// moorai · event flow

See the flow, not the content.

Data lineage for AI agents — without the surveillance. Security tools show you where data went by reading it. MoorAI draws the same picture from content-free signals alone: which app a coding agent read from, which actor drove it, where it was headed, the data class, and the risk — category, risk level, a one-way actor hash, tool, and stage. Never a filename. Never a prompt.

MoorAI — Security Dashboard OverviewTimelineEvent FlowPolicyCompliance

Event Flow — Source → Actor → Destination, content-free

Credential-class data read via hook:Read → headed to an external coding agent · blocked
Local → External agent
SOURCE ACTOR DESTINATION hook:Read Credential · 42 events · 6 risky hook:Bash Secret · 18 events mcp__slack Source code · 11 events claude -p PII · 27 events UBA Actor 7f3a 60 events · 6 risky ⛔ BLOCK ENFORCED Actor b1c9 38 events · 2 risky external model API egress · 31 events agent output output · 22 events agent context file · 16 events blocked 6 events · policy: block
allowed elevated blocked / critical Content-free — nodes are apps, actor hashes, and stages; never filenames or prompt content.

Lineage, not surveillance

Cyberhaven-style lineage tells the story from origin to exfiltration — but it reads the data to do it. MoorAI carries the same story with nodes, direction, and counts. The value was never the filename.

Every edge is redacted metadata

Source = the tool/MCP the agent read through. Actor = a one-way hash of the operator. Destination = the egress stage. Data class + risk color it. That's the whole graph — and none of it is content.

Content-free by construction

Not "we don't store your prompts" on faith. The agent is open source (AGPL-3.0); the telemetry is redacted before it leaves the machine. You can't leak what you never persist.

Get started free MoorAI overview → On-device AI DLP → OWASP LLM Top 10 →

The dashboard view shown is representative; nodes, actors, and counts are illustrative. Every element derives from content-free alert fields (category, risk level, actor hash, tool, stage) that MoorAI already emits — no filename, prompt, or file content is stored or displayed. Cyberhaven is a trademark of its respective owner; this page is not affiliated with or endorsed by it.

glick.run — AGPL-3.0