Data lineage for AI agents — without the surveillance. Security tools show you where data went by reading it. MoorAI draws the same picture from content-free signals alone: which app a coding agent read from, which actor drove it, where it was headed, the data class, and the risk — category, risk level, a one-way actor hash, tool, and stage. Never a filename. Never a prompt.
Cyberhaven-style lineage tells the story from origin to exfiltration — but it reads the data to do it. MoorAI carries the same story with nodes, direction, and counts. The value was never the filename.
Source = the tool/MCP the agent read through. Actor = a one-way hash of the operator. Destination = the egress stage. Data class + risk color it. That's the whole graph — and none of it is content.
Not "we don't store your prompts" on faith. The agent is open source (AGPL-3.0); the telemetry is redacted before it leaves the machine. You can't leak what you never persist.
The dashboard view shown is representative; nodes, actors, and counts are illustrative. Every element derives from content-free alert fields (category, risk level, actor hash, tool, stage) that MoorAI already emits — no filename, prompt, or file content is stored or displayed. Cyberhaven is a trademark of its respective owner; this page is not affiliated with or endorsed by it.