Your team is running AI agents right now.
Your compliance team can't see or stop them.
Copilot, ChatGPT, Cursor, Claude, Sierra. Every AI tool your team uses supports MCP. That's the integration surface, and it's where Conduct enforces. Every tool call is visible. Every dangerous one can be blocked. Every decision lands in a signed audit trail you can prove.
Free tier Β· Installs in 10 minutes Β· No infrastructure changes
Where Conduct sits
Conduct makes compliance structural. Not documented after the fact. Enforced before execution.
βWhat impressed me most about Conduct AI is that it approaches AI governance as a business capability, not just a technical feature. By bringing together cost management, security controls, and compliance oversight in a scalable architecture, it addresses a need that many enterprises are actively trying to solve.β
Works with
From 18 days of production use, one developer
Small sample, real system. We'll publish team-scale numbers when we have them.
The Problem
AI agents ship code. Nobody sees what they actually did.
Your team is already using Claude, Codex, ChatGPT, Cursor, Copilot, and Windsurf. But when something breaks, there's no trail, no policy, no audit log, no budget control.
Your team shipped a Friday deploy that an AI forced through unreviewed.
You found out on Monday. The AI ran the command at 3pm. Nobody saw it.
Finance asked what AI cost last quarter. Engineering had no answer.
The bill arrived. The sprint was over. The conversation was already awkward.
You have an AI usage policy. It didn't stop anything.
It exists in a doc. It wasn't running at the moment the agent acted. That's the only moment that matters. Without runtime enforcement, agents experience permission drift, accumulating authority across tool calls that no single approval authorised.
The PR review script broke when the engineer who wrote it left.
It lived in their terminal. It drifted. It broke. It left with them.
What it does
Three things, all of them enforced.
See every session.
Within ten minutes of install you know which AI tools your team is running, who's using them, what they're calling, and what it costs, by developer, by day, by tool.
Block what shouldn't run.
Policies are YAML rules evaluated at the moment the agent acts. A blocked call exits with code 2 and the agent stops. Not a prompt instruction the model can talk itself out of.
Prove it afterward.
Every decision is written to a SHA-256 hash-chained log. One click confirms the record is intact. Export for compliance review in 30 seconds.
Covering a whole org takes one URL. GitHub Copilot for Business supports hosted MCP servers. An admin pastes the ConductGuard URL into org settings once and every developer is covered on their next session. No per-developer install.
The full stack
From standards to enforcement: three layers, one platform.
Team OS
Write down your standards
CLAUDE.md gives agents project memory. REVIEW.md sets the quality bar. Standards encode how your team handles auth, security, and migrations.
Get the templates β
SDD
Spec before you build
Generate a SPEC.md before agents touch code. Every decision has a why. Drift detection tells you when implementation diverges from intent.
Generate your spec β
Guard
Enforce it at the MCP layer
Guard intercepts every AI tool call before it runs. One policy across Claude Code, Cursor, Copilot, and every MCP client. Blocks, logs, audits automatically.
Explore Guard β
What governance actually tells you
Every AI session, explained in plain English.
Guard watches every tool call across every AI session: Claude Code, Claude.ai, Claude Desktop, Codex CLI, Codex Desktop, ChatGPT, Cursor, Copilot, Windsurf. At the end of each day, it surfaces one sentence that tells your team what happened, what was blocked, and what it cost.
Whatever your team runs in Claude, whether a diligence desk, a security audit OS, or an engineering autopilot, ConductGuard is the enforcement layer that makes it safe to hand to an executive.
Guard Β· AI Narrative
dev@yourteam.com
You spent $245/day on AI this period across claude-code, codex, and cursor. Guard intercepted 6 production deploys before they ran unreviewed, warned on 2 destructive commands, and screened 589 events for PII before they reached any LLM. Claude Code dominates at 96% of total spend. RTK and Booster offset $235, 5.6% back.
$4,170
AI spend
6
Deploys
589
PII events
$235
Saved
Force-deploy to production, intercepted
AI attempted vercel deploy --prod --force at 3:11pm on a Friday. Guard blocked it before it executed.
Secret embedded in git commit, caught
AI tried to commit code with a credential token in the commit message. Fired twice in the same session.
971 PII events in a single day
Jun 19 spiked 30Γ the 32/day baseline. Without Guard, every one of those calls would have sent raw credentials to an LLM.
What would have happened without Guard?
The production deploy would have executed. Six times in 18 days, on one developer's machine.
How ConductGuard is different
A gateway governs what the model costs. Conduct governs what the agent does.
Provider gateways sit between your team and the LLM. They cap spend, enforce SSO, and log model requests. That's the right layer for cost control.
Provider gateway
- βCaps LLM spend per user
- βSSO sign-in
- βModel selection controls
- βSees tool calls (Bash, Write, Read)
- βBlocks destructive commands before they run
- βDetects credential leaks in tool input
- βOne policy across Claude, Codex, ChatGPT, Cursor, Copilot
- βCustody proof log
ConductGuard
- βCaps LLM spend per user
- βSSO sign-in
- βModel selection controls
- βSees tool calls (Bash, Write, Read)
- βBlocks destructive commands before they run
- βDetects credential leaks in tool input
- βOne policy across Claude, Codex, ChatGPT, Cursor, Copilot
- βCustody proof log
Use a provider gateway for spend control. Use ConductGuard for everything the model touches after it decides what to do.
What we don't protect yet.
Credentials are decrypted in the executor process. There's no per-environment egress allowlist. We don't statically analyse third-party playbooks before install. All of it is documented, with our plan for each.
Read the threat model βGuard learns as it runs. Every session makes the next one more accurate for your team.
See how it works βBuilt for the people responsible for how AI gets used.
Built for the people responsible
for how AI gets used.
Engineering Leaders
Your team is using 4 AI tools. You don't know which ones, what they cost, or what they did.
Conduct gives you a single view across every tool, every developer, every session, without adding any process to your team's workflow.
- βSee every AI tool your team uses, in one dashboard
- βKnow what AI is costing you, by person and by project
- βEnforce your engineering standards automatically
- βAnswer security and compliance questions on demand
IT & Security Leaders
Your AI usage policy exists in a doc. It has never once stopped an agent.
Conduct enforces policy at the layer where agents actually run. Not in a review meeting, not in a Notion page. At the moment the tool call happens.
- βOne policy layer across Claude, Codex, ChatGPT, Cursor, Copilot, Windsurf. Every surface your team uses.
- βNo infrastructure changes. Works with your existing stack
- βRole-based policies for different teams and access levels
- βSpend budgets per developer, per tool, per project
Security & Compliance
Compliance asked for an AI audit trail. You had nothing to show them.
Every tool call, every decision, every developer, logged from day one. Export the audit trail in 30 seconds. Answer any question on demand.
- βCredentials and PII blocked before they reach any LLM
- βEvery tool call logged with decision, rule, and developer identity
- βSecurity scanning on every PR, automatic not manual
- βCompliance audit trail exportable on demand
See it in action
Watch ConductGuard block a privilege escalation in real time
Flexible deployment
SaaS
Up in minutes. No infra.
Cloud (BYOC)
Your AWS / GCP / Azure account.
On-premise
Air-gapped. Your data never leaves.
Your team is already
using AI agents.
Conduct is how you
run them and govern them.
GitHub gives the CISO a setting. ConductGuard gives them enforcement.
Free tier Β· No infrastructure changes Β· Works in minutes
