The platform
One inventory, kept current
The system of record for endpoint-resident Shadow AI: a data-local inventory and change history for AI apps, agents, models, IDE tools, MCP servers, browser extensions, SDKs, and provider-key presence across the fleet.
- Scan →
- Inventory →
- Snapshots →
- Changes
Each snapshot starts with bounded local discovery. KeepRails normalizes identities before it compares state, so every change points back to what the collector actually observed.
What the loop produces
One fleet inventory, with history
Every snapshot feeds the same normalized inventory, change history, and status board.
Scan
Scan
Read local identity evidence for endpoint-resident AI without uploading configuration content.
Agent Health Check (CLI)
Endpoint AI Inventory
Inventory
Inventory
Normalize what was observed, where it came from, and what the collector did not scan.
Nothing in this stage ships yet. It is described here because the loop needs it, not because you can buy it today.
Snapshots
Snapshots
Store comparable fleet snapshots with ownership and declared scan boundaries.
Changes
Changes
Surface added, removed, changed and running-state events; export evidence views when needed.
Nothing in this stage ships yet. It is described here because the loop needs it, not because you can buy it today.
Not yet shipped
What is still ahead
Named here, and nowhere else on the site. These pages exist and can be read, but they are kept out of the navigation until the capability is real.
Claude Code Plugin
GRC integrations
Observed Use vs Installed
Team Dashboard
Team Baseline
The loop starts on one machine
keeprails scan