Discover the shadow AI on every employee's laptop.
Employees are wiring AI into Gmail, GitHub and your databases — with live credentials and no oversight. Connor maps every connection and skill across your team. Read-only, no secrets collected.
AI didn't ask for permission.
Credentials on every laptop
Every MCP connector holds live API keys and OAuth tokens. One leaked config is full access.
An invisible blast radius
Nothing tells you which AI tools can reach your data, your code, your finances.
It starts with your power users
Your highest-access engineers and admins connect the most — so exposure runs deepest exactly where access is greatest.
From invite to full inventory in under an hour.
Send it to your team
Sync your directory, or push it fleet-wide through Jamf, Kandji or Intune.
It scans locally, read-only
Inventories MCP connections and skills across Claude, Cursor and VS Code. Secrets flagged, never read.
See everything in one dashboard
Every connection mapped to every person — and where the risk concentrates.
Built to be trusted on day one.
The question isn't what it finds — it's what it takes. The answer: names, never values.
Secrets never leave the laptop
We read names only. Keys and tokens are marked present — never read or sent.
Read-only. No file contents
Known config locations only. No documents, history or keystrokes.
Transparent to employees
Each person sees what's collected before anything leaves their machine.
You control distribution
A self-serve link, or an IT-managed MDM push. Your call.
On the roadmap: code-signed & notarized installers, SOC 2, self-hosted ingestion.
Visibility in an afternoon, not a quarter.
- No agents, no committee — sync your directory and you're scanning.
- Find the credentials you didn't know were exposed.
- Map AI to data — know which systems each tool can reach.
- Turn discovery into control. Govern AI access from the same platform, when you're ready.
Discovery your CASB and MDM can't do.
Purpose-built for AI
MCP and skills are a new layer your CASB and MDM don't understand.
Discover to enable, not just block
Other tools discover shadow AI to shut it down. Connor turns the best of what it finds into governed capabilities your whole team can run.
No secrets, ever
Inventory without exfiltration — safe to run on every laptop.
Questions security teams ask.
MCP is how AI assistants connect to your apps and data — a connector that wires a model into Gmail, GitHub, a database, an internal tool. A skill is a packaged capability an employee adds to their assistant. Both are installed per-person, on the laptop, with no central record.
No. We read the names of tools and connections only. Keys, tokens and passwords are detected and marked “present” — their values are never read, never transmitted, never stored.
A one-click link they run themselves, or your MDM (Jamf, Kandji, Intune) pushes the scanner silently fleet-wide. Either way there's nothing for them to configure.
Claude Code, Claude Desktop, Cursor and the VS Code family, on macOS — with more clients and platforms coming.
The first scan of your organization is free.
We store inventory metadata only — the names of connections and skills mapped to people. You can delete it any time.
See the shadow AI on your team's laptops.
One scan. Every AI connection and skill, mapped to every person — without collecting a single secret.