Svalin - AI Governance Platform Logo
SVALIN AI Governance Platform
Svalin · Observability for AI coding agents

Engineers keep their speed.
Security keeps the receipts.

Svalin deploys through your MDM and silently maps every AI coding agent, every MCP server, and every session across the fleet. Security gets a live registry, a spawn gate on MCP traffic, and a real-time dashboard — without a single engineering impact.

Svalin conversation detail — governed Claude Code session with duration, token counts, model usage, environment snapshot, active MCP servers, policy version and a chronological timeline of sessions, LLM calls and tool invocations
Telemetry foundations for
SOC 2 ISO 27001 EU AI Act GDPR DORA
7 AI agent types detected
16 MCP servers mapped
85 governed sessions this month

Every agent your engineers run.
Detected. Versioned. Governed.

Svalin auto-detects every AI coding agent installed across the fleet — without engineers registering anything. See which clients are governed, which aren't, and every version currently in the wild.

CLIENTVERSIONS IN THE WILDDEVICES
Claude Codeclaude-cli
(v2.1.119, v2.1.139, v2.1.140, v2.1.185, v2.1.187, v2.1.193)
6
Claude Desktopclaude-desktop
(v1.12603.1, v1.14271.0, v1.15962.0)
5
Gemini CLIgemini-cli
(v0.46.0)
5
Codex CLIcodexNOT GOVERNED
2
GitHub CopilotcopilotNOT GOVERNED
2
JetBrains JuniejunieNOT GOVERNED
2
OpenCodeopencode
(v1.14.48, v1.17.10)
2

Every MCP server, mapped automatically.
With versions, per device.

Svalin keeps a live registry of every MCP server configured across the fleet — remote endpoints and stdio processes — with the versions running on each device. No engineer registers anything.

SERVERNAMES USEDVERSIONSDEVICES
REMOTE
http://localhost:7777/svalin/svalin-observe/mcp
svalin-observe
6
STDIO
code-intelligence
code-intelligence
2
REMOTE
https://mcp.context7.com/mcp
context7
1
STDIO
@modelcontextprotocol/server-filesystem
obsidian
(v2026.1.14)
1

Every MCP server across the fleet · sample shown above

The security picture. At a glance.

Active agent clients, MCP coverage, session volumes, governance gaps — one screen. Security concerns surface as incidents, not as noise in a log file.

Caller agents across the fleet
8 device-tool pairings active in window.
Claude Code 4
Claude Desktop 3
Gemini CLI 1
7
AI coding agent types detected across the fleet
16
MCP servers mapped — remote and stdio
3
ungoverned agent types flagged for review

Built around one idea: observe without getting in the way.

01

Engineers don't change a thing.

Deployed through your MDM in the same wave as any other endpoint. The agent watches Cursor, Claude Code, Gemini CLI and the MCP servers they connect to — invisibly, on the device. No proxy, no new IDE settings, no tickets in the engineering backlog.

02

One registry, every surface.

Governed devices, supported AI coding agents, connected MCP servers — all in one place. The CISO surface answers "who is using what, where" without an email thread.

03

Incidents, not log floods.

Secrets, credentials, PII and policy violations surface as incidents — triaged, owned, resolved. Everything else stays in the timeline where it belongs.

04

Compliance, as a side effect.

A signed, append-only audit trail of every call by every AI agent on every device. SOC 2, ISO 27001 and EU AI Act evidence falls out of the system you were going to deploy anyway.

You have an AI policy. You don't have proof anyone follows it.

Every InfoSec lead we talk to has the same answer: "we have a document registry." A Notion page, a Confluence space, a PDF that lists the AI coding tools they sanction and how they should be used. None of them can tell you, today, which engineer is actually running which agent against which MCP server.

The gap between the document and reality is where audit findings come from. It is also where credential leaks and unsanctioned MCP servers slip in.

Svalin closes the gap. The platform tells you which AI coding agents are in use across the fleet, which MCP servers they are connected to, and whether each device matches the policy you wrote — without asking engineers to log a thing.

Two surfaces. One source of truth.

A · Local agent

Lives on the device, deployed by your MDM in the same wave as any other endpoint tool. Watches every AI coding session in the background — and applies policy locally, with no network round-trip.

MDM deployment (Jamf, Kandji, Intune)
Local policy engine — zero decision latency
Captures tool calls, file access, MCP traffic
PII and credential detection on-device

B · Governance platform

The CISO and CTO surface. Registry of every governed device, every supported AI coding agent, every connected MCP server. Central policy management and the full audit trail in one place.

Device, agent and MCP server registry
Central policy management, pushed to every agent
Incident queue and audit log exploration
SOC 2 / ISO 27001 / AI Act evidence export

See what AI coding agents accessed yesterday.
Without asking a single engineer.

Book a demo