Find the AI your teams already use.

Upload network logs, sign-in grants, endpoint inventories, or code and config files, and within minutes see the unapproved AI tools across your organization, how exposed you are, and what to do next — mapped to the NIST AI Risk Management Framework.

LIVE GOVERNANCE PIPELINE4 systems in flight
  1. 01Upload
  2. 02Match
  3. 03Classify
  4. 04Score
  5. 05Map
  6. 06Report
Systems in flight
Upload — network, sign-in, endpoint or code exports

Three steps. About 15 minutes.

01

Create a free account

Sign up with your work email. No credit card, no sales call, no agent to install.

02

Upload your exports

Network logs, SSO app grants, browser/endpoint inventories, or code and config files for the secrets sweep. Scanning happens in your browser.

03

Get your Shadow AI report

See every AI tool in use, how often, by how many users, and an overall exposure score, then download the executive summary.

Works with the logs you already have.

  • Network: Cloudflare Gateway / DNS, Zscaler, Palo Alto, Cisco Umbrella, Fortinet, Windows DNS / Infoblox
  • Sign-ins: Google Workspace, Okta, Entra ID app-grant exports
  • Endpoint: browser-extension or installed-application inventories
  • Secrets & code: package.json, requirements.txt, .env, config files
  • Any CSV with a domain, URL, or application name column

A report you can take to leadership.

Every AI tool detected, grouped by category, across four discovery vectors
Request volume and distinct users or IPs per tool
Department hotspots and review flags for vendors with risky data terms
Exposure level for each tool and an overall score
NIST AI RMF next steps: Govern, Map, Measure, Manage
Executive summary PDF for your CEO or board
One-click add to your AI inventory

Raw file contents are processed in your browser and never stored.

Common questions.

Does my file get uploaded to your servers?

No. Exports are read in your browser. Only the summary (which AI tools, request counts and number of distinct users or IPs) is saved to your workspace so you can revisit it.

What can I scan?

Four discovery vectors: network/gateway logs, sign-in app grants, browser-extension or endpoint application inventories, and a secrets & code sweep that finds hardcoded AI keys, AI SDK dependencies, and MCP servers. Secret values never leave your browser.

What does the scan detect?

Commercial AI services and AI-capable tools: chat assistants, coding tools, meeting note-takers, image and video generators, writing tools, model APIs, AI agents, local runtimes, and browser extensions. It shows use, not the content that was sent.

Can it tell me if sensitive data was shared?

Not directly. It flags tools whose terms and use patterns make data exposure more likely, so you know where to look first. Confirming exposure needs a risk assessment.

What does it cost?

The audit is free. Platform plans add continuous AI usage monitoring, risk assessments, impact assessments, controls, evidence, vendor reviews and reporting.

Know where AI is. Find where it can go.

Start with an AI Governance & Opportunity Assessment.

Get your assessment