Deployment
Integrations & Deployment
Connect SinzAI to your environment in hours, not weeks — no agents installed on endpoints.
Agentless, Read-Only Detection
SinzAI Detect connects via APIs to systems your organization already runs. Nothing is installed on endpoints, no agents are deployed, and all connections are read-only by default. The collector pulls metadata and telemetry — never payload contents, PII, or business data.
API Gateway Log Ingestion
Connect to Kong, Apigee, AWS API Gateway, or Envoy to ingest request logs. SinzAI identifies agent-originated traffic patterns — high-frequency calls, structured payloads, LLM-typical headers (x-model, x-temperature) — and surfaces candidates for registration.
Network DLP Feeds
Ingest DLP telemetry from your existing network layer. Agentic outbound traffic to LLM providers (OpenAI, Anthropic, Google AI) is flagged even when it bypasses the API gateway entirely — catching shadow agents at the network edge.
SSO / Identity Provider Logs
Connect to Okta, Azure AD, or Google Workspace. SinzAI analyzes service accounts and machine identities for agent-like behavior: predictable session cadences, automated credential rotation, and API-heavy access patterns that differ from human usage.
Cloud Cost & LLM Usage APIs
Integrate with AWS Cost Explorer, Azure Cost Management, OpenAI usage endpoints, and Anthropic billing APIs. SinzAI flags AI-related spend — LLM API keys, model inference costs, vector database provisioning — that indicates unregistered agent activity. This is the 'pays for itself' wedge: governance funded by shadow spend discovery.
Optional Inline Enforcement Point
Where runtime control is required — human-in-the-loop approval gates, kill switches, or agent quarantine — SinzAI deploys a single lightweight gateway plugin or sidecar. This is not a pervasive agent fleet; it is one enforcement point at the ingress/egress boundary where agent traffic flows.
When enforcement is needed vs. when detection alone suffices
Detection only (log-based)
- •Agent inventory and discovery
- •Shadow AI flagging and reporting
- •Compliance audit trails (post-hoc)
- •Cost monitoring and anomaly detection
Enforcement required (inline plugin)
- •HITL approval gates on external side effects
- •Kill switch (global and per-agent)
- •Agent quarantine and isolation
- •Real-time policy enforcement (block before action)
Data Flow
Data flows from existing infrastructure sources through the SinzAI collector API into the governance pipeline. All connections are outbound-initiated from the customer environment — SinzAI never reaches into your network.
Sources → Collector API → Inventory → Governance pipeline. Enforcement is optional and only deployed where runtime control is needed.
Security & Trust
SinzAI is designed with a security-first posture. Every integration choice prioritizes minimizing your attack surface while maximizing visibility.
Read-only by default
All source connectors ingest data via read-only API access. SinzAI never writes to your infrastructure systems — it reads telemetry, classifies risk, and surfaces findings.
Outbound-initiated connections
The collector API accepts connections initiated from your environment. SinzAI never reaches into your network or requires inbound firewall rules. No VPN, no VPC peering, no network reconfiguration.
Metadata only — no data exfiltration
SinzAI collects metadata and telemetry: agent identity, traffic patterns, API call counts, credential TTLs, model versions. It never ingests payload bodies, PII, or business data. Your data stays in your environment.
Our posture
SinzAI operates under a SOC 2-aligned security program with continuous monitoring, encrypted data-at-rest and in-transit, role-based access controls, and SOC 2 Type II reporting (in process). This statement describes our operational posture; it is not a certification claim.
Deployment Time
SinzAI connectors are designed for rapid configuration — API key provisioning, scope selection, and validation are the only steps required. Typical organizations configure their initial detection surfaces in hours, not weeks.
Typical timeline
API gateway connector
Provision read-only API credentials, configure log stream target, validate traffic visibility.
SSO / IdP connector
Create a read-only service principal, grant log access scopes, verify agent identity detection.
Cloud cost connector
Configure IAM role with Cost Explorer read access, validate spend categorization.
Network DLP feed
Configure syslog or SIEM forwarding rule, test outbound LLM traffic detection.
Inline enforcement (optional)
Deploy gateway plugin or sidecar, configure HITL gate policies, test kill switch in staging.
Next Steps
Once your connectors are configured, SinzAI begins building your agent inventory immediately. From there:
- 1.Review the Detect page to understand how discovered agents are classified and flagged.
- 2.Configure data store mappings to enable toxic combination alerts.
- 3.Set up governance policies — purpose registration, access scoping, and HITL gates.