Shadow AI
Know what's actually running.
Every AI client, MCP server, skill, and credential on every laptop, on day one, attributed to a person. Coding agents and chat apps alike, and the combinations of tool calls and MCPs inside one session, where the real risk is. Before you write a policy or stand up a proxy.
How the Lander finds itDevices
42
AI clients
6
MCP servers
31
Unsanctioned
9
Control
Say yes to more tools. Deny the one call that matters.
Approve an MCP server once and it's installed and scoped everywhere. When an agent reaches for github.delete_repo, that call is denied, the tool keeps working, and you know who asked.
How policy worksgithub.delete_repo
repo: payments
- Rule
- allowed_tools
- Person
- j.doe@acme
- Device
- MBP-2291 verified
- Agent
- Claude Code
- Session
- 8f3a…
- Tokens
- 1,204 / 88
Recent
Distribute
What your best builders figured out becomes everyone's default.
A catalog of approved MCP servers, skills, and configs, installed into Claude Code, Cursor, Codex, or Claude Desktop in one click. Scoped, OAuth handled, kept current on every device.
The catalogMCP Servers
org-approved · 42 devices
Servers your organization has configured. Install the ones you want on your client.
GitHub
http
Google Drive
http
Notion
http
Slack
http
Snowflake
http
Linear
http
Confluence
http
Postgres (read replica)
stdio
Cost
Pay for work that ships.
Every token priced and attributed to a person, a session, and the PR it produced. Cost per merged PR, not cost per API key. Model defaults and caps by team, visible to the people they apply to.
Session telemetryIt's all about the correlation: what did a successful PR cost? And successful has to mean merged, with no incidents. I want to see which engineers use skills efficiently and promote that. If you spend a lot of tokens and do good work, great.
Michael Hart
Engineering leader
Total cost
$7,906
Total tokens
9.52B
Sessions
1,284
Merged PRs
212
Cost / merged PR
$37.30
Attribute AI sessions to remote repositories
claude-code
env-manager PR dry-run builds
claude-code
Date-range tags for request templates
cursor
Homebanking support workflow analysis
codex
How it fits together
One service on every laptop. One proxy in your cloud.
The Lander runs on every laptop: it sees each session and tool call as it leaves the device and keeps the device on the approved path. The Connector runs in your cloud: it holds the catalog, decides each tool call, and prices every event.
Finds every client and MCP server. Installs the catalog. Records each session natively.
Approves MCPs and skills. Decides every tool call. Prices and logs every event.
Deployment
Easy to install. Entirely yours to run.
One binary for the control plane.
Deploy the Connector on Kubernetes or as a standalone bundle. The Lander ships as one signed package through Jamf, Intune, or any MDM, nothing to configure on the device. Users sign in once.
Your cloud. Your data. We never see it.
Catalog, policy engine, session telemetry, and audit log all run inside your infrastructure. The only hosted option is the free personal plan, where one developer's data lives in our cloud.
Get started
Start free. Grow into the fleet.
One developer, free and hosted, on a personal or business account. Teams and enterprises get the full platform and a team from us that works alongside yours to tailor policies, MCPs, and skills to your use case.
Personal
The Lander on your own machine, hosted by us. Inventory and native session telemetry for one developer. Sign up with a personal or a business account.
- 1 device, 1 user
- Inventory and session telemetry
- Personal or business account
Team & Enterprise
The Lander on every device plus the Connector, on our SaaS or in your cloud. We don't hand over a license and leave: we work embedded with your team to tailor policies, MCPs, and skills to your use case, and to bring your engineers up to speed.
- Every device, every user
- Our SaaS, your Kubernetes, or your MDM
- Embedded with your team, tailored to your use case