Cloud Control Plane Blind Spot
- OpenAI and HuggingFace never touch CloudTrail
- SDKs slip in via .env files and lockfiles
- SaaS AI features leave no cloud audit trail
- Approvals lag actual usage by months
Discover unapproved AI in cloud and code, then map the frameworks, MCP servers, models, dependencies and secrets behind every agent.
Why It's Hard
Shadow AI hides in cloud control planes, in source code, and in the dependency tree of every agent framework you already have.

The valuable AI-governance work is deciding what is sanctioned. Agent workflows keep the discovery current and the risk-scored inventory ready so governance acts on findings rather than assembling them.
The Portfolio
Cloud control-plane analysis for native AI services plus source scans of your repositories for third-party SDKs, every finding scored by approval status and data volume, with the CloudTrail event IDs or exact source files cited.
See it workMaps agent frameworks, models, SDKs, MCP servers, prompt and tool schemas, dependencies, secrets and provenance, then flags vulnerable packages, poisoned artifacts, unsafe defaults and dangerous capabilities against where they are reachable.
01
Control-plane activity across accounts and regions is matched against a catalog of native AI services, the ones that leave a trail when they run.
02
Repositories are scanned for third-party AI SDKs, MCP servers, agent frameworks, the usage that never touches the cloud control plane and hides in dependency files and API keys.
03
Every dependency is resolved to its true origin and provenance, so a package that arrived transitively through an agent framework is attributed rather than hidden behind it.
04
Findings are ranked by approval status, data volume, and the capability they unlock, an unapproved high-volume service outranks a sanctioned one; a write-and-delete tool outranks a stale package nothing calls.
Coverage
Two discovery paths, one inventory, cloud shadow and code shadow surfaced together, with the evidence and the fix on every finding.
Native AI services across cloud accounts detected from control-plane activity, with principal, account, region and data volume attached.
OpenAI, Anthropic, Gemini, LangChain and HuggingFace usage found in code, from a gpt-4o call, an OPENAI_API_KEY in a .env, a transformers import.
Frameworks, MCP servers, SDKs, models, prompts, tool schemas, dependencies, secrets and provenance mapped for every agent workload.
Findings scored by approval status and the amount of data they move, the two things that must be blocked today are not lost among the approved ones.
Existing tools see fragments. Shadow-AI discovery pairs a cloud control-plane view with a source scan and adds the supply-chain map behind every agent, so the estate is inventoried before it is governed.
Business Outcomes
Seen
AI usage in cloud and in code, inventoried instead of invisible.
Ranked
Scored by sanction and volume, not by brand.
Actionable
Evidence and a tier-appropriate next step on every finding.
Discover unapproved AI usage across your cloud and your code, map the supply chain behind every agent, and score every finding by real risk.