Find every AI tool, agent and model your company runs
NoFly builds one inventory from laptops, browsers, code, cloud accounts and the AI vendors themselves. Each entry comes with an owner, what it can reach, and anything wrong with it.
- Coding assistants, MCP servers, agents, models and AI keys in one list
- Agent instructions, MCP servers and model files scanned before they run
- Found through tools you already own: EDR, MDM, identity and network logs
Sweeping laptops, browsers, code, cloud accounts and AI vendors.
What AI is running here, what can it reach, and who owns it?

AI arrives by download
Coding assistants, MCP servers and models get installed in minutes, with no purchase order and no review.
The keys sit in plain files
The credentials that make agents useful live in config files and .env files on laptops, one command away from leaving.
Agents get built outside IT
Business teams build agents in Copilot Studio, Agentforce and n8n that nobody in security has seen.
Discover in practice.
Each part below is shown the way it looks and works in the product.
One list for everything AI in the company
Every agent, MCP server, model, skill, hook and AI key lands in one inventory, grouped by where it was found and ranked by what is wrong with it.
- Sources side by side: workspace scans, endpoints, MCP governance, connected platforms
- Findings by severity over time
- Export as a CycloneDX AI bill of materials
The AI people use without asking
NoFly spots AI use from network egress, enrolled machines, OAuth consents, the browser and the vendors’ own admin APIs, then names the person behind each one.
- New tools marked new until someone reviews them
- Personal and company accounts told apart
- Whether a vendor trains on what you send, shown per vendor
Check any agent artifact before it runs
Paste or upload a skill, hook, MCP config, agent card, rules file or memory file and see what it would make an agent do, without running it.
- More than twenty kinds of agent artifact understood natively
- Nothing executed, secrets redacted from the report
- The same checks run in pull requests and on laptops
What most tools do, and what NoFly does.
Everything in Discover.
Every AI tool, agent, MCP server and model in the company, with its owner and reach.
D1Shadow AI from five directions
Network egress, enrolled machines, OAuth consent grants, the browser and the vendors’ own admin APIs, named per person.
D2Laptops you never installed on
Searches CrowdStrike, Defender and SentinelOne telemetry for AI tools, with fleet size from Intune, Jamf or Kandji.
D3Agents built in vendor consoles
Copilot Studio, Agentforce, Glean, n8n, Make, ServiceNow, Azure AI Foundry and Bedrock Agents, imported as governed agents.
D4Cloud and model accounts
AWS, Azure, Google Cloud, OpenAI, Anthropic, Hugging Face, Databricks and more, including what each key can reach.
D5Agent instructions read like code
Rules files, skills, slash commands, subagents, hooks, MCP configs and agent memory, scanned without running anything.
D6MCP servers vetted and watched
Scanned in a sandbox with no network, approved or denied, then watched for drift and for changing hands.
D7Model files and AI supply chain
Pickle, safetensors, GGUF, ONNX and Keras files, model licences, packages and images, matched against OSV and CISA KEV.
D8RAG sources and oversharing
Which documents feed which index, and which ones nobody should be able to retrieve.
D9Threat intel, checked backwards
When a new advisory or malicious package lands, NoFly checks what your agents already installed and already did.
Questions about Discover.
Security team ›Do we need to install anything to start?
Security team ›Does scanning run the tools it finds?
Security team ›What counts as an AI asset?
Find out what your AI is allowed to do today.
Book a call and we will map your agents, MCP servers and keys with you, or start on one laptop with the free scan.