Endpoint Guard
AI Border Gateway sees traffic routed through it. Endpoint Guard sees the rest: an employee using a desktop AI app, a browser-based assistant, or a local MCP tool that never touches a gateway. This is what "shadow AI" means in practice: real usage, with no visibility until now.
The problem it solves
Employees adopt AI tools faster than IT can approve or configure them. Some of that usage sends company data to a provider nobody vetted, and without a way to see it, there's no way to tell which.
How it works
Endpoint Guard installs a native agent on the device, macOS and Windows, running as a system service before login, with no per-user setup.
It intercepts only the domains it's told to watch, decrypts locally on the device, and sends the call to the same destination the user meant. It holds no provider API key. Cortega sees only what the device reports.
What's included
Local guardrails
A guardrail pack the device runs on its own, with no cloud call required. Pick an industry category (General, Healthcare, Finance, Government/classified) for a starter set of detectors, turn individual types on or off (SSNs, credit cards, phone numbers, addresses, medical and government identifiers, credentials, and more), and add custom patterns for org-specific terms. Each guardrail's action is observe (log only), mask, or reject, applied to the request, the response, or both. Configured independently of AI Border Gateway's own guardrails, and runs even when a device can't reach Cortega.
Budget checks
A device checks its team's remaining budget locally and allows or blocks a call before it's sent, using the same budget accounting AI Border Gateway uses.
Observability
Every observed request and response, in the same Observability view as AI Border Gateway's own traffic, filtered to the Endpoint Guard source.
Apps
Allow/deny rules for AI domains, applied to every device or overridden per domain. A domain not listed gets no interception and no guardrail.
Devices
Every enrolled device, by user, hostname, hardware serial, and how it proved its identity. Admins remove a device to free up its slot.
Enrollment options
An MDM rollout with per-device certificates for a fleet, a self-service rollout for admin-managed pilots, or a shared enrollment key for internal testing.
Fails open
If a device can't reach Cortega, AI traffic keeps working. A stricter, block-on-failure posture is available for customers who want it.
Install
The agent ships as a build artifact, .pkg for macOS and a .zip for
Windows, from your Cortega admin or release engineer. See
Install for the platform install paths that make Endpoint
Guard available to enroll devices against.