a focused endpoint group (macOS available today). Install the BeProof app on workstations or roll out via MDM for managed fleets. The admin console supports fleet enrollment, review workflows, and signed summary ingest.

Does BeProof replace GRC, EDR, or SaaS admin?

No. BeProof complements SOC 2, ISO 27001, and internal security programs. It adds AI-agent-specific evidence across the gaps that GRC, IAM, EDR, DLP, MDM, and SaaS administration do not fully cover.

Does BeProof block AI-agent actions?

No. BeProof is an independent evidence and assurance layer, not an endpoint enforcement product. As external-control adapters become available, their allow, warning, denial, or remediation results will be preserved with source attribution. A finding alone is never presented as proof that an action was blocked.

What data leaves the endpoint?

By default, sensitive collection stays local. Shared exports and fleet summaries use metadata, findings, review decisions, coverage gaps, and verification manifests — not raw secret values.

What does the 30-day pilot include?

Workstation scanning, AI-agent inventory review, access path review, findings triage, coverage gap reporting, exception workflow, and a signed evidence export your security and compliance teams can review.

30-day pilot

Start with an AI Agent Evidence Assurance Pilot.

Scan a focused workstation group, review AI-agent presence and access paths, identify coverage gaps, and export an evidence pack for security and compliance review.

At the end of the pilot, your team receives an AI-agent inventory, access review summary, findings review, source-attributed coverage gap register, exception log, and independently verifiable evidence package.

  1. Week 1

    Scan a small group of managed workstations

  2. Week 2

    Review agents, automations, access paths, and coverage gaps

  3. Week 3

    Map findings to internal security controls

  4. Week 4

    Export an evidence pack for security and compliance review