Skip to main content

Endpoint Guard

Install Sign Up

AI Border Gateway sees traffic routed through it. Endpoint Guard sees the rest: an employee using a desktop AI app, a browser-based assistant, or a local MCP tool that never touches a gateway. This is what "shadow AI" means in practice: real usage, with no visibility until now.

The problem it solves

Employees adopt AI tools faster than IT can approve or configure them. Some of that usage sends company data to a provider nobody vetted, and without a way to see it, there's no way to tell which.

How it works

Endpoint Guard installs a native agent on the device, macOS and Windows, running as a system service before login, with no per-user setup.

It intercepts only the domains it's told to watch, decrypts locally on the device, and sends the call to the same destination the user meant. It holds no provider API key. Cortega sees only what the device reports.

What's included

Local guardrails

A guardrail pack the device runs on its own, with no cloud call required. Pick an industry category (General, Healthcare, Finance, Government/classified) for a starter set of detectors, turn individual types on or off (SSNs, credit cards, phone numbers, addresses, medical and government identifiers, credentials, and more), and add custom patterns for org-specific terms. Each guardrail's action is observe (log only), mask, or reject, applied to the request, the response, or both. Configured independently of AI Border Gateway's own guardrails, and runs even when a device can't reach Cortega.

Budget checks

A device checks its team's remaining budget locally and allows or blocks a call before it's sent, using the same budget accounting AI Border Gateway uses.

Observability

Every observed request and response, in the same Observability view as AI Border Gateway's own traffic, filtered to the Endpoint Guard source.

Apps

Allow/deny rules for AI domains, applied to every device or overridden per domain. A domain not listed gets no interception and no guardrail.

Devices

Every enrolled device, by user, hostname, hardware serial, and how it proved its identity. Admins remove a device to free up its slot.

Enrollment options

An MDM rollout with per-device certificates for a fleet, a self-service rollout for admin-managed pilots, or a shared enrollment key for internal testing.

Fails open

If a device can't reach Cortega, AI traffic keeps working. A stricter, block-on-failure posture is available for customers who want it.

Install

The agent ships as a build artifact, .pkg for macOS and a .zip for Windows, from your Cortega admin or release engineer. See Install for the platform install paths that make Endpoint Guard available to enroll devices against.