Security for AI agents, MCP servers and models

Every AI action cleared before it runs.

NoFly sits between your AI agents and the systems they touch. Routine work is cleared, risky moves wait for a person, and the ones that end badly never run.

npm i -g @shomra/agent
Free and open source. Lists the AI on this machine, no account needed.
NoFly towerIllustrative
triage-botgithub.​get_file(​path: ".env")
StopNot cleared. Turn back.

Secrets never leave through tools. The file holds live keys.

Works inside
  • Claude Code
  • Cursor
  • Copilot CLI
  • Codex CLI
  • Gemini CLI
  • Windsurf
  • Cline
  • MCP servers
  • Copilot Studio
  • Agentforce
  • Bedrock Agents
  • Azure AI Foundry
  • n8n

Two ways to start

Talk to us

See it on your agents.

Book a call and we will map your agents, MCP servers and keys with you, then show what the platform adds on top of the free CLI.

  • Central policy across laptops, gateways and hosted agents
  • Approvals in Slack, Teams, the console or on a phone
  • Attack simulation, reporting and single sign-on
  • Self-hosted inside your network, if you need it

Machines are never metered.

Start free

Start on one laptop, today.

The CLI is open source under Apache-2.0 and runs entirely on your machine, with no account and no telemetry.

Any laptop · no account
  • npx @shomra/agent scan

    Lists every AI tool, MCP server and AI key on this machine.

  • npx @shomra/agent check

    Checks a repository’s AI config, skills and MCP servers before they merge.

  • npx @shomra/agent protect

    Puts the gate inside each coding agent on this machine.

Read the source on GitHub
The platform

One platform for every agent your company runs

AI discovery and scanning. Every AI tool, agent, MCP server and model in the company, with its owner and reach. Explore

Only in NoFly

Four things no other AI security product does.

Everyone scans and filters. These come from owning the gate, the attack engine and the record of every run at the same time, and from comparing behaviour across many companies.

1InterrogateBehaviour interrogation

Catch tools that change their story when an agent asks

We question live MCP servers and agent tools under controlled conditions to catch ones that change their story.

2ExplainWhy it acted

Know exactly why your agent did what it did

For every risky action, the exact input that caused it: the person’s request, or a line hidden in something the agent read.

3VerifyControl Ledger

Find out which controls actually work, even ones you bought elsewhere

Every AI security control you run, including other vendors’, graded by what it did when attacked.

4PreviewConsequence preview · Early access

See what an action will change, before it runs

Before an agent deletes, sends, shares or pays, NoFly tries it on a copy and shows what would change.

One rulebook

Write the rule once. It holds everywhere your AI acts.

The same rule is enforced by the hook on a laptop, the MCP gateway, the model proxy, a Copilot Studio agent, the browser and the pull request check, with one record of every decision.

A paper plane folded from a chart banks away from a red tracing-paper dome over the zone marked P-1 Secrets
Before you call us

Check our work yourself.

Security buyers should not have to take a vendor’s word for anything. These four take minutes, and none of them needs an account.

Before you call usPre-call checklist · no account needed
  1. 01The codeshomra-org/agent ↗

    Read the code on your laptops. The CLI and the gate inside each coding agent are open source under Apache-2.0, with zero dependencies.

    npm view @shomra/agent
  2. 02Attack libraryAttack benchmark ↗

    See what we attack with. The attack families and scenarios behind every simulation are published, mapped to MITRE ATLAS and OWASP.

  3. 03ScoresRead the spec →

    Recompute any score. Attack results use an open reporting spec: skipped or failed attacks are listed, never counted as passes.

    npx agentprobe-verify report.json
  4. 04QuestionnaireTrust center ↗

    Send us your questionnaire. The trust center has the security questionnaire, sub-processors and our SOC 2 status, answered before you ask.

Questions

What security teams ask first.

NoFly tower · 118.700Transcript
Security team ›What is free, and what do we pay for?
NoFly tower
The CLI is free and open source under Apache-2.0. It scans a machine for AI tools, checks repositories, and puts the gate inside coding agents, with no account. The platform, with central policy, approvals, attack simulation, reporting and single sign-on, is paid. Machines are never metered. Talk to us for a price.
Security team ›Do you see our code, prompts or data?
NoFly tower
The free CLI runs entirely on your machine with no account and no telemetry. With the platform, the gate sends the calls your policy cares about for a decision, and you choose what is enrolled. The platform can also run self-hosted inside your network. Details are in the trust center.
Security team ›What does it actually stop?
NoFly tower
Critical moves are refused on the machine even offline, such as a script piped from the internet into a shell. Others, like a request to cloud metadata, a destructive database write, a secret heading somewhere new or an instruction hidden in a tool result, are flagged, held for a person or blocked according to your policy.
Security team ›Which AI tools does it work with?
NoFly tower
Claude Code, Cursor, Windsurf, Gemini CLI, Codex CLI, GitHub Copilot CLI and Cline through hooks, Aider through the local proxy, any MCP server through the gateway, model traffic through the proxy or gateway plugins, and vendor-hosted agents such as Copilot Studio, Agentforce, Bedrock Agents and Azure AI Foundry. The full list is on the integrations page.
Security team ›Do we have to replace the tools we already own?
NoFly tower
No. NoFly reads from the EDR, MDM, identity provider and network tools you already run to find AI, and sends what it finds to Slack, Teams, Jira, ServiceNow and your SIEM.
Security team ›Is consequence preview available today?
NoFly tower
Consequence preview is in early access with design partners. Book a call to join.

Find out what your AI is allowed to do today.

Book a call and we will map your agents, MCP servers and keys with you, or start on one laptop with the free scan.

Book a demo
npm i -g @shomra/agent