AI for Agents

Local-First AI Security.

On-device runtime control for every AI workspace your employees use.
Desktop AI apps · IDE assistants · MCP tool calls · Direct LLM API calls · File activity · Data movement
The coverage

Every AI workspace beyond the browser.

Your team uses AI in places the browser can't see: standalone desktop apps, coding agents inside the IDE, and custom agent frameworks that call tools and LLM APIs straight from the OS. This tier covers those workspaces with the same on-device protection model as AI in Browser, run by a single endpoint daemon.

Four workspaces this tier covers

01
Desktop AI agents
02
IDE assistants
03
MCP tool calls
04
Clipboard movement

Desktop AI agents

Claude Desktop, ChatGPT Desktop, native AI applications. The standalone apps employees install outside the browser.

IDE assistants

Cursor, Claude Code, GitHub Copilot in the IDE, Continue. Coding assistants that work inside the developer's editor, not through a browser tab.

MCP tool calls

Bidirectional traffic between AI agents and the tools they connect to via Model Context Protocol. The traffic the agent generates on the user's behalf, not the user's typed prompts.

Clipboard movement

Data copied from one application and pasted into an AI tool, or copied from an AI output and pasted somewhere it shouldn't go. The pathway many sensitive data leaks actually use.

What you get from this tier specifically:

01

Enforcement on agent tool calls, not just visibility

When an agent reads a file, calls an API, commits code, or runs a shell command, the action is classified and policy-evaluated before it executes, and blocked or gated when it violates policy.
02

Coverage of direct LLM API traffic

Agents that skip MCP and call provider APIs directly are intercepted at the SDK and framework layer. The prompt, system message, and attached documents are inspected and tokenized before the request leaves the machine.
03

Agent goal drift detection across both surfaces

Every session gets a goal anchor on its first call, and each subsequent tool call or API request is scored against it. When an agent starts doing something it wasn't asked to do, drift crosses threshold and the policy engine intervenes.
04

Runtime control across native AI applications

Desktop AI apps and IDE assistants get the same enforcement as web AI tools: semantic content classification, tokenization, and allow / gate / block at the moment of use.
05

Visibility into data movement off the prompt path

Content is classified on-device, agent skill and prompt files are scanned before they load, and clipboard movement between AI tools and other applications is detected and logged during active agent sessions.
Architecture

One on-device service. Every workspace. No cloud round-trip.

A single endpoint agent coordinates protection. Every adapter talks to it and receives a decision back. The agent owns the on-device small models, the session store, and the policy engine. It's the same classification model as AI in Browser. Classification happens entirely on the machine; the only thing that leaves is hashed metadata.
AI Workspaces
01

Desktop AI

Claude, ChatGPT
02

IDE assistants

Cursor, Claude Code, and more
03

MCP tool calls

Agent traffic
04

Direct LLM API calls

SDK + framework traffic
05

File activity

skill files
06

Data movement

copy/paste between apps

MagicMirror On-Device Service

One service, every workspace, local small models, on-device.
Four Products
See it

Risk Monitoring

Control it

Policy Enforcement

Protect it

Data Protection (Marv)

Measure it

Insights

Products

The MagicMirror AI Security Platform.

Four products, one platform. Coverage across every web AI tool and agent your employees use.
(Each product's "in agents" line updated to include API calls and file activity.)

AI Risk Monitoring

In the browser
Every web AI tool, account, and prompt across Chrome, Edge, Brave, and Arc.
In agents
Desktop AI app usage, IDE assistant activity, MCP tool calls, direct LLM API calls, file-system activity, and clipboard movement.

AI Risk Monitoring

Together

full visibility across every AI workspace your team uses.

AI Policy Enforcement

In the browser
Allow, guide, redirect, or block actions on any web AI tool, enforced at the moment of use.
In agents
The same enforcement on MCP tool calls and direct API calls inside native apps and IDE assistants, with agent goal drift detection across both surfaces.

AI Policy Enforcement

Together

policy you can't bypass by switching workspaces.

AI Data Protection (Marv)

In the browser
Last-mile tokenization for PII, PCI, PHI, and IP before data leaves the browser.
In agents
The same tokenization for desktop AI app prompts, MCP tool calls, and direct LLM API requests. The data paths that never touch a browser tab.

AI Data Protection (Marv)

Together

sensitive data is protected at the moment of use, in every workspace.

AI Insights

In the browser
Productivity, proficiency, and adoption metrics for web AI tools.
In agents
The same metrics extended to desktop AI agents, IDE assistants, MCP tool calls, and direct API traffic, with per-user, per-agent, per-model token-spend attribution.

AI Insights

Together

real ROI data, not just usage data from one surface.
Two tiers. One platform.

Browser and Agents cover different layers.

Most organizations need both. The extension handles web AI tools. The on-device service handles the rest. One policy model.
Tier 1

MagicMirror AI in Browser

Browser-Native AI Security.

On-device protection for every web AI tool your employees use. Browser extension across Chrome, Edge, Brave, and Arc.
Tier 2

MagicMirror AI for Agents

Local-First AI Security.

On-device runtime control across desktop AI agents, IDE assistants, MCP tool calls, and clipboard movement.
You are here
Common questions

AI for Agents FAQ.

What's the on-device service's footprint?

The daemon runs as a userspace Rust process. No kernel driver, no reboot, no separate agent per tool. Specific surfaces (clipboard monitoring, certain MCP scenarios) may require elevated privileges, documented in the architecture white paper. The footprint is intentionally smaller than EDR, in both memory and CPU.

Do you install a certificate?

For the API proxy, the recommended default is TLS interception via a local CA, which gives full coverage of direct LLM API traffic regardless of how each client is configured, including apps that hardcode the provider URL. A cert-free mode is also supported, where coverage is limited to traffic routable through patched SDK base-URL configuration; customers who decline the cert accept the narrower visibility. The browser extension needs no certificate on its surface, since it reads content after TLS terminates inside the browser.

How does this coexist with our EDR?

EDR sees process-level activity, malware behavior, and post-breach signals. The MagicMirror daemon sees AI-specific activity at the workspaces where AI happens: prompts, tool calls, API requests, file writes, clipboard moves, agent actions. Different layer, different problem. We coexist with major EDR vendors and validate it during the pilot.

What happens if the on-device service stops running?

The synchronous enforcement hooks wired into coding agents fail open if the daemon is unreachable, so developer workflows aren't broken by an outage. For surfaces where you'd rather classify and log without blocking, observe-only mode is available, delegating enforcement to the hook layer in the agent's execution path.

What can't this tier do today?

We're precise about boundaries. Cloud-hosted agents that run off the employee's machine are out of scope by design (we're endpoint-first). Browser, MCP, and API sessions are scored independently today; real-time cross-surface correlation is on the roadmap. The Gate decision currently falls back to Block; a real-time consent dialog is future scope. Clipboard movement is detected, not prevented.

Local-First AI Security, on your environment.

Get started

Schedule a demo with our security experts. We'll walk through the local AI workspaces your team uses and how MagicMirror would protect them.