For teams running AI agents

Protect everything your AI agents touch.

AgentSaw prevents confidential data leaking through your AI agents.

It runs where your agents run, remembers every private thing they read, recognizes it later even after it has been copied somewhere else, and stops it before it reaches a place it should not be. All on the machine itself, so nothing private has to leave it.

20 minutes with the founders. We install it on one machine the same week. Nothing to buy.
Runs with
Claude Code Cursor Cline Codex more through plug-ins
Coller Startup CompetitionSemi-finalist · 2026
One example, out of many

A normal week. Your keys go public.

Nobody did anything wrong here, which is the whole problem. Every step is something a person asked for and an agent is allowed to do.

MONDAY

The agent reads the keys

Someone asks their agent to fix a payment job that keeps failing. To do it, the agent opens the settings file that holds the live keys to the company's cloud account.

While it works, it saves itself a short note with the failing command in it, in a file called notes.md. The keys are in that note.

THURSDAY

The agent publishes them

Same person, same agent, new session. This time they ask it to write a setup guide for the team.

The agent finds Monday's notes.md and uses it as the example. The guide goes up on the company wiki, where every employee and every contractor with an account can read it.

Nothing complained

The agent is trusted software, the instructions were reasonable, no file moved anywhere and no permission was exceeded. Every security tool the company pays for looked at Thursday on its own and found nothing worth reporting.

What AgentSaw did

It noticed the keys on Monday, when they were read. On Thursday it recognized the same keys inside the draft, even though they arrived through a different file, and raised one alert with both days on it. Turn blocking on and it holds the write instead.

Sixty seconds, no sound needed. A composite of real, observed agent behaviour; the credentials are made up. Three days is what fits on a page: it happens within the hour too, and one agent, twice, is enough.

Why nothing you already own catches it

Every tool you have looked at Thursday and shrugged.

Not because they are bad tools. Because each of them watches one moment, and this only exists as the line between two of them.

What you have
Why it walks past this
Verdict
Endpoint protection
antivirus, EDR
Everything involved is trusted software doing ordinary work with files. No malware, nothing broken into, and its whole model says the agent is one of the good ones.
CLEAR
AI guardrails
the layer that inspects what people ask AI
Nobody asked for anything out of line. The keys moved through what the agent did, not what anyone typed, so they never pass in front of this.
CLEAR
Data-loss tools
DLP and the like
Built to follow files between company apps. Here no file moved: the keys were retyped into a new document, by an agent allowed to write it.
CLEAR
Agent permissions
the AI-security tool you may have just bought
This is a trusted agent doing a permitted thing while carrying something it should not be carrying. These check who is acting, not what they are holding.
CLEAR
AgentSaw
what we do
Follows the keys themselves, from the file they were read in to wherever a later session takes them, even after they have been copied into something else.
CAUGHT
Every tool you own looks at one moment and finds it fine. The problem only appears when you put Monday and Thursday next to each other, and that is the one thing none of them does.

Standardising on one agent does not close it either: your team runs that agent all day, and this happens between one run and the next.

Before you ask

Questions, and what stays on your machine.

Runs on the machine, not in our cloud Nothing private leaves your network Watches by default, steps in when you ask
Which agents does it work with today?
Claude Code, Cursor, Cline and Codex, with more through plug-ins. It connects the way each agent already allows, so there is nothing to patch and nothing to wrap. If you run something that is not on the list, tell us and we will say honestly how long it would take.
What does it see, and what leaves the machine?
The actions your agents take: which files they open, which commands they run, what they send out. It does not copy your repository or look at anything an agent did not touch. The private parts stay on the machine, in storage only that machine can read. Your team's screen runs in your own network and gets the movements, the times and the destinations, with the values stripped out.
Is this watching my people?
No. It watches the agents, not the people. Whoever runs the agent sees their own line of it too, and most people want to: nobody enjoys finding out that their assistant parked a live key in a notes file.
What does it cost, and what do you want from us?
Right now, nothing. We work closely with a small number of teams while the product is young. You get the tool and a direct line to us. We get your honest feedback, including the parts we will not enjoy hearing.
Where this is going

Soon your agents will outnumber your people.

Most of them will not have anyone watching. They will run on a schedule, inside a product, answering to another agent, touching real customer data and real credentials at three in the morning. Every security tool your company owns was built on one assumption: that a person is behind each action, and can be asked what they were doing. That assumption is quietly expiring.

So we started where the agents already are, on the machines your team works on every day, and we are building toward one thing: knowing what every agent in your company is holding, wherever it runs, and being able to stop the moment it carries something out.

Today that means one machine at a time, alongside the agents listed at the top of this page, mostly telling you what happened. That is what our first partners run right now, and we install it with them. Three directions from there.

One machine, then the whole team

A lead sees everything the team's agents are doing with private data in one place, instead of one machine at a time.

Telling you after, then stopping it live

With rules each team writes for itself, so the things you never want leaving simply do not leave.

Watched agents, then unwatched ones

The ones on a schedule, inside a product, or working for another agent. Nobody is sitting in front of those.

One day a company will run thousands of agents, at a speed no one can follow by reading, and still be able to say with evidence that nothing private walked out through any of them. That is the whole point of this.
We are taking on a few teams now

Your team runs agents? Give us 20 minutes.

We will install it on one machine and show you what has been moving between your own sessions. If the answer is nothing, that is a good afternoon for both of us. Nobody pays anybody, and we ask for one thing back: tell us honestly what you think.

Tamir Magnezi
Co-founder and CEO · LinkedIn
Reli Magnezi
Co-founder and CPO · LinkedIn