Vijil Discover
Identifies every agent in your organization.

Find the agents nobody told you about. And tag each with a verifiable ID.

Your inventory is a guess. Discover turns it into a census, and grants every agent it finds a name it can prove.

WHY THE POPULATION GREW WITHOUT YOU

Nobody filed a ticket to create an agent

An agent is a few lines of code and an API key. A developer builds one on a Thursday, deploys it to a runtime that already existed, and wires it to a data source it already had credentials for. No procurement, no review, no diagram, and no reason for anyone to have told you. The population accumulated without a design, and the three people who answer for it feel it differently.

THE BUSINESS OWNER

“I answer for what the company’s agents do, and that covers a set nobody can list. The ones I approved are in it. So are the ones nobody brought to me.”

THE RISK OWNER

“I cannot assess what I cannot enumerate. The count I am given is the count somebody remembered to mention, and no policy produces the real one.”

THE AGENT DEVELOPER

“My agent is already somebody else’s shadow IT, and the first person to ask will ask during an incident.”

You have already looked, with the tools you own
“Our CSPM already inventories cloud resources.”

It inventories resources. An agent is a behavior assembled from several — a runtime, a model endpoint, tool credentials, a retrieval source. Your CSPM sees every part and still has no row for the agent, because the agent was never registered as an object.

“We already have an agent registry.”

Then you have the declared population. The gap between what is declared and what is running is the whole problem, and a register is made of declarations. Only something that looks at the running systems can measure it.

Either way you hold a list — a hostname and no principal, true on the Tuesday it ran. What all three need is a census, with an identity attached to every row.

WHAT DISCOVER IS

Every agent it finds gets a name it can prove

Plenty of scanners find undeclared agents; that part is table stakes. Discover attests what it finds. A cloud or Kubernetes workload takes a SPIFFE X.509 identity of its own — one per agent class, one per running instance — with a trust score attached to that identity. An attested agent is addressable: it can be named in a policy, scored by Diamond with no endpoint or wrapper, monitored, and cut off. Every agent also carries a card, written when it is found rather than when somebody asks. Purpose, constraints, capabilities: the artifact a review wants and nobody has time to write under pressure.

Cloud VPCAWS accountsOn-premKubernetes · VMwareEndpointsMac · Windows · LinuxBrowsermodel use in the browserSource codeGitHub repositoriesDISCOVERscanners + agent fingerprintingalways on · continuousENRICHED AGENT RECORDidentity · model · authendpoints · evidenceattested — SPIFFE X.509 SVIDCENTRAL REGISTRYevery agent stored, searchable and attestedauditortriage→ verifyCloud VPCAWS accountsOn-premK8s · VMwareEndpointsMac · Win · LinuxBrowserLLM useSource codeGitHub reposDISCOVERscanners + agent fingerprintingalways on · continuousENRICHED AGENT RECORDidentity · model · authendpoints · evidence✓ attested — SPIFFE X.509 SVIDCENTRAL REGISTRYevery agent stored, searchable and attestedauditor · triage · → verify
WHAT DISCOVER IS

The registry, as the auditor opens it

The Vijil Discover console: three cards counting frameworks, models and providers across the estate, above a findings table naming each one.
Everything found, classified by framework, model and provider, over the rows that name each one.
The same console with an alerts panel above the findings: four agents flagged with the reason each was raised and a control to review or dismiss it.
What changed since the last run, raised as alerts rather than left in the table to be noticed.

A census is only useful if somebody reads it. The rows are the record; the alerts are what makes it a control.

WHERE IT FITS

First, because everything after it needs a name to hold on to

specYOUR INPUTidentifyDISCOVERverifyDIAMONDdeployYOUR CI/CDdefendDOMEevolveDARWINcodeYOUR AGENTdashed steps use your platform of choice
Discover is the single door into the Trusted Agent Lifecycle: itdiscovers what is running and registers the identity that makes one attested. Diamond scores by that identity, Dome enforces on it, Darwin attributes to it.
WHAT IT COSTS

Three ways in

We publish no list price because there is no meter to read from. Finding agents is free at any scale and stays free. The paid tier is a deployment inside your own network, with no agent count and no token bill. Every tier is on the pricing page.

Endpoint — Open Source
For consenting developers
Installers for macOS, Windows and Linux, plus a browser extension.
  • Register your agent to give it a SPIFFE identity
  • Attach a trust score to the agent identity
  • Minimize the time to compliance with appsec and GRC regs
Hosted — free
START HERE
Your estate, on our console
  • Every GitHub org and cloud account, scanned as often as you like
  • An agent card per agent, with the evidence that found it
  • Recent history rather than a year of it, and no export
  • Nothing is metered by how much you can see — only by how long you can keep the records.
Air-gapped
Unmetered, in your VPC
Your hardware is the only limit.
  • Your own VPC, on-premises, or air-gapped
  • Every surface, including what a hosted scan cannot reach
  • Attested identity, and policy over the population
  • The registry stays inside your network
How the whole family is priced →
HOW TO GET STARTED

Rows on the first run, identities on the second

  1. Scan a cloud account or a GitHub org

    Read-only API access, nothing installed. This is the fastest way to see rows, and it is where most people start — no change window, no ticket.

  2. Add the hosts where the agents actually are

    The laptops. Installers for macOS, Windows and Linux, plus a browser extension. Agents pull their schedule; nothing reaches inward, so your firewall does not move.

  3. Attest what you are keeping

    A cloud or Kubernetes workload takes an identity of its own, and that identity is what policy, scoring and runtime control key off. An endpoint reports through an attested node agent, so its rows carry provenance even where the agent itself holds no SVID yet.

The New scan dialog on its Scan surfaces tab, listing the surfaces available to scan.
One dialog. Pick the surfaces, start the scan; the rows arrive without anything installed.

One org is enough to see the shape of it. vijil register github.com/acme/agent moves a single agent from found to attested.

WHAT A FIRST RUN RETURNS

One row per agent, and one for what it could not reach

What it is, where it runs, and whether it carries an attested identity. Discover fingerprints the binary rather than the category, so a row names a tool instead of saying “an AI assistant”.

The Vijil Discover targets table: repository rows, one of them expanded into eight discovered agents, each naming its framework, its model and its tool count, with a Register control per row.
One row per agent, named by what it is rather than what it resembles. The framework and the model are the row — langgraph 0.2.0 on qwen3-32b is a fact you can act on, where “an AI assistant” is not. Register moves one from found to attested.

A segment nobody reached is reported as a row carrying the reason. A coverage report that omits what it missed is a number wearing the clothes of evidence.

The New scan dialog on its Source code tab: a GitHub connection, the vijilAI organization selected, and a filterable list of repositories to scan.

Scan one GitHub repository

Pick the one you would have guessed was tidy. The agents it turns up are usually the interesting part.