AI Engineering Control Plane
Control and measure how AI actually builds software inside your company.
A small background agent observes how AI coding tools are used, sends privacy-filtered telemetry to one central portal, and helps engineering and security leaders govern, protect, and measure that usage across every tool.
No keystrokes, no screen capture, no raw prompts by default.

Works with
The visibility gap
Companies pay for AI coding tools but cannot answer basic questions
Are company subscriptions being used on company repositories or personal side projects?
Which MCP servers and local skills are wired into agents?
Are prompts leaking secrets or customer data?
How much of a pull request was written by AI?
Did AI-written code survive, or did it cause rework?
Each vendor shows only its own slice. MainLayer covers the whole AI development stack.
One operating layer
Five jobs. One clear view.
From the first local signal to the engineering outcome, MainLayer keeps the evidence connected.
Observe
See the AI development environment as it is—not as purchasing records suggest it should be.
- Installed AI tools by developer and device
- Active and idle sessions, models, MCP servers, and skills
- The repository behind every observed session
- Cross-provider visibility in one live inventory

Control
Set desired-state policy across tools while staying honest about what each provider can enforce.
- Approved tools and models by team
- Allowed MCP servers and prohibited skills
- Rules tailored to repository sensitivity
- Enforced, best-effort, detect-only, or unsupported status

Protect
Find risk before sensitive data leaves the machine and expose shadow AI usage without collecting source code.
- Local scanning for secrets, private keys, connection strings, and PII
- Warn, redact, or block actions where providers support them
- Detection of AI work in unmanaged repositories
- Visibility into tools the company never approved

Measure
Connect AI activity to pull requests and durable engineering outcomes—with confidence attached to every estimate.
- Adoption and AI-assisted pull request rates by team
- Estimated AI share backed by evidence, never text-style detection
- Code survival, rework, and revert rates at 7, 30, and 90 days
- Review time, agent retries, and human interventions


Optimize
Move from usage counts to the business value created by AI-assisted engineering.
- Cost per merged pull request
- Cost per accepted change
- Model and provider efficiency
- Quality-adjusted engineering value
Compare spend with work that survives review, merge, and production.
How it works
Useful evidence in four steps
The endpoint does the sensitive work locally. The portal gives every team a consistent operating view.
- 01
Connect your repositories
Sync the company inventory from GitHub, GitLab, or Bitbucket.
- 02
Install the endpoint agent
Enroll each monitored developer with one device-scoped command.
- 03
Discover tools automatically
MainLayer finds supported agents, models, MCP servers, and skills.
- 04
See policy and evidence
Policies, session evidence, and outcome metrics appear in the portal.
curl -fsSL https://mainlayer.ai/install.sh | sh -s -- --token enr_…install + enrollHonest by design. Every policy reports whether it is enforced, best-effort, or detect-only.
Policy engine
One policy for every AI coding tool, enforced where it can be and honest where it cannot
Write a rule once. MainLayer distributes it to every developer machine as a signed bundle, applies it inside Claude Code, Cursor, Codex, Gemini CLI and the rest, and tells you per tool whether the outcome was enforced, warned, or only observed.
Approved tools and models
Allowlist providers and models per organization, team, repository pattern, or person. Anything outside the list is logged, warned, or blocked.
MCP servers and skills
Allow or deny MCP servers and skills by name, pinned to a version fingerprint so a silently changed server no longer passes.
Secrets and personal data
Keys, tokens, private keys, card numbers and IDs are detected on the developer machine. Warn, redact the input, or block the call. The matched text never leaves the device.
Repository rules
Unmanaged repositories, restricted repositories by name pattern, and escalation after repeated use. Time-boxed exceptions with an approval trail.

Every rule starts in log mode. Before you turn on warn or block, MainLayer shows how many sessions, developers and tools it would have touched in the last 30 days.
Each policy reports enforced, warn-only, observe-only, or unsupported per provider, using each tool's real hook capabilities. No policy is ever claimed as blocking when it cannot be.
Bundles are Ed25519-signed and pinned on the device. If the control plane is unreachable, the last good bundle applies and nothing ever fails closed against a developer.
Developers see which rules apply to them, get a clear message with your contact line when something is stopped, and can request a time-boxed exception from their own workspace.
Security & privacy
Built to protect work, not watch people
MainLayer measures AI development activity with privacy boundaries developers can understand and security teams can verify.
We collect
- Tool, model, session, and repository context
- Fingerprints, counts, and risk labels
- Policy results and engineering outcomes
We never collect
- Keystrokes or mouse activity
- Screens or terminal history
- Unrelated application activity
- Raw prompts or source code by default
Device-scoped Ed25519 credentialsNo shared API keys on developer machines.
Local secret scanningRisk checks run before anything leaves the machine.
Metadata-only by defaultDerived evidence replaces sensitive content.

Evidence, not guesswork
Every attribution explains how much you should trust it
Direct provider diff
Provider-native evidence ties generated code to an exact change.
Tool, file, and time correlation
Multiple signals connect an AI session to a later change.
Excluded from headlines
Weak evidence stays visible for analysis but never inflates the main number.
Pricing
Simple, per monitored developer
Pay only for the people whose AI development activity is monitored. SSO is included in every plan. Every plan starts with a 14-day free trial for up to 5 developers; a card is required and nothing is charged until the trial ends.
Billed per monitored developer. Admins, managers and viewers are free.
Observe
$12per monitored developer / month, billed annually
- Endpoint agent for nine AI coding tools
- Sessions, adoption, teams, repositories, unmanaged repo detection
- AI-assisted PRs and contribution estimates with confidence
- Token usage and cost estimates, 30-day retention
- SSO, audit log, metadata-only by design
Observe + Govern
$24per monitored developer / month, billed annually
- Policy engine: provider, model, MCP and skill allow/deny
- On-device secret and PII detection with warn, redact or block
- Shadow AI discovery and MCP proxy enforcement
- Signed policy bundles, exception workflow, security admin role
- Audit export with integrity chain, 12-month retention
Enterprise
Customfrom 100 monitored developers, annual agreement
- SCIM, on-prem or hybrid, data residency
- Custom retention, customer-managed keys
- Policy packs, custom adapters, SLA and named CSM
- Attribution & ROI intelligence add-on available on every plan
A seat is one monitored developer: a person whose enrolled endpoint produced at least one AI session in the trailing 30 days. Admins, managers, security admins, finance users, and viewers are free and unlimited.
Yes. Every plan starts with a 14-day free trial that covers up to 5 monitored developers. A card is required at checkout, nothing is charged until the trial ends, and you can cancel from the billing portal at any time before then.
When your active monitored developer count exceeds the seats you purchased, automatic true-up increases your subscription quantity. We only increase seats automatically, never decrease them; use the billing portal to make downward adjustments.
Yes. Pick the Govern plan at checkout and the same 14-day trial applies, including the policy engine, DLP, MCP proxy, notifications and event streaming. Discount codes can be entered on the checkout page.
Polar is our merchant of record and handles checkout, cards, invoices, VAT and other applicable taxes, and the customer billing portal. MainLayer never stores your card details.
Bring the whole stack into view
