Skip to main content

🔨 Building in Public · Enterprise Roadmap · BSL 1.1 Licensed

I'm here as

Bypass the CISO Block.
Enable Secure AI Coding.

Tame the Sprawl. Securely deploy local AI coding tools (VS Code, IntelliJ, Cursor, Visual Studio) across your engineering team. Restrict directory access, prevent credential leaks, and audit spend out-of-band behind your firewall.

Explore Tiers ↓
Works with:
Google Antigravity Antigravity
VS Code Copilot Copilot
VS Code VS Code
IntelliJ IntelliJ
Cursor Cursor
Visual Studio Visual Studio
Claude Claude
Gemini Gemini
Google Antigravity Antigravity
VS Code Copilot Copilot
VS Code VS Code
IntelliJ IntelliJ
Cursor Cursor
Visual Studio Visual Studio
Claude Claude
Gemini Gemini
0% Leaks Plaintext credentials exposed in prompts
40% Saved Average LLM token waste reduction
< 10ms Local execution latency overhead
100% Audited SOC2 evidence logs compiled out-of-band

The Developer AI Wild West

The hidden risks of running unmonitored local AI agents.

Visibility Gap

The Black-Box Blindspot

Cloud gateways and proxies inspect only network payloads. They are completely blind to the local filesystem execution occurring on developer laptops.

Security Risk

The Exfiltration Threat

Recursive agent loops searching directories can autonomously read SSH credentials (`~/.ssh/id_rsa`) or local configuration configs, and stream them to external API endpoints.

Inefficiency

The Context Waste Drain

Local agents frequently ingest massive build caches and redundant project directory files, causing "lost-in-the-middle" attention degradation and inflating token spend.

Drift Control

Guideline Drift

AI assistants generate code loops without loading version-controlled security templates, resulting in silent syntax vulnerabilities and policy drift.

The Containment Framework

How Sprawl secures agent workloads without introducing developer latency.

[ PILLAR 1 ]

Workstation Sandbox

Restricts agent operations to targeted active project filesystems via local, directory-locked MCP servers, preventing access to host credentials and private configuration folders.

[ PILLAR 2 ]

Out-of-Band Telemetry

Logs session timelines and agent actions out-of-band directly to a self-hosted auditing dashboard, ensuring 100% data residency inside your corporate network.

[ PILLAR 3 ]

GitOps-Driven Audits

Enforces workspace rules via version-controlled templates in Git. Custom pre-commit gates evaluate session telemetry logs, blocking the commit if model rules or safety constraints were bypassed.

[ LIVE TELEMETRY DATA ]

The Telemetry Cockpit, Running Now

Real fleet analytics collected out-of-band from local developer workstations. 133 agent sessions. 11 workspaces. Zero editor lag. Zero cloud dependency.

01 / Fleet Overview

Fleet-Wide Compliance & Spend Auditing

Automatically harvest telemetry from all active developer workstations to get a unified view of your organization's AI usage. Monitor spend, token volume, and policy compliance in real-time.

  • 133 active agent sessions audited across 11 local workspaces.
  • $1.4180 accumulated spend tracked dynamically behind the firewall.
  • 94.7% rules compliance rate across all active developer environments.
Sprawl Fleet Analytics: $1.4180 accumulated cost, 5,019,714 tokens, 133 runs, 94.7% compliance rate
02 / Session Inspector

Deep-Dive Session Auditing

Inspect any individual agent run to see the exact context files ingested, token count distribution, and estimated cost breakdown. Drill down to prevent context bloat and optimize token efficiency.

  • Per-run cost estimating maps model price tokens to actual dollar spend.
  • Context coverage analysis tracks precisely which files (e.g. 6 of 135) were sent to the LLM.
  • Turn-by-turn volume metrics show token usage over 475 reasoning steps.
Sprawl Session Inspector: per-run cost, token breakdown, workspace file coverage analysis, and rules loaded
03 / Agent Audit Trail

Agent Reasoning & Tool Auditing

Capture the agent's internal thinking process and monologue before it executes a command. Audit the exact parameters, inputs, and outputs of local CLI tools and script runs.

  • Thinking monologue logs reveal model intent, reasoning steps, and safety checks.
  • Zero-overhead auditing extracts local histories with zero developer latency.
  • Audit-ready evidence logs mapping directly to SOC2 compliance criteria.
Sprawl Session Debugger: Agent's internal thinking process, monologue, and tool call execution details

Workspace Control Cockpit

How Sprawl satisfies the distinct requirements of your organization.

Secure Local Fencing & Compliance

Prevent local model tools from accessing host credentials. Sprawl encapsulates process namespaces, guaranteeing that agent actions remain directory-locked and fully logged.

  • Directory path-scoping via scoped MCP servers
  • Intercept path-traversal reads outside active folders
  • Full session audit logs, feed directly into your SOC2 evidence packages

Enforced Security Controls

Workstation-level constraints applied instantaneously upon initialization.

  • Filesystem Scoping: Directory-Locked
  • Credential Shielding: ~/.ssh Interception
  • Audit Logging: Zero-Overhead Local
  • Rules Compliance (POC): 94.7%, 5.3% gap detected
  • Audit Trail: SOC2 Evidence-Ready

Flexible Pricing Tiers

Select the plan that aligns with your workspace scale and policy requirements.

Community Tier

Individual Sandbox

For single engineers securing their personal workspaces and AI configs.

€0 / forever
  • ✓ Local CLI Workspace Grafting
  • ✓ Filesystem Boundary Fencing
  • ✓ Universal IDE Adapters (VS Code, IntelliJ, Cursor, Visual Studio)
  • ✓ 100% Offline & Private
Get Free CLI
Team Sync

Unified Governance

For engineering leads managing rules across teams of >5 developers.

€19 / seat / month excl. VAT
  • ✓ Zero-Knowledge Workspace Sync
  • ✓ Shared DNA & Persona Registry
  • ✓ Central Secret Injection (Key Vaulting)
  • ✓ Local Configuration Drift Alerts
  • ✓ GitOps pre-commit compliance gates
Enterprise

Sovereign Control

For high-compliance organisations requiring absolute security containment.

€39 / seat / month excl. VAT
  • ✓ Shell Sandboxing
  • ✓ Private Telemetry Dashboard
  • ✓ CI/CD PR compliance validation gates
  • ✓ SOC2/GDPR Cryptographic Evidence logs
  • ✓ SSO & Okta Directory Synchronization
  • ✓ Custom SLAs & Dedicated Support
The Enterprise Offer

The €100k/Year Secure AI Enablement Package (excl. VAT)

Unlock AI developer velocity (VS Code, IntelliJ, Cursor, Visual Studio) company-wide without security risk. Get up to 400 seat licenses, a self-hosted telemetry server (sprawl.telemetry) in your VPC, and a 3-day onsite CISO blueprinting and policy mapping workshop.

The 30-Day Security Integrity Guarantee

We guarantee deterministic workspace isolation. If your security team proves a containment breach or leak caused by Sprawl within 30 days, we refund 100% of your software license fee.*

*Subject to pre-agreed technical parameters. Professional services and travel fees are non-refundable.

Forward to your security team → sprawl.software/team

"Velocity without containment is just technical debt generation. The data proves it. The GitClear study shows that while AI speeds up typing, it triggers a 2x increase in code churn. We enforce deterministic context boundaries at the workstation file boundary before a single token is burned."

, Younes Baghor, Founder & Systems Architect

Frequently Asked Questions

What is Sprawl.software?

Sprawl.software is the workstation containment and telemetry layer for autonomous AI coding agents. We act as the local compliance fabric, giving enterprises unbreachable folder sandboxing and out-of-band audit trails without forcing you to use external cloud logins.

Does Sprawl make us SOC2 compliant?

No tool grants SOC2 certification. What Sprawl provides is the continuous audit trail that SOC2 auditors require as evidence: timestamped logs of every AI agent session, file access patterns, rules compliance rates, and tool execution history. Our telemetry output maps directly to SOC2 CC6.1 (logical access controls) and CC7.2 (system monitoring) criteria. Your auditor gets a queryable database, not a stack of self-reported questionnaires.

How does the out-of-band telemetry work?

Instead of intercepting network payloads or installing sluggish proxy servers, Sprawl harvests session telemetry out-of-band on the developer workstation. It parses prompt timelines, context coverage, and thinking steps with zero editor lag.

Where is my session telemetry data stored?

Your code, prompts, and credentials stay entirely behind your corporate firewall. Sprawl aggregates all telemetry in a local encrypted database and pushes it exclusively to a self-hosted Sprawl dashboard inside your private VPC. No code or keys ever touch Sprawl clouds.

What is the difference between Sprawl and Atomic Agentic Fabric (AFF)?

AFF is the open-source specification and schema layout format (declaring rules, workflows, and personas). Sprawl.software is the commercial containment runtime engine and compliance cockpit that reads those schemas, sets up filesystem sandboxes, and compiles editor bindings.

How is the agent containment enforced?

Containment is enforced via a local MCP server that acts as a file operations proxy for the agent. When an agent requests a file path read or write, the proxy validates that the target path is mathematically resolved within the allowed repository workspace root before permitting OS execution.