Cross-session security for AI coding agents

One session reads a secret.
Another leaks it.

Your developers run the same AI coding agent dozens of times a day. A secret one session reads gets parked in a file, and a later session picks it up and ships it out. AgentSaw follows the value across every session and agent on the dev's machine, and catches the handoff no single tool can see.

Local-first · raw values never leave the dev's machine
Become a design partner Let's talk
20 minutes with the founders · local install · no procurement · free for design partners
Cursor reads a secret in one session, and a later session of the same tool publishes it to a wiki. Every tool would call it clean. AgentSaw catches the handoff. full walkthrough →
Works with
Claude Code Cursor Cline Codex + more via plugin
Why nothing on your stack catches this

It's the gap between the tools.

Endpoint, prompt firewalls, DLP. Even the agent-security tool you may have just bought. None of them is built to follow a value across your coding agents. Here's why each walks right past it.

Layer / tool
Why it slips past
Verdict
Endpoint
EDR · antivirus
Every actor is a signed, trusted dev tool doing normal file and network work. No malware, no exploit. Its trust model says "Cursor = good."
Clear
Prompt
AI gateway · prompt firewall
Nothing to flag. Every instruction is in policy. The value moves through the agents' own actions, not their prompts, so it never reaches what this watches.
Clear
Data & AI-DLP
DLP, DSPM platforms
Built to trace files across SaaS and watch AI in the browser and chat. Here nothing moves as a tracked file. The value travels as plain text through the agents' own work, outside what these watch.
Clear
Agent identity
agent-security · identity tools
Permissions were never exceeded. Every action was allowed. The leak is a trusted agent doing a permitted thing with a value it shouldn't be carrying. These watch who the agent is, not what value it moves.
Clear
Cross-session lineage
agentsaw
Follows the value itself across every session and agent. Recognizes it the moment any later session moves it somewhere it shouldn't go.
Caught
Each tool watches one session, or one agent, and calls it clean. The leak only appears when you connect all of them, which is the one thing none of them does. And no, standardizing on one agent doesn't help: your devs run that one tool all day, and the leak lives between sessions.
How it works

Follow the value, not the file.

AgentSaw tags a sensitive value the moment a session reads it, then follows that exact value across every session, agent and tool, even after it's copied, logged or moved between files, and acts before it lands somewhere it shouldn't.

01 · TAG

Tag at origin

The moment an agent reads a secret or sensitive value, AgentSaw marks it at the source: .env, a vault, a customer record.

02 · FOLLOW

Follow the value

It traces that exact value as agents copy, log and transform it, across every session, in Claude Code, Cursor, Cline and Codex.

03 · RE-IDENTIFY

Re-identify anywhere

When a later session moves the same value toward a risky destination, AgentSaw recognizes it, no matter which agent is holding it now.

04 · ACT

Alert or block

One clear alert on the cross-session timeline. Turn on blocking and it stops the action before the value reaches a wiki, a PR or a public doc.

AgentSaw connects through each agent's own hook and extension APIs and reads the tool calls they make (file reads, shell commands, network requests) right on the developer's machine. It watches what your agents do, not just what's in their prompts.

7
Cross-session handoffs
caught · last 7 days
The metric you'll watchExample

Every catch is one leak that didn't ship: a value read in one session, recognized when a later session moved it toward an internal wiki or a customer email.

Example data — your number depends on how your team runs agents. A healthy week trends toward zero, and each catch comes with the full cross-session story behind it.

Your code and secrets stay yours

Everything sensitive stays on the machine.

AgentSaw is local-first by design: the watching, the tagging and the decisions all happen on the developer's machine. The dashboard runs in your network and works from redacted events — never raw values.

The dev's machine

Where everything sensitive lives

AgentSaw reads the agents' tool calls through their own hook APIs, tags sensitive values and follows them — all locally, in an encrypted local store. Raw secrets never leave the laptop.

Secrets stay here
Your dashboard

One cross-session timeline

Runs in your network. It receives redacted events — the movement, the sessions, the destinations — and builds the timeline and alerts your team works from.

No raw values
Local-first Nothing sensitive leaves your network Observe-only by default · blocking opt-in Up and running in an afternoon
FAQ

Questions we get from every team.

What exactly does AgentSaw see?
It connects through each agent's own hook and extension APIs — Claude Code, Cursor, Cline and Codex — and reads the tool calls they make: file reads, shell commands, network requests. It watches what agents do on the machine. It doesn't clone your repo, index your codebase or read anything an agent didn't touch.
What is "cross-session lineage"?
Following a specific sensitive value across sessions and agents. The moment any session reads a secret, AgentSaw tags it; when a later session — same tool or a different one — moves that same value toward a risky destination, AgentSaw recognizes it and connects both into one timeline. That connection is the thing no single-vendor tool has.
Where does the data live? What leaves the dev's machine?
Everything sensitive stays local, in an encrypted store on the machine. Your dashboard — running in your own network — receives redacted events: the movement, not the values. Raw secrets never leave the laptop.
Is this monitoring my developers?
No — it watches the agents, not the people. AgentSaw records what AI coding agents do with sensitive values. Developers see their own timeline too; most want to know when an agent quietly parked a live key in a notes file.
Does it slow down or block my agents?
Observe-only by default: hooks are read-only and don't get in your agents' way. Blocking is opt-in, per rule — when you turn it on, AgentSaw stops the action before the value lands in a setup guide, your API docs or a customer email.
What does the design-partner program involve?
Free, hands-on, small group. A 20-minute call, a local install the same week, and you're watching your own sessions — with a direct line to the founders. No procurement, no credit card; we ask only for honest feedback.
Design-partner program · now onboarding

Your team lives in AI coding agents?
Let's spend 20 minutes finding what's moving between your sessions.

We're working hands-on with a small group of AI-native teams who run AI coding agents every day. Local-first: almost nothing to approve, so you can have it watching in an afternoon. You get the cross-session timeline and a direct line to the founders; we get your feedback.

Tamir Magnezi
Co-founder & CEO · LinkedIn
Reli Magnezi
Co-founder & CPO · LinkedIn
20 minutes · local install · no procurement · free for design partners
Coller Startup Competition Selected as Semi-finalist · Coller Startup Competition 2026