Cortex
SecurityProtect

See AI use.
Prove what happened.

Discover. Control. Investigate.

ObservedPolicyAction

Where the sensor looks

AI is in the tools people already use.

Cortex finds sanctioned and shadow AI on supported capture paths: device, browser, IDE, SaaS, and MCP. Coverage is named, not assumed.

Endpoint

Chat, coding agents, local tools

  • Claude
  • Cursor
  • ChatGPT
  • Grok

SaaS

Support, knowledge, and ops work

  • Slack
  • Notion
  • Linear
  • Teams

Code

PRs, agents, and review loops

  • GitHub
  • Cursor
  • Linear
  • Claude

Cloud

Hosted models and MCP

  • OpenAI
  • Gemini
  • Claude
  • Grok

One event

One incident through Discover, Control, Investigate.

A sanctioned MCP read is denied on a Cortex-controlled path. The same payload is pasted into an unsanctioned ChatGPT tab and is observed only.

Discover · INC-SYNTH-01

Inventory and exposure

Requester
ACME-SUPPORT-01
Surface
Chrome · unsanctioned tab
Model
ChatGPT
Data class
pii.ssn

Control · INC-SYNTH-01

Decision on a managed hop

Requester
ACME-SUPPORT-01
Surface
Cursor MCP · approved client book
Data class
pii.ssn
Destination
MCP client-book read

Investigate · INC-SYNTH-01

Record the officer can defend

Incident
INC-SYNTH-01
Requester
ACME-SUPPORT-01 · Support · triage-helper
Surface
Chrome · unsanctioned tab
Data class
pii.ssn · SSN •••-••-0000
Deployment, lineage & assurance

One security program. Every session accounted for.

Run one evidence program across endpoints, cloud workloads, and self-hosted environments, with the deployment record and assurance posture in the same view.

  • Which person or agent initiated the session
  • Which surface, destination, and data class were involved
  • Whether Cortex discovered, controlled, or investigated the event
Deploy where the session runs
  • Human-operated AI

    Browser and desktop tools people already use. ChatGPT, Claude, Grok, Cursor, and the rest of the consumer surface.

    ChatGPTClaudeGrokCursor

    On-device sensor

  • Cloud workloads

    Hosted agents, provider APIs, and MCP paths: Slack agents, OpenAI, Gemini, GitHub.

    OpenAIGeminiSlackGitHub

    Your cloud

  • Self-hosted

    Run capture in your VPC or on-prem. Same inventory, same data classes, inside your boundary.

    CloudData planeHosted

    Your VPC or on-prem

Assurance carried with the evidence

Review your AI exposure.

Discover. Control. Investigate.