Developer fleet
A light agent on developer machines reports what is installed and where it came from, signed, so you know your build environment before an attacker does.
What it watches
- Packages, ten ecosystems and more
npm, pip, Homebrew, Cargo, Go, Maven, NuGet, Composer, RubyGems and Conda: names, versions and sources.
- IDE extensions
Extensions in each editor, their publisher, their version and the permissions they ask for.
- Browsers and browser extensions
Which browsers developers use and which extensions can read the pages they open.
- AI tools
Coding agents and assistants installed locally, handed to the AI posture module.
- Coverage and agent health
Which machines report, which stopped, and which run an old agent.
- Exposure surface
Per machine: how much of the line it can reach, from source code to cloud credentials.
One machine, everything on it
A slice of one developer's inventory. The tower ranks each item by what it can reach, not by how often it is used.
| Installed | Reads code | Holds tokens | Runs shell | Talks to internet | Exposure |
|---|---|---|---|---|---|
| AI coding agent | ●yes | ●yes | ●yes | ●yes | High |
| npm package with install script | ●yes | ●yes | ●yes | ●yes | High |
| Cloud CLI | ·no | ●yes | ●yes | ●yes | High |
| Browser extension: all sites | ·no | ●yes | ·no | ●yes | Medium |
| IDE Git extension | ●yes | ●yes | ·no | ●yes | Medium |
| Homebrew formula | ·no | ·no | ●yes | ·no | Low |
| Colour theme | ·no | ·no | ·no | ·no | Low |
How it connects
Every module reports to the tower. Some feed each other.
The services behind it
The module watches. These services set the station up, with your team, so there is something worth watching.
In development. Early-access teams get it first and shape what it watches.
Join early access →