Skip to content
octic.ai

Find AI at every layer, not just the API.

Octic combines API, network, and kernel-level discovery into one map of your estate: AI agents, MCP servers, API endpoints, AI apps, packages, and processes.

Acme Corp's estate by discovery layer, showing all three layers: API, network, and kernel.
  • 2 of 8 are visible to an API-only inventory: support-triage-agent and the OpenAI API.
  • Network traffic adds invoice-extractor, which calls the OpenAI API, and mcp-postgres-prod, a flagged MCP server with production database access.
  • Kernel sensors on eng-ws-14 (Linux) and WIN-ENG-07 (Windows) add what runs on them: shadow-summarizer, a flagged AI agent with no owner that connects to mcp-postgres-prod, and Codex signed in with a personal account.
Discovery depth

An API-only inventory stops at 2 of 8.

Sensors see what runs on each host

Install the Octic sensor on servers and engineer laptops. It sees the AI apps, packages, dependencies, and processes on each host, including AI agents that never touch an API you manage.

Linux and Windows are supported today. Coverage grows as you roll sensors out.

Kernel sensors on three hosts and what each one finds running there.
  • eng-ws-14, Sensor LinuxHost. Approved.
  • shadow-summarizer, AI Agent. Flagged.
  • WIN-ENG-07, Sensor WindowsHost. Approved.
  • Codex, Software Application. Flagged.
  • ip-172-31-67-241, Sensor LinuxHost. Approved.
  • openai 1.51.0, Software Package. Unreviewed.
  • eng-ws-14 runs shadow-summarizer.
  • WIN-ENG-07 runs Codex.
  • ip-172-31-67-241 has package openai 1.51.0.

Network traffic shows what no inventory lists

Traffic analysis finds AI services that no inventory lists, such as an MCP server someone stood up without telling anyone, and the AI agents talking to it.

Relations seen in network traffic: AI agents connecting to MCP servers and calling model APIs.
  • invoice-extractor, AI Agent. Unreviewed. Found in network traffic.
  • shadow-summarizer, AI Agent. Flagged. Found by kernel sensor.
  • mcp-filesystem, MCP Server. Unreviewed. Found in network traffic.
  • OpenAI API, Model API. Approved. Found via API.
  • mcp-postgres-prod, MCP Server. Flagged. Found in network traffic.
  • invoice-extractor connects to mcp-filesystem.
  • invoice-extractor calls OpenAI API.
  • shadow-summarizer connects to mcp-postgres-prod.

API connections and sensors land in one map

Octic connects to the platforms you already run to list known AI agents, MCP servers, and API endpoints, then matches them against what the sensors and the network see. Every finding lands in one graph: which AI agents call which models, which MCP servers they use, and which hosts they run on.

Discovery runs in the background. New AI agents and MCP servers show up as they appear, not at the next quarterly audit.

One graph joining what API connections report with what kernel sensors found on each host.
  • eng-ws-14, Sensor LinuxHost. Approved.
  • Claude Code, Software Application. Approved. Found by kernel sensor.
  • payments-api, Code Repository. Approved. Found via API.
  • Anthropic API, Model API. Approved. Found via API.
  • ip-172-31-67-241, Sensor LinuxHost. Approved.
  • support-triage-agent, AI Agent. Approved. Found via API.
  • mcp-jira, MCP Server. Approved. Found via API.
  • eng-ws-14 runs Claude Code.
  • Claude Code commits to payments-api.
  • Claude Code calls Anthropic API.
  • ip-172-31-67-241 runs support-triage-agent.
  • support-triage-agent connects to mcp-jira.

Discovery is where the loop starts

What discovery finds is a starting point. Trust gives it an owner and a state, Observe shows what it does at runtime, and Remediate turns what is wrong into a finding with an owner. Agentic fixes are coming late 2026.

Put your own estate on the map

Install a sensor on a Linux or Windows host and coding-agent sessions start showing up, with no extra setup. Connect your APIs and the rest of the map fills in.

Or join the Design Partner Network.