Product capabilities

See the AI estate. Decide what can act.

Your organisation owns the controls over reachable tools, credentials, shared state, and delegated authority. 3LS brings discovery and visibility into one operating surface, then connects inventory, policy decisions, approvals, cases, and evidence.

On supported managed MCP stdio paths, typed action classification can grant or deny before downstream, with journalled outcomes and at-most-once handling.

From signal to response

Inventory the relationship
Product, installation, account, endpoint, provenance, confidence, and freshness.
Evaluate the action
Action class, policy version, rule, rationale, acknowledgement, or approval.
Keep the evidence
Outcome, case history, remediation, coverage state, and audit record.

Operating surface

Follow one record from discovery to response

The useful feature is not another dashboard tile. It is the connection between what was found, which policy applied, what happened next, and what an operator can prove.

01

AI and MCP fleet inventory

See AI products, MCP servers and installations, accounts, devices, and the associations between them. Each record keeps provenance, confidence, ownership, first-seen and last-seen evidence, and coverage freshness in view.

What is installed, where did it come from, and is it still active?

  • Managed and user-installed software
  • Endpoint and account associations
  • Coverage views and inventory exports
02

Managed MCP action controls

On supported managed MCP stdio paths, typed action classification identifies an operation as read, write, delete, admin, execute, or unknown. 3LS can hold the action for acknowledgement or privileged approval, then grant or deny before downstream.

What is the agent trying to do, and does this policy version authorise it?

  • Policy-bound holds and approvals
  • Zero downstream calls for denied operations
  • Journalled outcomes and at-most-once handling
03

Risk, findings, and cases

Turn current inventory evidence into deterministic findings, a versioned 0–100 risk score, issues, and incidents. Operators can see recurrence, dismiss with a recorded reason, or attach remediation evidence.

Which exposure needs attention now, and what proof closes it?

  • Explainable severity and risk factors
  • Issue and incident timelines
  • Recurrence and remediation evidence
04

Policy lifecycle and approvals

Create a draft, validate it, publish a signed version, assign it, roll it out, and see which endpoints have acknowledged it. Rollback intent and approval history remain part of the audit trail.

Which policy made this decision, who changed it, and where is it active?

  • Separate author, publisher, and responder roles
  • Versioned validation and rollout
  • Endpoint acknowledgement and rollback
05

Enterprise console

Work from one routed operator surface for AI agents, MCP, devices, activity, issues, risk frameworks, policies, approvals, coverage, configuration status, and audit records.

Can an operator move from an inventory record to the decision and its evidence?

  • Filterable inventory and exports
  • Issue, policy, and approval drill-down
  • Coverage, activity, and audit workspaces
06

Sensitive-data and prompt-risk detectors

Inspect supported observable channels for PII, PHI, financial data, credentials and secrets, and infrastructure patterns. Prompt heuristics add evidence for jailbreak, role-override, and policy-evasion signals.

What sensitive material or instruction pattern is present in the activity 3LS can observe?

  • Bounded request and response scanning
  • Pattern packs for common sensitive-data classes
  • Detector evidence, not a compliance certification
07

Browser and API workflow controls

Bring supported ChatGPT and Claude browser activity, plus OpenAI and Anthropic API traffic, into the same policy and evidence model. Security teams can review prompt, upload, and API-route activity alongside the rest of the AI estate.

Which AI channel is in use, and what company policy should apply?

  • Edge and Chrome controls for supported AI sites
  • Managed routing for supported API clients
  • Redacted evidence and policy outcomes
08

Privacy-safe evidence

Central inventory and audit records use bounded metadata, argument hashes, redacted fields, and tenant-scoped identifiers. Raw prompts, secrets, or local transcripts are not collected into those records by default.

What does the security team need to decide, and what data can stay on the endpoint?

  • Secret presence without secret values
  • Bounded evidence and redacted audit fields
  • Tenant-isolated records and signed cursors

Integrations

Keep the security workflow you already run

3LS evidence does not have to end in a separate queue. Connect it to the systems your SOC, governance team, and service owners already use.

Available enterprise integrations. Exact deployment and connector availability is confirmed during solution design.

Explore enterprise security integrations
SIEM

Splunk, QRadar, and Microsoft Sentinel

Put findings and audit evidence beside the rest of the security estate.

SOAR

Phantom and Demisto

Carry 3LS events into existing triage and response playbooks.

Ticketing

ServiceNow and Jira

Route ownership, remediation, and follow-up through established queues.

Extensibility

APIs and webhooks

Connect inventory, evidence, and response data to internal workflows.

Bring one real workflow

We will map the endpoint, AI or MCP association, policy decision, approval path, evidence, and integration handoff with your team.

See the product walkthrough