New Patent Pending! Demos: MP4 | PDF Learn more →
EntPEP Enterprise Policy Enforcement Point
How it works Sign in
Governance for AI at work

Endpoint and proxy AI policy enforcement.

EntPEP intercepts every agent and chat request, checks it against central policy, enforces on the desktop or within the enterprise network, and keeps the record — so teams can use AI securely.

Enforcement on the endpoint via PreToolUse, PostToolUse and UserPromptSubmit hooks, or in the browser as a configured proxy for any AI provider.

The enforcement loop

Four steps, on every request.

The same loop runs whether the request comes from an agent on a laptop or a chat session in the browser. Nothing about the AI is trusted by default — each action is decided as it happens.

01

Intercept

Catch the action before it runs — a tool call via a PreToolUse hook, or a request through the browser proxy.

02

Evaluate

Check it against centrally managed policy: what this user, on this endpoint, in this company is allowed to do.

03

Enforce

Allow, block, or hold for approval — right on the desktop or at the server, before anything happens.

04

Log

Record the session — who, which agent, which model, what was allowed and what was stopped — as an auditable trail.

Governance model

One control plane, three roles.

EntPEP is multi-tenant: each company manages its own people, endpoints, and policy. Authority flows down the chain — each role invites the next.

Admin
Runs one company: its policy, its people. → invites managers
Manager
Adds users and approves access bundles when they’re requested. → invites users
User
Runs the agent on their endpoints; requests and uses the access they’re granted.
Patent pending · See it in action

One grant. Three surfaces. Per user.

A short walk-through: the same policy governs Claude Code, Claude.ai in the browser, and the Claude desktop app. Block before a tool runs, grant access to a person, and every one of their surfaces opens — then closes again on revoke.

Get started

Turn on the record.

Sign in to the console to enroll an endpoint, set policy, and watch sessions land in real time.

Sign in to the console