Discovery & Governance

AI Risk Posture

What AI do we have — and how exposed is it?

Continuous discovery of every AI asset across cloud, endpoint, browser, and code. Understand each agent's supply chain, drift from trusted baseline, and shadow AI reaching your data — before something breaks.

Fits
Pre-runtime discovery + governance
Owned by
Security · Governance · GRC
Built on
Agentic Awareness Layer
Six Pillars

Every surface where AI touches your enterprise.

Risk Posture is not a single view. It's continuous coverage across six pillars — each a distinct surface where AI exposure is discovered, assessed, and governed.

01
AI Apps
Desktop, web, and SaaS AI applications discovered across the fleet.
02
Identities
Human, non-human, and machine AI actors with resolved attribution.
03
Shadow AI
Unsanctioned AI reaching corporate data through personal accounts, side-loaded installs, and unmanaged channels.
04
AI Agents
Custom agents, frameworks, and orchestrators — with full supply chain mapped.
05
MCP Servers
Sanctioned and shadow MCP servers, tool authority, protocol posture.
06
Data Risks
Exposure, exfiltration, secret leakage, compliance, shadow-AI data flows.

Continuous discovery.

AI adoption doesn't wait for procurement. Developers install agents on their laptops, teams sign up for SaaS copilots, engineers spin up MCP servers on their machines — every week. Traditional discovery tools scan on a schedule. By the time they run again, the estate has shifted.

Scan0 discovers every AI asset in your enterprise, continuously — across cloud accounts, endpoints, browsers, and CI/CD pipelines. Every install, every session, every model version, every MCP server. Fleet-wide.

What it catches A developer side-loads Cursor with a personal GitHub account on Monday. By Tuesday morning, Risk Posture surfaces it — identity mismatch flagged, install path unsanctioned, catalog gap noted.
Fleet Inventory · Last 24h
3,847 AI assets · 214 shadow
ENG-MBP-22
claude cursor codex · personal
MKTG-DESKTOP-11
copilot chatgpt
HR-LAPTOP-04
claude copilot
ENG-MBP-14
claude github-mcp · shadow supabase-mcp · shadow
FIN-LT-08
copilot slack-mcp · shadow
SALES-LAPTOP-01
cursor copilot
Coding agents 38% · Copilots 24% · MCP 19% 214 shadow · not in catalog

Supply chain risk.

An AI agent is never one thing. It's a foundation model, a set of toolsets, a knowledge base, a framework, an identity, and a chain of downstream calls. Risk hides in the connections — an over-scoped tool, a stale model, a knowledge base with public data, a gateway with weak guardrails.

Risk Posture maps every agent's full supply chain — models, toolsets, knowledge, gateways, and data sources — and evaluates risk at each edge. When something in the chain changes, you know before it propagates.

What it catches A staging agent runs without guardrails, no IAM role scoping, and no ownership tags — a shadow deployment ready to be promoted. Risk Posture flags it for approval before production.
cx_agent_staging · Bedrock AgentCore
Low Risk
cx_agent_staging LangGraph · Bedrock
Models
All Foundation MFoundation Model
Titan Text EmbedFoundation Model
Toolsets
k8s-apiGateway · 5
bedrockagentcoreToolset · 8
tavily-searchGateway · 1
Knowledge
agentic-ai-kbKnowledge Base
cx-agent-kbKnowledge · 5 issues
compliance-custoKnowledge Base

Behavioral drift.

AI environments don't stay still. A trusted baseline this morning becomes a different attack surface by afternoon — a new MCP command, an approved shell hook, a widened OAuth scope, a hidden character injected into a rules file.

Risk Posture continuously compares the current AI environment to a trusted baseline — and surfaces every drift, mapped to the surface it changes, with recommended remediation. Not just anomalies. Specific, indisputable changes with technical context.

What it catches A GitHub MCP command changes to add write access. Attack surface grows +68%. Risk Posture flags it as Critical with the exact permission diff — before an agent uses the new authority.
Behavioral Drift · Endpoint · 24h
9 findings
Repository Access Expanded
GitHub MCP command changed after trusted baseline.
Tool Surface
Critical
Execution Path Added
Link handler can run code from a single click.
Tool Surface
Critical
Automatic Shell Execution Enabled
Hook on SessionStart runs a shell command.
Tool Surface
Critical
Approval Guardrails Disabled
Tool calls no longer require user confirmation.
Tool Surface
High
Hidden Prompt Instructions
Bidirectional Unicode characters in rules file.
Reasoning
High
Shadow Configuration Detected
Auto-trust configuration appeared without baseline.
Composition
Medium

MCP tools risk.

MCP is where agents earn their power — and where authority sprawl begins. A local Postgres MCP server. A GitHub connector installed from a community catalog. A Slack MCP with authorization to post. Most enterprises can't answer a basic question: which MCP servers are running, on which endpoints, connected to what?

Risk Posture inventories every MCP server on every endpoint — sanctioned and shadow — and assesses each for tool authority, catalog compliance, exposure, and known vulnerabilities. From protocol poisoning to command injection to unauthenticated servers.

What it catches 62 endpoints run 24 distinct MCP servers outside the sanctioned catalog. Highest concentration: engineering laptops connecting to internal Postgres via personal installs. None have hit the secrets vault yet — but the authority path exists.
MCP Inventory · Shadow & Risk
62 outside catalog · 47 endpoints
github-mcp
ENG-MBP-22 · supabase-mcp
Shadow
postgres-mcp
LAPTOP-R180TR52
Shadow
slack-mcp
ENG-MBP-14 · linear-mcp
Shadow
vuln-mcp-server
Exposes tools without authentication
CVE
filesystem-sync
Agent can read/write local files
Tool Exposure
custom-rag
ENG-MBP-08 · github-mcp
Shadow

Shadow AI governance.

Shadow AI is not a policy failure — it's a discovery failure. Employees paste code into consumer LLMs, browsers connect to personal ChatGPT accounts on corp devices, marketing teams spin up SaaS copilots without IT, developers grant OAuth scopes to community agents.

Risk Posture surfaces every unsanctioned AI touching corporate data — across desktop, browser, cloud, and SaaS. Each with the identity behind it, the data path it touches, and a one-click path to sanction, block, or investigate.

What it catches 57 unsanctioned AI tools reaching corporate data across four surfaces. 24 users. 4 departments. All caught in the same week — before any triggered a policy violation.
Cross-Cutting Threat · 7d
Shadow AI
57
unsanctioned AI tools are touching your corporate data. Spans all four pillars — discovered, unsanctioned, receiving data, unmonitored at runtime.
Cloud
37
Browser
13
Desktop
7

Configuration posture.

Every AI deployment is a set of configuration choices — routes, policies, JIT trust settings, CI/CD guardrails, remediation paths. Get them wrong and the attack surface widens; get them right and enforcement follows. But nobody is auditing them continuously.

Risk Posture scores your full AI configuration posture in real time. Not a monthly report — a live score, categorized by the six pillars, with mitigation workflows for every gap: one-click routing through proxy, JIT trust enrollment, CI/CD remediation.

What it catches 607 configuration findings across the estate. 42% already mitigated, 25% one click away. Highest-impact gap: 174 workloads not routed through the enforcement proxy.
AI Security Posture · Today
↑ 2 vs yesterday
61
/ 100
Posture is elevated
57 shadow tools · 2 critical
27 runtime events
Enforcement live
607
Config Findings
42%
Mitigated
25%
One Click
Where It Fits

AI Risk Posture runs before something breaks.

Continuous, pre-runtime. Sits alongside AI Workload Security and Agentic Runtime Protection — three products, one platform.

Who Owns It

The teams responsible for AI asset posture, catching shadow AI, and enforcing pre-runtime compliance.

Security
Governance
GRC
Platform Engineering

See your AI attack surface.
Before something breaks.

Deploy in your VPC. Continuous. Sovereign. No data leaves your environment.