AI Engineering Control Plane

Control and measure how AI actually builds software inside your company.

A small background agent observes how AI coding tools are used, sends privacy-filtered telemetry to one central portal, and helps engineering and security leaders govern, protect, and measure that usage across every tool.

No keystrokes, no screen capture, no raw prompts by default.

MainLayer overview showing AI adoption, live sessions, policy coverage, and repository activity
Overview · one place for every AI coding tool

Works with

Claude CodeCursorGitHub CopilotCodex CLIGemini CLIAntigravityAmpOMPOpenCodeGitHubGitLabBitbucketAzure DevOps

The visibility gap

Companies pay for AI coding tools but cannot answer basic questions

01

Which AI tools and models are actually used, and by whom?

02

Are company subscriptions being used on company repositories or personal side projects?

03

Which MCP servers and local skills are wired into agents?

04

Are prompts leaking secrets or customer data?

05

How much of a pull request was written by AI?

06

Did AI-written code survive, or did it cause rework?

Each vendor shows only its own slice. MainLayer covers the whole AI development stack.

One operating layer

Five jobs. One clear view.

From the first local signal to the engineering outcome, MainLayer keeps the evidence connected.

01

Observe

See the AI development environment as it is—not as purchasing records suggest it should be.

  • Installed AI tools by developer and device
  • Active and idle sessions, models, MCP servers, and skills
  • The repository behind every observed session
  • Cross-provider visibility in one live inventory
MainLayer sessions page listing active and recent AI coding sessions by provider, developer, and repository
Sessions · live activity across providers
02

Control

Set desired-state policy across tools while staying honest about what each provider can enforce.

  • Approved tools and models by team
  • Allowed MCP servers and prohibited skills
  • Rules tailored to repository sensitivity
  • Enforced, best-effort, detect-only, or unsupported status
MainLayer findings page listing secret detections, shadow AI tools, and exception requests
Findings · secrets, shadow AI, exceptions
03

Protect

Find risk before sensitive data leaves the machine and expose shadow AI usage without collecting source code.

  • Local scanning for secrets, private keys, connection strings, and PII
  • Warn, redact, or block actions where providers support them
  • Detection of AI work in unmanaged repositories
  • Visibility into tools the company never approved
MainLayer repositories page highlighting unmanaged repositories where AI tools were used
Repositories · shadow usage made visible
04

Measure

Connect AI activity to pull requests and durable engineering outcomes—with confidence attached to every estimate.

  • Adoption and AI-assisted pull request rates by team
  • Estimated AI share backed by evidence, never text-style detection
  • Code survival, rework, and revert rates at 7, 30, and 90 days
  • Review time, agent retries, and human interventions
MainLayer pull requests page showing AI contribution, confidence, and review outcomes
Pull requests · evidence-backed attribution
MainLayer adoption page charting AI coding tool usage by team and provider
Adoption · team and provider trends
05

Optimize

Move from usage counts to the business value created by AI-assisted engineering.

  • Cost per merged pull request
  • Cost per accepted change
  • Model and provider efficiency
  • Quality-adjusted engineering value
Coming with Intelligence tier
Cost per accepted changeIntelligence tier

Compare spend with work that survives review, merge, and production.

How it works

Useful evidence in four steps

The endpoint does the sensitive work locally. The portal gives every team a consistent operating view.

MainLayer data flowRepository providers connect to a local endpoint agent, which discovers AI tools and sends privacy-filtered evidence to the MainLayer portal.Git providersEndpoint agentTools discoveredEvidence in portal
  1. 01

    Connect your repositories

    Sync the company inventory from GitHub, GitLab, or Bitbucket.

  2. 02

    Install the endpoint agent

    Enroll each monitored developer with one device-scoped command.

  3. 03

    Discover tools automatically

    MainLayer finds supported agents, models, MCP servers, and skills.

  4. 04

    See policy and evidence

    Policies, session evidence, and outcome metrics appear in the portal.

$curl -fsSL https://mainlayer.ai/install.sh | sh -s -- --token enr_…install + enroll

Honest by design. Every policy reports whether it is enforced, best-effort, or detect-only.

Policy engine

One policy for every AI coding tool, enforced where it can be and honest where it cannot

Write a rule once. MainLayer distributes it to every developer machine as a signed bundle, applies it inside Claude Code, Cursor, Codex, Gemini CLI and the rest, and tells you per tool whether the outcome was enforced, warned, or only observed.

  • Approved tools and models

    Allowlist providers and models per organization, team, repository pattern, or person. Anything outside the list is logged, warned, or blocked.

  • MCP servers and skills

    Allow or deny MCP servers and skills by name, pinned to a version fingerprint so a silently changed server no longer passes.

  • Secrets and personal data

    Keys, tokens, private keys, card numbers and IDs are detected on the developer machine. Warn, redact the input, or block the call. The matched text never leaves the device.

  • Repository rules

    Unmanaged repositories, restricted repositories by name pattern, and escalation after repeated use. Time-boxed exceptions with an approval trail.

MainLayer policies page listing organization rules with kind, scope, action, enforcement mix, and pending exception requests
Policies · rules, enforcement mix, and exception requests
Simulate first

Every rule starts in log mode. Before you turn on warn or block, MainLayer shows how many sessions, developers and tools it would have touched in the last 30 days.

Honest enforcement

Each policy reports enforced, warn-only, observe-only, or unsupported per provider, using each tool's real hook capabilities. No policy is ever claimed as blocking when it cannot be.

Signed and offline-safe

Bundles are Ed25519-signed and pinned on the device. If the control plane is unreachable, the last good bundle applies and nothing ever fails closed against a developer.

Developer-facing

Developers see which rules apply to them, get a clear message with your contact line when something is stopped, and can request a time-boxed exception from their own workspace.

Security & privacy

Built to protect work, not watch people

MainLayer measures AI development activity with privacy boundaries developers can understand and security teams can verify.

We collect

  • Tool, model, session, and repository context
  • Fingerprints, counts, and risk labels
  • Policy results and engineering outcomes

We never collect

  • Keystrokes or mouse activity
  • Screens or terminal history
  • Unrelated application activity
  • Raw prompts or source code by default

Device-scoped Ed25519 credentialsNo shared API keys on developer machines.

Local secret scanningRisk checks run before anything leaves the machine.

Metadata-only by defaultDerived evidence replaces sensitive content.

MainLayer personal activity page showing the AI usage data visible to a developer
Every developer sees exactly what their company sees.

Evidence, not guesswork

Every attribution explains how much you should trust it

High

Direct provider diff

Provider-native evidence ties generated code to an exact change.

Medium

Tool, file, and time correlation

Multiple signals connect an AI session to a later change.

Low

Excluded from headlines

Weak evidence stays visible for analysis but never inflates the main number.

Pricing

Simple, per monitored developer

Pay only for the people whose AI development activity is monitored. SSO is included in every plan. Every plan starts with a 14-day free trial for up to 5 developers; a card is required and nothing is charged until the trial ends.

Billed per monitored developer. Admins, managers and viewers are free.

Observe

Observe

$12per monitored developer / month, billed annually

  • Endpoint agent for nine AI coding tools
  • Sessions, adoption, teams, repositories, unmanaged repo detection
  • AI-assisted PRs and contribution estimates with confidence
  • Token usage and cost estimates, 30-day retention
  • SSO, audit log, metadata-only by design
Start 14-day free trial
Govern

Observe + Govern

$24per monitored developer / month, billed annually

  • Policy engine: provider, model, MCP and skill allow/deny
  • On-device secret and PII detection with warn, redact or block
  • Shadow AI discovery and MCP proxy enforcement
  • Signed policy bundles, exception workflow, security admin role
  • Audit export with integrity chain, 12-month retention
Start 14-day free trial
Enterprise

Enterprise

Customfrom 100 monitored developers, annual agreement

  • SCIM, on-prem or hybrid, data residency
  • Custom retention, customer-managed keys
  • Policy packs, custom adapters, SLA and named CSM
  • Attribution & ROI intelligence add-on available on every plan
Talk to sales

Pricing FAQ

Straightforward billing, without surprises

Have another question? Talk to the team.

Bring the whole stack into view

Know how AI actually builds software in your company.