Runtime control layer

Own the controls around AI use.

3LS gives your organisation visibility across Codex, Claude, browsers, and MCP-connected systems, with discovery, classification, policy evaluation, and evidence for broad AI use. Your organisation owns the controls over reachable tools, credentials, shared state, and delegated authority. On supported managed MCP stdio paths, 3LS can grant or deny before downstream and record journalled outcomes.

Runtime AI governance console shows broad usage evidence and its policy evaluation.
Visibility:
On-device collection brings supported AI activity into view for classification and policy evaluation.
Policy ownership:
Your organisation owns the policy evaluation and the resulting evidence.

Why Three Laws?

Why we called it Three Laws Security

Asimov described an order of responsibility. He did not describe a security architecture. We use the name because the organisation, not the model, must decide what its agents are allowed to do.

Broad AI activity can be discovered, classified and evaluated. Pre-execution grant or deny remains limited to supported managed MCP stdio paths.

Runtime control capabilities

A small set of runtime decisions security teams can explain, audit, and apply consistently.

AI visibility

See how people, assistants, and agentic tools are using AI across the organization.

Prompt classification

Understand whether AI is being used for drafting, coding, research, data handling, or higher-risk workflows.

Sensitive data detection

Detect PII, secrets, and restricted content before it becomes an incident or a compliance problem.

Policy evaluation

Evaluate observed activity against policy. Supported managed MCP stdio operations can be granted or denied before downstream.

Go deeper into fleet inventory, managed MCP actions, risk and cases, policy rollout, approvals, privacy-safe evidence, and enterprise integrations.

See all product capabilities

Detect and manage shadow AI usage

Discover unmanaged AI use across browsers, assistants, coding tools, and agentic workflows before it becomes an exposure problem.

Recognize real tools in use

Identify usage across tools like Codex, Claude, browser-based assistants, MCP-connected workflows, and other agentic tools.

Separate approved from unmanaged use

Understand which tools and workflows align with policy and which ones need review, coaching, or controls.

See trends before they become incidents

Track adoption, risky behavior, and sensitive usage patterns so security teams can act early.

Evidence trace

Unmanaged browser assistant

Source
Browser assistant in finance workspace
Classified as
Data handling with external destination
Policy result
Needs review Evidence retained

Detect what matters

Focus operator attention on the usage, content, and actions that actually change risk.

Understand intent

Classify whether AI is being used for drafting, coding, research, summarization, or sensitive data handling.

  • Drafting and editing
  • Coding and agentic development
  • Research and synthesis

Detect sensitive content

Highlight when prompts, outputs, or tool actions involve PII, credentials, or restricted internal data.

  • PII and customer records
  • Secrets and tokens
  • Restricted internal material

Evaluate risky behavior

Apply policy based on context, from simple visibility and evidence to review and escalation.

  • Observe and classify
  • Evaluate and review
  • Escalate with evidence

Evidence for operators, clear outcomes for teams

Give security teams clear evidence and effective controls without turning every AI interaction into a manual review queue.

See usage patterns clearly.

Understand which tools are managed and which are shadow AI.

Respond to risky behavior with consistent controls.

Keep a clear audit trail of findings and outcomes.

Operator evidence view highlights PII in a customer CSV upload and records a policy evaluation with its rationale.

Bring AI use into view

Detect shadow AI usage, understand how tools like Codex and Claude are being used, and evaluate that activity against policy with clear evidence.