DLP for Claude Code, Cursor & Copilot · runs in your cloud

Your developers put
your data into AI tools
every day.
You can't see what leaves.

Tether shows you what your team sends to AI tools, blocks what's dangerous, and keeps proof you can hand to an auditor — all inside your own cloud.

Code, secrets, and customer data go into Claude Code, Cursor, Copilot, and the rest all day long. The security tools you already own can't read any of it. Tether runs on the developer's machine, shows you that traffic, stops the risky moments, and keeps a signed record — without getting in your developers' way.

How much you see depends on the tool. For the ones that connect through Tether — Claude Code, Codex CLI, Aider, Zed, Continue — you see the full prompt. For the ones that don't, like Copilot chat or Cursor's default mode, you still see who used them and which AI vendor they hit.

Runs in your cloud.  No copy of your data on our side to leak. No certificate on laptops.  Nothing decrypts your traffic.

Free for up to 25 developers, two weeks, in your own cloud. If it's not for you, delete it — there's nothing on our side to clean up.

A risky moment, governed
IN YOUR CLOUD
BEFORE
A developer pastes a customer record into an AI prompt.
   It leaves the laptop. You never see it.
AFTER, WITH TETHER
Security sees the attempt in the SIEM you already run.
Policy catches the risky moment — no developer ticket.
An operator decides in seconds. The dev keeps working.
A signed receipt your auditor re-verifies offline.
   And it never left your cloud.

One hop — and it never
leaves your cloud.

Your developer's AI tool reaches the model through Tether, running in your own cloud account. Tether sees the request, applies your policy, and records it. Nothing routes through us.

Developer machine Claude Code · Cursor · Copilot Tether in your cloud · no root cert AI model API api.anthropic.com · openai.com Your cloud · Overwatch console Signed policy, ~10s to the fleet · streams to your SIEM · reads your IdP · nothing transits Tether

No Tether-hosted transit. Policy verified offline. No root certificate on the laptop.

You are paying for security tools
that cannot see AI traffic.

Data loss prevention is blind to developer AI tools. Here is why your current stack misses the prompt.

EDR

EDR does not see prompts.

Your EDR sees the process, the network connection, the binary. It does not read the JSON body inside the TLS tunnel a coding agent opens to its vendor.

CASB

CASB does not classify them.

CASBs are tuned for SaaS-app posture and shadow-IT discovery. A Claude Code or Cursor call to api.anthropic.com is just another approved SaaS host.

DLP

DLP does not catch them in flight.

Network DLP runs on egress patterns at the perimeter or on file content. A developer paraphrases a customer record into a prompt and the patterns never fire.

AI Vendor Logs

Vendor logs are not discoverable.

The only record of what your developers prompted is at the AI vendor. It is not in your SIEM, not on your audit timeline, and not available during incident response.

You do not need to replace your stack. Tether covers the exact blindspot your other tools can't reach, and feeds the evidence directly into the SIEM you already operate.

Where Tether is
  • Sees prompts and completions before they leave, on the tools that route through the proxy
  • Attributes activity to a person, an agent, and a host
  • Blocks the patterns you name; pauses the ambiguous moment for an operator
  • Leaves signed evidence your auditor re-verifies offline
Where Tether isn't
  • EDR still does endpoint malware and behavioral threat detection
  • CASB still does SaaS shadow-IT discovery and posture
  • IdP/SSO still owns identity; Tether reads from it, doesn't replace it
  • DLP still does org-wide file-level content classification

That's the short version. The full 13-row map — including the rows where Tether is only partial — is on the Pilot page, and the category-by-category fit — network/SASE, supply-chain gateways, EDR, CASB, DLP, IdP — is on How it works.

The day this matters is the day
you can't answer the question.

Three moments when "we don't have a record" becomes an immediate crisis.

Audit

The auditor asks what left.

SOC 2, FedRAMP, an AI-governance review — the control owner asks for evidence of what your developers sent to AI tools, and which policy decided it. Today the only record is at the vendor, and it isn't on your timeline.

Breach

Incident response has no trail.

2 a.m., a credential is being used from an IP you don't recognize. Your IR lead asks the one question that scopes the blast radius: did it go out through an AI tool, and what else went with it? The only record that could answer is at the AI vendor — off your timeline, behind a support ticket, useless to the people on the bridge right now.

Deadline

The mandate lands with a date on it.

A customer contract, a regulator, or your own board sets a date to govern AI usage. A control you can stand up, prove, and tear down in two weeks beats a year-long platform program — and the AI tools are already in production.

The fix

Close the gap before you're asked.

Tether turns this blind spot into a verifiable, tamper-evident audit trail running entirely in your environment. You hold the keys, and your auditor checks the math. Try it on your own data in two weeks →

Three things your board
is about to ask about.

You don't need a statistic to feel this one. It's already true in your own org.

Adoption

Your developers already use AI tools every day.

Claude Code, Cursor, and Copilot got into your engineering org faster than security got any view of what leaves with them. That gap is widening, not closing.

Blind spot

The prompt body isn't in your SIEM.

Today the only record of what a developer sent to an AI tool sits with the AI vendor — not on your timeline, not in the tools your SOC actually watches.

Pressure

Auditors have started asking.

SOC 2, HIPAA, and AI-governance reviews increasingly ask what controls AI-tool egress. "We have no record" is a hard answer to give with a straight face.

The move

Close it before you're asked.

Two weeks, your own cloud, your real traffic. Start a free pilot →

Proof, not promises

Proof your auditor can check
without taking our word for it.

Most security tools ask your auditor to trust a vendor dashboard. Tether does the opposite: every decision it makes is saved as a signed record your auditor can verify on their own laptop — no access to us, no reason to trust us. That's the answer to "will this hold up in an audit?" — and it's the same answer whether it's a customer, a regulator, or your own incident team asking.

Signed at the sourceEvery decision carries the Ed25519-signed policy version that made it.
Verified offlineYour auditor pulls the bundle and confirms it cryptographically, on their own machine.
In your tenantThe record lives in your own cloud — there's no Tether-side copy to request or trust.
Keeping that record for the long term means forwarding it to your SIEM — which is why the SIEM connectors ship in the same release. Technical brief →

The controls you need, built to be proven.

We don't sell black-box AI. We sell deterministic security controls that you can verify in your own environment on day one.

01 · VISIBILITY

Read the prompt before it leaves

The developer's prompt, the AI's response, and the exact identity of the sender are captured at the endpoint and shipped directly to your SIEM. You see what the TLS tunnel hides from the network.

Proof: Watch the exact prompt land in your SIEM in real-time.

02 · ENFORCEMENT

Block the dangerous payloads

Normal traffic flows uninterrupted. When a policy triggers, the request is held at the endpoint. The developer gets immediate feedback, or an operator clears it in seconds.

Proof: Change a policy and see it enforced on a machine in seconds.

03 · COMPLIANCE

Cryptographic evidence for auditors

Every enforcement decision is tied to the exact policy version active at that millisecond, signed with an Ed25519 key. You don't ask us for a report—you hand the auditor the signed bundle.

Proof: Your auditor verifies the cryptographic signature offline.

04 · ARCHITECTURE

No TLS interception required

We do not install a MITM root certificate on the developer's laptop. Tether binds to the local loopback and only proxies the AI developer tools you choose. The rest of their traffic is untouched.

Proof: Inspect the developer machine. There is no Tether CA installed.

05 · INTEGRATION

Built for the stack you own

Tether pulls identity from your IdP, reads device posture from your MDM, and pushes events to your SIEM. It is a targeted, surgical addition to your existing security architecture.

Proof: Connect Tether to SSO and SIEM during the first hour of a pilot.

FOR THE ENGINEER

Want to see under the hood?

Every claim above points to the exact code behind it — the proxy, the signing chain, the SIEM connectors, the audit records. The technical brief lays it all out, with sources, for whoever has to vet it.

Read the technical brief →

We're building the system of record for what leaves your company through AI tools. Why we think this is inevitable →  ·  Meet the team →

Try it on your own data.

Free for up to 25 developers, two weeks, in your own cloud. If it's not for you, tear it down — there's nothing on our side to delete.