Deployment

Integrations & Deployment

Connect SinzAI to your environment in hours, not weeks — no agents installed on endpoints.

Agentless, Read-Only Detection

SinzAI Detect connects via APIs to systems your organization already runs. Nothing is installed on endpoints, no agents are deployed, and all connections are read-only by default. The collector pulls metadata and telemetry — never payload contents, PII, or business data.

API Gateway Log Ingestion

Connect to Kong, Apigee, AWS API Gateway, or Envoy to ingest request logs. SinzAI identifies agent-originated traffic patterns — high-frequency calls, structured payloads, LLM-typical headers (x-model, x-temperature) — and surfaces candidates for registration.

Network DLP Feeds

Ingest DLP telemetry from your existing network layer. Agentic outbound traffic to LLM providers (OpenAI, Anthropic, Google AI) is flagged even when it bypasses the API gateway entirely — catching shadow agents at the network edge.

SSO / Identity Provider Logs

Connect to Okta, Azure AD, or Google Workspace. SinzAI analyzes service accounts and machine identities for agent-like behavior: predictable session cadences, automated credential rotation, and API-heavy access patterns that differ from human usage.

Cloud Cost & LLM Usage APIs

Integrate with AWS Cost Explorer, Azure Cost Management, OpenAI usage endpoints, and Anthropic billing APIs. SinzAI flags AI-related spend — LLM API keys, model inference costs, vector database provisioning — that indicates unregistered agent activity. This is the 'pays for itself' wedge: governance funded by shadow spend discovery.

Optional Inline Enforcement Point

Where runtime control is required — human-in-the-loop approval gates, kill switches, or agent quarantine — SinzAI deploys a single lightweight gateway plugin or sidecar. This is not a pervasive agent fleet; it is one enforcement point at the ingress/egress boundary where agent traffic flows.

When enforcement is needed vs. when detection alone suffices

Detection only (log-based)

  • Agent inventory and discovery
  • Shadow AI flagging and reporting
  • Compliance audit trails (post-hoc)
  • Cost monitoring and anomaly detection

Enforcement required (inline plugin)

  • HITL approval gates on external side effects
  • Kill switch (global and per-agent)
  • Agent quarantine and isolation
  • Real-time policy enforcement (block before action)

Data Flow

Data flows from existing infrastructure sources through the SinzAI collector API into the governance pipeline. All connections are outbound-initiated from the customer environment — SinzAI never reaches into your network.

SOURCESAPI GatewaysNetwork DLPSSO / IdP LogsCloud Cost APIsLLM Usage APIsread-onlyCollector APImetadata onlyoutbound-initiatedInventoryagent registryshadow flagsMapclassify dataGovernHITL • kill switchProvecomplianceUndorollbackOptional inline enforcement (plugin/sidecar)

Sources → Collector API → Inventory → Governance pipeline. Enforcement is optional and only deployed where runtime control is needed.

Security & Trust

SinzAI is designed with a security-first posture. Every integration choice prioritizes minimizing your attack surface while maximizing visibility.

Read-only by default

All source connectors ingest data via read-only API access. SinzAI never writes to your infrastructure systems — it reads telemetry, classifies risk, and surfaces findings.

Outbound-initiated connections

The collector API accepts connections initiated from your environment. SinzAI never reaches into your network or requires inbound firewall rules. No VPN, no VPC peering, no network reconfiguration.

Metadata only — no data exfiltration

SinzAI collects metadata and telemetry: agent identity, traffic patterns, API call counts, credential TTLs, model versions. It never ingests payload bodies, PII, or business data. Your data stays in your environment.

Our posture

SinzAI operates under a SOC 2-aligned security program with continuous monitoring, encrypted data-at-rest and in-transit, role-based access controls, and SOC 2 Type II reporting (in process). This statement describes our operational posture; it is not a certification claim.

Deployment Time

SinzAI connectors are designed for rapid configuration — API key provisioning, scope selection, and validation are the only steps required. Typical organizations configure their initial detection surfaces in hours, not weeks.

Typical timeline

API gateway connector

Provision read-only API credentials, configure log stream target, validate traffic visibility.

15–30 minutes

SSO / IdP connector

Create a read-only service principal, grant log access scopes, verify agent identity detection.

15–30 minutes

Cloud cost connector

Configure IAM role with Cost Explorer read access, validate spend categorization.

30–60 minutes

Network DLP feed

Configure syslog or SIEM forwarding rule, test outbound LLM traffic detection.

1–2 hours

Inline enforcement (optional)

Deploy gateway plugin or sidecar, configure HITL gate policies, test kill switch in staging.

2–4 hours

Next Steps

Once your connectors are configured, SinzAI begins building your agent inventory immediately. From there:

  • 1.Review the Detect page to understand how discovered agents are classified and flagged.
  • 2.Configure data store mappings to enable toxic combination alerts.
  • 3.Set up governance policies — purpose registration, access scoping, and HITL gates.