Integrations
Every AI surface. Governed from one place.
MCP clients, AI API proxies, browser-based AI services, vibe-coding platforms, SaaS admin APIs, identity providers, SIEM destinations. No agent code changes. Here's the full map.
The numbers.
Agents point at the proxy. Policy enforced from day one. Your SIEM gets better data. Your compliance team gets an audit artifact.
11 MCP clients/6 AI API proxies/12 browser services/7 vibe-coding platforms/30 AI platforms discoverable/4 SIEM connectors
MCP clients.
Agents point their MCP config at the Behavry proxy. Every tool call is governed before execution: identity, DLP, policy, audit. No agent code changes.
| Client | Transport |
|---|---|
| Claude Desktop | Streamable HTTP |
| Claude Code | Streamable HTTP |
| Cursor | Streamable HTTP |
| Windsurf | Streamable HTTP |
| Zed | Streamable HTTP |
| VS Code / Copilot | Streamable HTTP |
| JetBrains IDEs | Streamable HTTP |
| Warp Terminal | Streamable HTTP |
| Cline | Streamable HTTP |
| Continue | Streamable HTTP |
| Open Interpreter | stdio · critical risk tier |
Plus fingerprints for Google Antigravity, OpenAI Codex CLI, and Amazon Kiro. Any MCP client supporting Streamable HTTP or stdio works. The proxy is protocol-agnostic.
AI API proxies.
Transparent reverse proxies for major AI model APIs. Identity, DLP, policy, and audit applied to every API call. Token extraction for cost attribution across all 6.
| Provider | Models |
|---|---|
| OpenAI | GPT-4o, o1, o3 |
| Anthropic | Claude 4, Sonnet, Haiku |
| Google Gemini | Gemini 2.5 |
| Ollama | Local models |
| NemoClaw | NVIDIA NIM |
| OpenShell | Open-source models |
Cost attribution with 14 seeded model prices + tenant-configurable overrides. Aggregation API with CSV export.
Browser extension.
DLP scanning on browser-based AI interactions. 26 patterns in real time. Shadow AI detection for unenrolled services.
ChatGPT/Claude/Gemini/Perplexity/DeepSeek/Copilot/Poe/HuggingChat/You.com/Phind/Mistral Le Chat/GitHub Copilot Chat
Vibe-coding platforms.
DOM fingerprinting + platform API connectors discover and govern apps built by non-developers. 7-signal risk scoring. OPA policy enforcement. Full story →
| Platform | Discovery method |
|---|---|
| Replit | DOM + GraphQL API |
| Lovable | DOM + deploy detection |
| Bolt | DOM + deploy detection |
| v0 / Vercel | DOM + REST API |
| Cursor | IDE domain matching |
| Windsurf | IDE domain matching |
| Copilot Workspace | IDE domain matching |
AI surface discovery.
Four-state model: Licensed → Enabled → Active → Governed. Cross-references IdP apps, SaaS admin APIs, and browser fingerprints.
| Okta | Read-only app list |
| Azure AD / Entra ID | Read-only app list |
| Google Workspace | Read-only app list |
| Microsoft 365 | Copilot SKU + usage |
| GitHub | Copilot billing + seats |
| Slack | AI feature flags |
| Google Workspace | Gemini per-OU |
| Salesforce | Einstein enablement |
| Atlassian | AI feature status |
| ServiceNow | Now Assist |
| Zendesk | AI feature status |
30 AI-capable SaaS platforms in the fingerprint DB. Browser extension adds 10 passive DOM fingerprint rules for admin page detection. Credentials encrypted via AES-256-GCM.
SIEM and security operations.
Structured, identity-attributed audit events in your existing SIEM. Better data in the glass you already have.
| Destination | Transport |
|---|---|
| Splunk | HEC (HTTP Event Collector) |
| Microsoft Sentinel | Data Collector API |
| Google Chronicle | Ingestion API |
| IBM QRadar | LEEF 2.0 |
Plus webhook delivery to Slack, PagerDuty, or any custom endpoint. Configurable severity filtering. Signed payloads with retry and dead-letter queue.
Data protection.
Four-stage pipeline: classification, redaction with pseudonymization, BYOK envelope encryption (AES-256-GCM + AWS KMS), and retention purge with decryption audit trail.
AWS keys/GitHub tokens/Private keys/SSNs/Credit cards/OAuth tokens/API keys/Email addresses/Phone numbers/IP addresses
26 patterns total. Luhn validation, SSN structure checks, cross-session fragment reassembly detection. Critical-severity patterns auto-block before OPA evaluation. DB-managed with hot-reload. Add custom patterns without restart.
Frameworks and deployment models.
Six compliance frameworks mapped. Four ways to run the stack. All models share a single data plane image with identical governance capabilities regardless of deployment.
| Framework | Controls |
|---|---|
| SOC 2 | CC6.1 · CC6.7 · CC7.2 · CC7.3 · CC7.4 |
| ISO 27001 | A.12.4.1 · A.12.4.2 · A.9.4.1 |
| EU AI Act | Art. 9 · Art. 13 · Art. 14 |
| NIST AI RMF | GOVERN · MAP · MEASURE · MANAGE |
| GDPR | Art. 32 · Technical measures |
| HIPAA | §164.312 · Technical safeguards |
OWASP ASI mapping + PDF export. Full framework-to-control mapping in dashboard.
Behavry manages everything. Fastest start.
Control plane SaaS. Data plane in your VPC.
Full stack in your cloud. Helm + Terraform.
Air-gapped. No external dependencies.
Zero agent code changes. Deploys in a day.
BOOK A BRIEFING →