Everything 8200.dev does
Control comes first: see every AI tool with access, decide per rule what it may do, and act at the source when you opt in. Around it sit the inventory, compliance evidence and integrations that fit your stack — organized by category, with the plan each capability ships in.
Control — decide what AI may do, and act on it
Enforcement is opt-in and off by default, and we say so up front. It acts only when three things are true: the organization switch is on, a policy is armed for the rule, and you have granted that connector write scopes. Until all three hold, every enforcement is shown as a simulation — nothing in your sources changes by surprise, and you stay the one who decides.
Agent Guard — decide what each AI agent may reach
TeamEvery AI agent and service account on a scope-vs-trust risk matrix, with its exposure. You set the access policy each agent is allowed; when one exceeds it you get a finding with the exact fix — and, once you grant write access, an admin can revoke or reduce that access from 8200.dev.
Learn moreFlow Guard — decide where your data may go
StarterAn interactive map of who shares what with whom outside your org, with external hubs highlighted. Each risky flow gets a plain-language verdict — allow, flag or block — against the destinations and sensitivity you allow; a block is enforced only when prevention is switched on for that connector, and shown as a simulation until then.
Learn moreEnforcement Policies — your rules, your tier
BusinessFor every detection rule, decide what happens: override its severity, switch it off, route its alerts, and choose its tier — Detect & Alert, Recommend & Guide or Auto-remediate. One global kill switch returns everything to simulate-only.
Learn morePrevention rules engine
BusinessProactive watch-and-act rules that alert or queue a fix the moment a new finding matches — scan-based and honest.
Learn moreAuto-remediate — act at the source, when you arm it
EnterpriseStep-by-step fix guidance for every finding. When you arm it, 8200.dev revokes or reduces access itself: public links, external shares and unused or orphaned API keys can be removed unattended; downgrades always wait for a person's click. Every action is audit-logged with the state before and after.
Learn moreAI Governance & Accountability
AI Governance dashboard
FreeOne view answering “what AI is running in your org, and is it governed?” — shadow AI discovered through OAuth grants (DeepSeek, Kimi, Grok, Perplexity), agentic platforms like Manus on elevated watch, vendor AI-training posture, and governance findings from the connected AI vendors (Mistral AI, OpenAI, ChatGPT Enterprise, Anthropic, Cursor). Point-in-time posture from read-only admin-API and OAuth metadata — no traffic interception, no prompt inspection.
Learn moreAI agent inventory
TeamA complete, continuously-updated inventory of every AI agent and service account that can reach your data. You cannot govern — or prove you governed — what you cannot see.
Learn moreAI Data Contribution Awareness
FreeFlags when a connected platform is set to use your organization’s content or metadata to train third-party AI models, so it’s a decision you make on purpose, not a default you never saw.
Learn moreAI Agent Registry
FreeManually register every AI agent on a platform we don't connect to yet — WhatsApp, Telegram, ManyChat, Tidio, custom and voice bots. Classify each agent's data access, get an automatic risk score and findings, and export the audit-ready proof of inventory. Discovered + registered = your complete inventory.
Learn moreAI-Built App Detection
TeamFlag the OAuth apps built with AI app builders — Lovable, Base44, Bolt.new, Cursor and similar — see exactly what data each can reach, and get findings the moment one touches customer PII or holds broad access with no retention policy. You deployed it; you're accountable for it.
Learn moreShadow AI discovery
TeamFind the third-party and AI OAuth grants already connected to your Workspace, so an unsanctioned tool is caught before it becomes a liability.
Learn moreAccountability audit trail
EnterpriseAn immutable, exportable record of access decisions (CSV / JSON / CEF / SIEM) — the audit-ready evidence a reviewer or auditor expects.
Learn moreCompliance evidence
BusinessGenerate the documentation auditors request, mapped to SOC 2, ISO 27001, and GDPR controls. Maps to frameworks; it never claims certification.
Learn moreCustomer Support AI Governance
Intercom Fin AI Agent governance
TeamConnect Intercom and discover the Fin AI Agent and every custom bot — their knowledge sources, whether they answer on sensitive topics, the external data they reach, and whether a human is in the loop. You are accountable for what a customer-facing AI says; govern it before it speaks.
Learn moreZendesk AI & Copilot governance
TeamConnect Zendesk and surface its AI bots and agent Copilot — sensitive-field and PII access, escalation policy, third-party AI apps — alongside account security (SSO, 2FA enforcement, public ticket sharing, API-token age and custom-role delete rights).
Learn moreDiscovery & scanning
42+ security checks
FreePublic links, external sharing, stale access, over-permissioning, owner sprawl, AI-agent reach and more — every scan, read-only.
Learn moreShared Drive scanning
FreeInventory every Shared Drive, its members and external access, restriction settings and orphaned-manager risks.
Learn moreThird-party OAuth app audit
TeamDiscover which marketplace and OAuth apps users granted access to your Workspace, with a risk score per app.
Learn moreSensitive-data (DLP) patterns
BusinessFlag files whose names or locations match credential, financial, HR and PII patterns — tunable per organization.
Learn moreNo-code custom detection rules
BusinessBuild your own checks in an 18-field rule builder — no code — and fold them into every scan alongside the built-ins.
Learn moreVisualize & detect
Behavioral anomaly detection (UEBA)
BusinessPer-user baselines plus seven anomaly types — sharing spikes, bulk access, dormant reactivation, OAuth bursts.
Learn moreSecurity awareness scores
BusinessA per-user security score with a leaderboard and badges, so good data hygiene becomes visible and rewarded.
Learn moreRisk timeline
BusinessOne chronological feed of findings, scans, audit events and OAuth grants — the unified story of your security posture.
Learn moreIndustry benchmarking
BusinessSee how your posture score compares to anonymized peers in your industry and company-size band.
Learn moreActivity analytics & MTTR
BusinessTrack mean-time-to-remediate, SLA attainment and team activity over time — see how fast risks get fixed and where the bottlenecks are.
Learn moreGovern & prevent
External sharing governance
FreeEvery external share in one place with an approval workflow, trusted-domain trust list and a sharing report PDF.
Learn moreSmart alert feed
FreeScan findings grouped into one alert per category, routed by severity, with quiet hours and noise-killing suppression.
Learn moreIncident tracking
BusinessA full incident lifecycle (Open → Investigating → Contained → Resolved → Closed) with an exportable response PDF.
Learn moreCompliance & reporting
5-framework compliance mapping
BusinessMap findings to SOC 2, ISO 27001, GDPR, HIPAA and NIST CSF controls — Satisfied / Partial / Gap, no spreadsheets.
Learn moreAuto-generated evidence packages
BusinessOne audit-ready ZIP per framework — a folder per control with the product data that proves it. Secret-free.
Learn morePosture score breakdown
FreeA single 0–100 score, decomposed by category and rule, with the top improvements and quick wins ranked.
Learn moreExecutive report
BusinessA board-ready, AI-written summary PDF over fact-only data — risks, trend, peer comparison and recommended actions.
Learn moreScheduled reports
StarterOpt into a weekly or monthly posture report emailed as a PDF — no one has to remember to run it.
Learn moreIntegrations & API
Slack bot
TeamRich Block Kit finding cards with Acknowledge / Snooze buttons, slash commands and per-org install — no SDK.
Learn moreTicketing integration
BusinessAuto-create Jira, Linear, GitHub or Asana tickets for new findings, with two-way status sync that auto-resolves.
Learn moreSigned webhooks
TeamHMAC-signed webhooks for every security event, plus Slack/Teams formatting and SIEM (CEF) presets.
Learn moreSIEM export
EnterpriseStream the audit trail to your SIEM — CSV / JSON / CEF export and a live event stream for enterprise tooling.
Learn moreREST API & keys
BusinessProgrammatic access to findings and posture with scoped API keys, Bearer auth and rate limits.
Learn moreAccess & account security
SSO / SAML
EnterpriseEnterprise single sign-on with Okta, Azure AD, Google and OneLogin — metadata import, JIT provisioning, require-SSO.
Learn moreMFA / 2FA
BusinessOrganization-wide multi-factor enforcement with TOTP authenticator apps and one-time backup codes.
Learn moreCustom RBAC
EnterpriseFine-grained roles built from per-feature permission atoms, with templates — beyond Owner / Admin / Viewer.
Learn moreIP allowlisting
EnterpriseRestrict access to your trusted CIDR ranges (IPv4 and IPv6), with self-lockout prevention.
Learn moreSession management
FreeSee active sessions, set max-duration and idle-timeout policies, and force-logout a user.
Learn moreAudit log
BusinessA per-organization, append-only trail of who did what and when — the record an auditor asks for.
Learn moreExperience
AI product expert, 24/7
FreeA grounded, multilingual sales-and-support agent that answers product questions in your language, day or night.
Learn moreAsset inventory
FreeThe positive “what do I have” view — users, files and Shared Drives, searchable, filterable and exportable.
Learn more33 languages
Free13 hand-translated locales plus 20 more translated on the fly, with full right-to-left support.
Multi-organization
FreeManage several organizations under one login and switch between them in a click — built for teams and partners.
Learn moreHelp center & status page
FreeTwo dozen how-to articles, a searchable help center, and a public status page with uptime monitoring.
Learn moreSelf-serve billing
FreeA usage dashboard, invoice history and self-serve plan changes — no sales call to upgrade or cancel.
Learn moreFor MSSPs & IT partners
Manage every client from one account
MSSPs, IT consultancies and managed service providers run all their clients' Google Workspace security from a single partner account — a consolidated dashboard, portfolio reports, white-label, and self-serve onboarding.
Start managing your clients' security