Skip to content
MoorAI
// product

MoorAI for Endpoints

Keep secrets and personal data out of AI tools, catch risky agent actions before they run, and see every AI tool on the fleet. The check runs on the device, so prompts, code and files stay there.

Building an AI app, agent or API? MoorAI for Runtime → · Running AI agents on case data? AI in digital forensics →

// ai coding agents

A check inside every coding agent

Claude Code, Codex, Copilot CLI, Gemini CLI and Cursor each get MoorAI in their own pre-tool hook, so every shell command, file read and MCP tool call passes the check before it runs. Enforcement is validated end to end on Claude Code.

For developers using AI coding agents →

// employee ai use

The AI everyone else uses

// desktop app

A guarded home for agent CLIs

The macOS and Windows app runs Claude Code, Codex or Copilot CLI in its own terminal. It reviews each prompt before it reaches the agent, with Send redacted or Send anyway, and scans files you drop, paste or pick, reading images with on-device OCR.

// browser extension

AI on the web

MoorAI Browser Guard, for Chrome and Edge, checks what you type into ChatGPT, Claude, Microsoft Copilot, Gemini, Perplexity, Le Chat, DeepSeek and Grok before it is sent. Coach warns and lets you proceed; Block stops a high-severity send.

// on-device dlp

Secrets and PII stay off the model

Secrets, keys and personal data are caught before they reach a model: in prompts, in files an agent reads into its context or writes, in MCP tool calls and in pasted images. On-device AI DLP

// shadow ai

AI tools nobody approved

AI desktop apps and AI browser and editor extensions found on the device, matched against a catalogue, and moorai-shadow compares what it finds with your allow-list. Shadow-AI detection

// local ai inventory

Models running on the machine

Which local model servers are running (Ollama, LM Studio, llama.cpp llama-server, vLLM) and whether they listen beyond loopback, plus a count of local models whose name says their safety training was removed.

// keys at rest

AI provider keys on disk

Anthropic, OpenAI, Hugging Face, Perplexity and Google keys in shell startup files, AI CLI config folders and project .env files. Each is reported as a provider, a location class and a keyed hash; the key never leaves the device.

// policy, enrollment and fleet view

Coach first, enforce when enrolled

StateWhat MoorAI does
Not enrolledCoaches: the same detection and built-in defaults, showing what it caught and the safer way. It never blocks, never asks for sign-off, never ends a session and posts nothing anywhere.
Enrolled in a consoleEnforces per policy: block, a signed justification, or ending the agent session. The console is free for up to 200 users.
Managed rolloutJamf Pro (macOS) and Microsoft Intune (Windows) packages in the repository write the device config and register the hooks.

The console shows the fleet: every agent, MCP server, model and device, built from content-free signals (a category, a risk level and a keyed one-way hash). The console →

// platform support

What runs where, and what is tested

PlatformWhat shipsTested
macOS (Apple silicon)Desktop app (DMG or Homebrew cask) and the agent hooksThe DMG is signed and notarized in CI.
Windows (x64)Desktop app installer from GitHub Releases and the agent hooksCI runs the hook, gateway and egress suites on Windows. No live PowerShell run yet, and the Intune install script has not run on a live device.
LinuxThe agent hooks, installed from the command line; no desktop app is publishedCI runs the agent’s test gates on Linux. On-device OCR is a second-class tier there.
Coding agentsClaude Code; Codex CLI, Copilot CLI, Gemini CLI and CursorClaude Code is validated end to end. The other four are tested against each vendor’s documented hook payloads, not yet against the live agents.
// every boundary, on the device

Prompts, files and retrieved input coming in; tool calls and skills both ways; AI output going out — each control mapped to its MITRE ATLAS technique.

Promptsin
Files / contextin
Input · retrievedin
The device · content stays here
MoorAIOn-device
MoorAI hookevery crossing, on the devicecontent stays on the machine
AI coding agentClaude CodeCursor · Copilotruns inside MoorAI
Runs locally · no cloud
  • PreToolUse hook in the agent
  • MCP stdio gateway / proxy
  • Companion browser extension
  • Local-model escalation (Ollama)
79-threat matrix
Tools / actionsboth ways
AI output protectionout
Skillsboth ways
MITRE ATLAS

The open knowledge base of real-world adversarial tactics and techniques used against AI systems — ATT&CK, for AI. Each control above links to the ATLAS technique it counters.

Inspected on the device — only category · risk · a keyed one-way hash (plus the login and hostname, which the console pseudonymises on arrival) ever leaves it.

Read the full mapping →

// limits

What it doesn’t do

  • Governance, not a sandbox. MoorAI runs as the same user as the agent and fails open if its hook crashes or times out.
  • It sees only where it is installed. Native AI desktop apps with no integration, phones, other devices and machines without MoorAI are outside its view, so the console shows the risk of the devices that run it, not of the whole organization.
  • The browser extension is narrow. It checks typed prompts, not uploads, with regex rules; it fails open when a site changes its markup; and it is loaded unpacked in Chrome or Edge, with no store listing.
  • Shadow-AI discovery is presence, not activity. An installed extension may be disabled, and installed-app discovery finds nothing on Linux.
  • Safety-removed models are flagged by name only. A renamed model is not caught, and a name proves nothing about a backdoor.

Guard the AI people use,
on their own machines.

Free and open source (MIT). It coaches with no account; enrolled, it enforces.