Browser extension
Govern AI in the browser
Route work email to company SSO for governed access to AI. Or create setup/recovery access when you need it.
Browser prompts, MCP tools, and app grants resolve into one evidence chain.
Govern AI in the browser
Control tool and model access
Discover and assess enterprise apps
You're in control. Aegress doesn't access your data.
Governs every AI surface your team already uses
AI surfaces
Enterprise apps
Why Aegress
Control and evidence that keep up with how quickly your team picks up new tools.
Discover shadow AI across browsers, MCP clients, and Entra app grants in a single view.
Identity-first routing keeps people moving while policy runs quietly in the background.
Every access decision lands in an append-only audit chain you can export for review.
Trace intelligence
Browser
Prompts and extension policy
MCP
Tool call scope and client
Entra
App grants and ownership
Identity
SSO, SCIM, owner access
Policy
Allow, warn, block, monitor
Evidence
Hash-linked audit trail
Coverage modes
Extension, MCP gateway, and Entra app scan stay separate in setup, then converge into one audit chain.
Traceback canvas
Policy decision
The same user, tool, policy, and tenant context follow the trace.
Evidence chain
Verifiable records are ready for audit, export, and replay.
Entry logic
We route work email traffic to company SSO once a domain is verified, keep a setup/recovery owner for bootstrap and recovery, and choose coverage mode only after identity is established.
Work email routes to company SSO when a domain is verified.
Setup/recovery owner access stays for bootstrap and recovery.
Coverage mode is chosen after identity: extension, gateway, or scan.
Evidence
Governed access produces an immutable record you can hand to a compliance review — no scrambling for screenshots.
Evidence chain
Immutable audit trail for AI access and activity
SSO connection
Microsoft 365AI access allowed
ChatGPTMCP tool call
Jira MCPGrant scan
Entra IDSSO-native
Verified domains route to your IdP.
No data access
Aegress never reads your content.
Append-only evidence
Tamper-evident, hash-verified logs.
Minutes to deploy
Extension rollout in three steps.
FAQ
The questions security and IT teams raise first.
No. Aegress governs access and records the metadata needed for evidence. It never reads your prompts, files, or content.
Verify a domain to route work email through SSO, or create a setup/recovery owner first. Extension rollout is connect, assign, verify.
Browser AI extensions, MCP clients and agent tools, and Microsoft 365 and Entra app grants — governed from one place.
Every decision is written to an append-only, hash-verifiable audit chain you can export by tool, user, or time window.
Route a verified domain to SSO, or create setup/recovery access in minutes.
You’re in control. Aegress doesn’t access your data.