---
title: AI-TC Enterprise | AKA Security
url: https://akasecurity.io/technology/ai-tc-enterprise/
description: One signed AI Traffic Control policy across every endpoint.
---

# One signed policy across every endpoint.

AI Traffic Control Enterprise signs one policy, distributes it to the fleet and records what every endpoint enforces.

[Talk to an engineer](https://akasecurity.io/contact)

## Community and Enterprise.

Community is free for individual use. Enterprise adds central control across the organization.

## AI-TC Enterprise puts the fleet on the record.

1.  ### Every finding, fleet-wide

    A credential caught on one laptop is a fleet problem, not a laptop problem.

      This browser cannot play the demo. [Download the video.](https://akasecurity.io/demos/ai-tc-enterprise/credential-exposure.mp4) Read the Credential Exposure transcript

    Demo for AKA AI Traffic Control, or AI-TC for short. First, AI-TC is a solution you can deploy in your environment. While the harness plugin is open source, the Enterprise version is something that you can license from AKA. Once you've installed AI-TC in your environment, you'll be able to monitor deployment health and push the AI-TC plugin to all endpoints. Once on your endpoints, you'll be able to monitor what is being done with AI in your environment. First, it takes inventory of everything you have. It looks across the harnesses and by type. That includes all projects running on the endpoints, including correlation and deduplication of shared projects, skills, MCP servers and other configurations. Finally, credentials. Credential exposure looks for cases where a credential may be in the shell, on disk or in the transcript. Credentials exposed in a transcript or through another mechanism to an external party or LLM before AI-TC was installed are brought up as findings. In the overview, you can see which credentials may be at risk and which ones you want to change and rotate. AI-TC also tracks how long credentials have been in use and whether more than one team or project uses them. These could be signals that you need to rotate or split apart the credential at the source. In inventory, you can refine by type and look for potentially risky MCP servers. MCP servers that you haven't approved may be reviewed, then verified or blocked. If blocked, AI-TC prevents the harness on the endpoint from using the MCP server, so the user is unable to send data to it. That's it for this highlight. More highlights follow.

2.  ### Where the data actually goes

    Knowing which models the agents talk to is not the same as knowing what they send.

      This browser cannot play the demo. [Download the video.](https://akasecurity.io/demos/ai-tc-enterprise/data-shares.mp4) Read the Data Shares transcript

    AKA AI Traffic Control, or AI-TC for short, is open source. You can use the plugin directly in your harness to improve local security. You can also deploy it as a licensed tool in an Enterprise environment. Once licensed and set up, AKA AI-TC can be deployed to endpoints where people use Claude Code, Cursor, Codex or another harness. A browser plugin can check calls made through the browser to any of the LLMs. Once installed, it takes a full inventory of the harnesses on the endpoints, as well as projects, skills, MCP servers and other information. It also checks what data is being shared externally, both in code and through other harnesses. AI-TC determines whether you're sharing data with an endpoint that isn't an authorized provider and what kind of data is being sent. This provides central visibility into code that intentionally sends data out and harnesses that may be sending data externally. With this view, you can understand what developers or other people using AI in local coding work are sending to. You can flag it. To explore an individual case, open it to see where the call is going and what data is being sent. This gives you visibility into what is going to those endpoints. If you want to block an endpoint used by a specific harness, you can. If you want to change something in code, ask the developer to use their development tools to modify it. At least the visibility is there. That's an overview of how AI-TC checks data sharing.

3.  ### Deployed, signed, attested

    An endpoint that cannot prove what it is running is not enforcing.

      This browser cannot play the demo. [Download the video.](https://akasecurity.io/demos/ai-tc-enterprise/mdm-deployment.mp4) Read the MDM Deployment transcript

    For AKA AI Traffic Control, AI-TC, this demo reviews how AI-TC works with mobile device management. The harness plugin for AI-TC is available as open source. Pushing it to every endpoint requires a connector. After AI-TC Enterprise is deployed, its self-hosted environment connects devices through integrations. Add a directory such as Fleet, Microsoft Intune or Jamf. Connected endpoints appear automatically in the endpoints interface, along with a full inventory of connections. Applications connected through the SDK appear as well and do not have to go through MDM. Each endpoint shows whether its attestation is verified, confirming that the AKA AI-TC plugin is installed and working. The AI-TC CLI provides the base for Claude Code, GitHub Copilot, Codex and browser plugins. Those tools connect automatically and report to the Enterprise server. Configuration remains available through Fleet or another MDM. That is it for today. Another demo follows.
