AI Engineering Control Plane
Control and measure how AI actually builds software inside your company.
A small background agent observes how AI coding tools are used, sends privacy-filtered telemetry to one central portal, and helps engineering and security leaders govern, protect, and measure that usage across every tool.
No keystrokes, no screen capture, no raw prompts by default.

Works with
The visibility gap
Companies pay for AI coding tools but cannot answer basic questions
Are company subscriptions being used on company repositories or personal side projects?
Which MCP servers and local skills are wired into agents?
Are prompts leaking secrets or customer data?
How much of a pull request was written by AI?
Did AI-written code survive, or did it cause rework?
Each vendor shows only its own slice. MainLayer covers the whole AI development stack.
One operating layer
Five jobs. One clear view.
From the first local signal to the engineering outcome, MainLayer keeps the evidence connected.
Observe
See the AI development environment as it is—not as purchasing records suggest it should be.
- Installed AI tools by developer and device
- Active and idle sessions, models, MCP servers, and skills
- The repository behind every observed session
- Cross-provider visibility in one live inventory

Control
Set desired-state policy across tools while staying honest about what each provider can enforce.
- Approved tools and models by team
- Allowed MCP servers and prohibited skills
- Rules tailored to repository sensitivity
- Enforced, best-effort, detect-only, or unsupported status

Protect
Find risk before sensitive data leaves the machine and expose shadow AI usage without collecting source code.
- Local scanning for secrets, private keys, connection strings, and PII
- Warn, redact, or block actions where providers support them
- Detection of AI work in unmanaged repositories
- Visibility into tools the company never approved

Measure
Connect AI activity to pull requests and durable engineering outcomes—with confidence attached to every estimate.
- Adoption and AI-assisted pull request rates by team
- Estimated AI share backed by evidence, never text-style detection
- Code survival, rework, and revert rates at 7, 30, and 90 days
- Review time, agent retries, and human interventions


Optimize
Move from usage counts to the business value created by AI-assisted engineering.
- Cost per merged pull request
- Cost per accepted change
- Model and provider efficiency
- Quality-adjusted engineering value
Compare spend with work that survives review, merge, and production.
How it works
Useful evidence in four steps
The endpoint does the sensitive work locally. The portal gives every team a consistent operating view.
- 01
Connect your repositories
Sync the company inventory from GitHub, GitLab, or Bitbucket.
- 02
Install the endpoint agent
Enroll each monitored developer with one device-scoped command.
- 03
Discover tools automatically
MainLayer finds supported agents, models, MCP servers, and skills.
- 04
See policy and evidence
Policies, session evidence, and outcome metrics appear in the portal.
curl -fsSL https://mainlayer.ai/install.sh | shinstallmainlayer enroll --server https://api.mainlayer.ai --token enr_…enrollHonest by design. Every policy reports whether it is enforced, best-effort, or detect-only.
Security & privacy
Built to protect work, not watch people
MainLayer measures AI development activity with privacy boundaries developers can understand and security teams can verify.
We collect
- Tool, model, session, and repository context
- Fingerprints, counts, and risk labels
- Policy results and engineering outcomes
We never collect
- Keystrokes or mouse activity
- Screens or terminal history
- Unrelated application activity
- Raw prompts or source code by default
Device-scoped Ed25519 credentialsNo shared API keys on developer machines.
Local secret scanningRisk checks run before anything leaves the machine.
Metadata-only by defaultDerived evidence replaces sensitive content.

Evidence, not guesswork
Every attribution explains how much you should trust it
Direct provider diff
Provider-native evidence ties generated code to an exact change.
Tool, file, and time correlation
Multiple signals connect an AI session to a later change.
Excluded from headlines
Weak evidence stays visible for analysis but never inflates the main number.
Pricing
Simple, per monitored developer
Pay for the people whose AI development activity is monitored. Admins, managers, and viewers are free.
Observe
Per seatper monitored developer / month · early-access pricing for design partners
- Admins, managers, and viewers free
- Cross-provider visibility and inventory
- Control and Intelligence tiers coming
No. MainLayer observes AI development sessions, not people. It never collects keystrokes, mouse activity, screen captures, terminal history, or unrelated application activity, and it never ranks developers against each other.
The MVP targets Claude Code and Cursor first. The product is designed for adapters across Codex, Gemini CLI, and similar tools, and every integration reports exactly which capabilities it supports.
Metadata and derived signals such as fingerprints, counts, risk labels, provider, and repository state. Raw prompts and source code are off by default, and local secret scanning runs before anything is sent.
Hybrid and on-premises deployment are on the enterprise roadmap. If you need it for a pilot, tell us during onboarding and we will share timing.
MainLayer correlates direct provider diffs, tool and file events, repository context, and time windows. Every result carries a confidence tier; low-confidence estimates are excluded from headline metrics.
Policy evaluation happens locally in under 30 ms. Provider hooks fail open, so a MainLayer issue does not block the developer’s workflow.
Bring the whole stack into view
