Certiv
1.0.0 commercialCertiv is an AI-powered code security tool that identifies and remediates vulnerabilities in software development workflows.
Summary
Certiv is a commercial ai-security platform that gives organizations visibility and control over AI agents running on their endpoints, discovering what agents are installed and governing what they do. It runs an endpoint observer, called Scout, alongside a policy engine that evaluates agent sessions and can block, pause, or steer them in real time, with a hosted service layer behind lead-capture and demo-request endpoints suggesting a SaaS-delivered product. It is aimed at security and compliance teams who need to answer what AI is running inside their organization rather than at the developers building those agents. Its Privacy Mode feature narrows what those teams see by default, surfacing only sessions with policy violations while keeping compliant sessions private unless someone records a justified reason for access, with that access logged for audit.
Certiv is an AI-powered code security tool that identifies and remediates vulnerabilities in software development workflows.
What Certiv answers
Which AI agents on our machines would this actually catch?
Scout observes the endpoint directly, so it discovers agents that were installed without going through IT rather than only ones already registered
Does blocking a session require someone watching a dashboard in real time?
the policy engine evaluates sessions as they happen and can intervene on its own, with a human only pulled in when access to a private session needs justifying
Will turning this on mean security reads every employee's AI conversations?
by default only sessions that violate policy are surfaced, compliant sessions stay hidden until someone logs a specific reason for opening one
Is there a record we can hand to a works council or auditor?
every access to a private compliant session is logged with who opened it and the reason given
Do we need to roll this out ourselves or is it something Certiv turns on for us?
it is a preview feature enabled on request by the Certiv team for existing customers, not a self-service setting
Does narrowing what security sees weaken the real-time blocking?
visibility and intervention are separate, so hiding compliant sessions from view does not change how Block, Pause, and Steer respond to a violation
Release history
- 1.0.0
Certiv now publishes an API — 2 endpoints across 1 area: Lead Capture
- ›Lead Capture (2 endpoints) — Public endpoints for requesting a demo or subscribing to the newsletter.
- Enterprise Security with Privacy by Design: Introducing Privacy Mode
Certiv introduces Privacy Mode, making agent session visibility proportional to risk — violations surface automatically, compliant sessions stay private.

- ›Introduces Privacy Mode (now in Preview), which restricts session visibility by default so that only agent sessions with policy violations are automatically surfaced to security teams.
- ›Compliant sessions without policy violations remain private unless an authorized governance team member records an explicit justification for access, with Certiv logging who accessed the session and why.
- ›Privacy Mode integrates with the existing Policy Engine and Scout endpoint observer — Block, Pause, and Steer runtime interventions continue operating unchanged; Privacy Mode governs only post-session review access.