Skip to main content
Enfors captures AI activity two ways, with no code changes:
  • Coding assistants — Claude Code (CLI) and Claude Desktop — are captured by the local watcher, which reads their session transcripts and uploads completed turns to data.enfors.ai. It reads files only; no proxy, no TLS interception, no certificate. This replaces the earlier mitmproxy approach.
  • Agent SDKs (e.g. the OpenAI SDK) call the Enfors gateway (llm.enfors.ai) directly, where each call is captured and enqueued.
This section is the buyer- and IT-facing summary. A complete IT & CISO Deployment Package — with the watcher/gateway internals and the MDM (Jamf/Mosyle) rollout runbook — is available under NDA from your Enfors representative.

What it does

  • Captures LLM / agent–human sessions, identity, and context — who, when, how.
  • Records the full decision record: inputs, evidence, reasoning trace, tool activity, findings, artifacts, operational telemetry, and metrics.
  • Gives IT and AI leadership visibility into who is using what, when, and how much.
  • Enables cost allocation and ROI measurement across the AI workforce.
  • Discloses itself to the monitored user: the Enfors mark is shown in the macOS menu bar or the Windows system tray exactly while capture is active (see the menu bar / tray indicator).

What it does not do

  • It does not modify the content of AI conversations.
  • For coding assistants, it does not run a proxy, intercept traffic, or install a certificate — the watcher only reads the local transcript.
  • It does not touch provider authentication or credentials.

How it’s deployed

What the system answers

  1. What did our agents produce? — an inventory of meaningful outputs per session.
  2. What are people using AI for? — use-case classification by person, team, and tool.
  3. Is this a one-off or a pattern? — behavioral signatures over time, so recurring work worth standardizing is distinguished from episodic exploration.

In this section

Data captured vs. not captured

What’s captured (gateway + watcher), what is never captured, and the PII nuance.

Data residency & retention

Region, encryption, and retention periods.

Tenant isolation & access

Row-Level Security and access controls.

Network & TLS

Connection paths and endpoints for the gateway and the watcher.

Security controls summary

The control-by-control summary and how to get the full package.

Enterprise deployment

Fleet rollout via MDM (Jamf/Mosyle).