The Platform
Governance infrastructure for AI agents
Sielum gives you visibility into what agents do, control over what they are allowed to do, and the ability to intervene when behavior becomes risky, without blocking the teams building with AI.
Platform Capabilities
Everything you need to govern AI agents
See every AI agent on every machine
Sielum's lightweight endpoint agent scans running processes and config files to build a live inventory of all AI tools in your environment, without proxying traffic or touching file contents.
“From unknown shadow-AI to a live, auditable inventory”
Agent Inventory
Detects Claude Code, Cursor, Copilot, Codex, Amazon Q, ChatGPT Desktop, Gemini CLI, Windsurf, and OpenCode, automatically, across every enrolled endpoint.
MCP Server Inventory
Lists all configured MCP servers per endpoint: name, command, enabled/disabled state. Know exactly which extensions your agents have access to.
API Connection Tracking
Network-level monitoring of which external domains each agent contacts. No proxy, no MITM. Tracking happens at the OS network layer.
Define and enforce how agents operate
Set boundaries for which agents are allowed, which APIs they may contact, and which MCP servers are permitted, and enforce those boundaries at the network layer, not as suggestions.
“Policy-as-config, enforced, not just recommended”
Policy Engine
Four built-in policy types: unknown agent, unauthorized API domain, new MCP server, config violation. Alerts fire automatically when any policy is breached.
Managed policy enforcement
Enforce allowed tools, disable specific MCP servers, and lock settings fleet wide across your AI tools. No manual per machine work.
Network-Layer Blocking
Firewall rules (iptables / pf / WFP) block unauthorized API domains at the OS level. There is no proxy and no MITM. Blocking happens at the network layer.
Export audit evidence for every compliance framework
Sielum writes every policy event, enrollment, and config change to an immutable audit log. Export structured evidence for SOC 2, EU AI Act, and GDPR on demand, with no manual data assembly.
“Audit-ready without audit prep”
Immutable Audit Log
Every policy event, enrollment, and configuration change is written to an append-only log. Tamper-evident, exportable as JSON/CSV, queryable by time range or endpoint.
Compliance PDF Reports
Pre-built report templates for SOC 2 and EU AI Act, generated from live audit data, ready for auditor review without manual compilation.
GDPR Art. 17 Controls
Process data deletion requests from the dashboard. Full endpoint data purge on demand, covering agent events, config snapshots, and enrollment records.
Detect & Intervene
Catch unsafe AI usage before it becomes an incident
Visibility is the start. Sielum also detects when AI safety guardrails get switched off, and lets you require a human decision before risky agent actions run.
Detect when guardrails get switched off
A single flag disables every permission check in an AI coding tool. Sielum logs every attempt across your fleet, and remediates the dangerous ones automatically.
- High-severity alert with endpoint, process, PID, and the exact flag used
- Cursor configs auto-remediated to safe values, atomically, no manual fix
- Config Guard blocks bypass flags fleet-wide, even when passed on the CLI
- Live 24-hour unsafe-event counter on the AI Safety dashboard
Require sign-off before risky actions run
Route sensitive agent actions through a human. The agent pauses and waits for an admin to approve or reject, right from the dashboard, with a full audit trail.
Agent requests approval
MCP server access · production
Admin approves with a note
audit-logged decision
- Agent pauses on a policy match and waits for a human decision
- Approve or reject from the dashboard, optionally with a note
- Every decision is written to the immutable audit log
- Auto-rejects after a configurable timeout, no agents stuck waiting
Architecture
Secure by design
Your data stays in the EU. End-to-end encryption on every connection, mutual TLS for every agent. Security built in at every layer.
Lightweight endpoint agent
A small Go binary deployed per host. Monitors AI tool processes at the OS level, with no code changes required in agent applications. Direct process inspection, not a proxy.
Mutual TLS enrollment
Each agent authenticates via mTLS during enrollment. Device certificates are issued automatically, with no shared secrets and no manual key distribution. Revocation is immediate.
Encrypted event stream
Events flow over gRPC with end-to-end encryption. The server receives structured event data and applies policy evaluations in real time, in a sub-100ms round trip.
Central control plane
The Sielum server aggregates events, evaluates policies, and stores audit logs. Deployed on Hetzner Cloud DE by default, with data residency in the region you require.
Who Uses Sielum
Built for the teams responsible for AI
Enforce guardrails across every AI deployment
- Block agents from contacting unauthorized API domains at the network layer
- Alert on policy violations: unknown agents, new MCP servers, unauthorized APIs
- Maintain immutable audit trails for incident response
Operationalize AI agents at scale
- Enforce one policy across every AI tool fleet wide
- Monitor which agents and MCP servers are active across all machines
- Manage enrollment, certificates, and policy assignments centrally
Make AI decisions explainable and auditable
- Export structured audit logs for SOC 2 and EU AI Act reviews
- Prove API domain restrictions were enforced at the network layer
- Process GDPR Art. 17 deletion requests from the dashboard
Documentation
Technical Documentation
Full documentation is hosted in our Docusaurus portal: installation guides, API references, architecture diagrams, and operations runbooks.
Open Full DocumentationPowered by Docusaurus 3: full-text search, versioned docs, MDX support
Need implementation support?
Our team provides hands-on onboarding and PoC support.