SENTILAI

Your developers
already adopted AI.
Now adopt control.

Sentilai is the AI control plane for software teams — not enterprises. Every AI coding tool your developers run — Claude Code, Cursor, GitHub Copilot, Gemini CLI and Codex CLI — on every machine they run it on, routed through one gateway that audits every action and blocks the dangerous ones in real time. Developers change nothing, and keep their own subscriptions. You get visibility, policy, and proof.

Start free

5 users, 30 days · no card, no sales call · EU-hosted

Watch 13 real catches in 3½ minutes ↗ · recorded live, not mockups

Already have an account? Sign in

The Sentilai Activity view: every AI request from a developer team, with two blocked rows — an AWS access key caught in a prompt, and a call to a blocked MCP server.

Every AI request your developers make — with the policy decision attached. Blocked rows are blocked before the request leaves the machine.

Keep the subscription

Governance without the 10× invoice

Gateways that issue managed API keys quietly convert a developer's flat Claude Pro or Max subscription into pay-per-token API billing. Sentilai forwards the developer's own credential through the governed path instead — same subscription, same speed, full audit.

$20–200 /developer/mo

A Claude Pro or Max subscription: flat, budgetable — and untouched by Sentilai's governed path.

$150–250 /developer/mo

The same work billed at API list rates, on Anthropic's published averages — and heavy agentic use runs to multiples of that.

€149 /team/mo

Where Sentilai starts: flat seat bands, no per-request meter, no token resale. Your provider bill stays exactly yours. See pricing.

Claude Code routes with the developer's own Pro or Max credential. Tools that only route with organisation keys — Cursor, GitHub Copilot, Gemini CLI, Codex CLI — are governed with your own provider keys. And where a cheaper model is good enough, route that tool to it — per tool, to Anthropic, OpenAI, Azure, Gemini or any OpenAI-compatible endpoint, governed identically. Either way, we never resell tokens. The full mechanism and the per-tool truth table →

One platform

Governance that actually stops things

Not another dashboard that tells you about yesterday. Sentilai sits in the request path, so policy is enforced while the request is still in flight.

mcp_policy

Real-time MCP policy

Allow, warn, report or block — per MCP server and per tool, enforced in the request path. The inventory fills itself from what your developers actually run, new installs can require admin approval before first use — and a tool whose description quietly changes after approval gets flagged. That's the MCP rug-pull, caught.

MCP Inventory listing discovered servers with per-server Allow, Warn and Block policies.
secrets · pii · trifecta

Secrets blocked mid-flight

An AWS key pasted into a prompt never reaches the model. Detectors for secrets, personal data, prompt injection and lethal-trifecta exfiltration paths run inline, not in a nightly report.

Activity rows showing a blocked request flagged aws_access_key_id and a PII warning.
ungoverned_agents

Shadow agents, surfaced

OpenClaw and agents like it are detected on every governed device and logged as a durable episode history. Set your policy to warn and the device shows non-compliant; set it to block and the device's governed AI access stops until the agent is gone.

autonomy_posture

Auto-approve, governed

Most agent incidents start with a setting: auto-approve, sandbox off, "act without asking". Sentilai reads the AI-tool configuration on every device, shows who runs which posture, rewrites it to the one you chose — and re-governs it when it drifts back.

device_identity

Device-bound identity

Every machine gets a hardware-backed key in the OS keychain. Access is per person and per device — and dies the moment either is revoked.

offboarding

One-click AI offboarding

When someone leaves, their devices, tokens and passkeys go with them — in one action, with a receipt. Classic checklists never reach AI tooling.

provider_routing

Your models, your choice

Route each tool to the provider you pick — Anthropic, OpenAI, Azure, Gemini, or any OpenAI-compatible endpoint, your own self-hosted vLLM included. Per tool, with identical governance on every path.

evidence

Audit trail and evidence pack

Every request, decision and policy change: real-time alerts to Slack or Teams, SIEM export, and an evidence pack for the day a customer, an auditor or a regulator asks what your developers' AI tools actually did. From August 2026 the EU AI Act's enforcement machinery can ask exactly that — the wrong answer is having no record.

The Compliance evidence view, showing inventory, policy and traffic evidence ready to export.
supply_chain

Hallucinated packages, caught

AI invents package names; attackers register them and wait. Every AI-suggested dependency is checked against the real npm and PyPI registries first — and a confirmed fake is quarantined for every tenant at once.

How it works

Three moving parts. Developers touch none of them.

No proxy to configure, no VPN, no new workflow. Install once and the tools your team already uses keep working — governed.

1

Endpoint Suite

A small signed app for macOS and Windows points the installed AI tools — Claude Code, Cursor, Copilot, Gemini CLI, Codex CLI — at Sentilai in one click, and gives the device its own identity.

2

Gateway

Every request passes through, carrying that device identity. Policy is evaluated in flight: allowed, warned, or blocked before it reaches the model or the MCP server.

3

Console

You see what happened, set the policy, and export the evidence. Your developers never see a console at all — which is exactly why they keep using it.

Built to be trusted

The boring parts, done properly

CSA STAR Level One: Self-Assessment badge CSA STAR Level 1 Published self-assessment (CAIQ v4) in the Cloud Security Alliance's STAR Registry — all 197 control answers, public, since August 2026.
EU company, EU infrastructure Built and hosted in the EU, GDPR by construction — not a US platform with an EU region bolted on.
Passkey-only sign-in Phishing-resistant authentication everywhere, for your admins and ours. No shared passwords to leak.
Your prompts aren't training data We never train on your traffic and never sell it. Capture is opt-in, and retention is yours to set.
Binaries your OS can vouch for The Endpoint Suite is Developer ID-signed and Apple-notarized on macOS, code-signed on Windows. Who published it is attested by your OS — not by a badge we printed.

We publish what we've actually built, and name roadmap items as roadmap. The STAR listing above is a self-assessment and labelled as one; we'll list independently assessed certifications when they're earned, not before.

See it on your own traffic

Install on one machine, route one tool through it, and look at what comes back. Nothing to uninstall if it isn't for you.

Start free

5 users free for 30 days · no card, no sales call

Want to read first? The documentation is public — every screen and setting, already written.