Built for engineering-driven organizations
Detect, control, and enforce AI usage policies across ChatGPT, Claude, Copilot, coding agents, IDEs, and enterprise AI workflows.
No credit card required. · Install in minutes.
Coverage
The AI governance gap
Employees and coding agents are already:
Most organizations have no visibility or control.
Detect · Control · Enforce
From visibility into prompts and AI activity, to policy enforcement and high-risk action controls, Oconee Runtime covers every step of AI use.
Detect
Monitor AI usage across browser tools, coding agents, and enterprise workflows in real time.
Control
Apply organization-wide AI policies without disrupting engineering workflows.
Enforce
Stop risky AI-assisted actions before sensitive data leaves your organization.
AI Action Governance
Visibility tells you what AI did. Oconee helps govern what supported AI agents are allowed to do — evaluated in context, before execution, on surfaces that can intercept.
AI proposes. Policy decides.
A coding agent asks to run a command, write a file, install a dependency or call a tool.
The action is classified and matched against policy using the repository, environment and resource it targets.
A decision is returned before the action runs, on integrations that can intercept it.
What policy decided, what enforcement achieved and whether execution was observed are recorded separately.
npm install package-xAn illustrative policy configuration. Repository classification is set by your administrators and resolved server-side, so a modified client cannot downgrade its own repository.
| Proposed action | Context | Decision |
|---|---|---|
| Dependency install | Critical repository | BLOCK |
| File write to a credential-sensitive resource | Any repository | BLOCK |
| Destructive shell command | Production-facing repository | BLOCK |
| Routine file edit | Development repository | ALLOW |
Oconee records what policy decided, what enforcement actually achieved, and whether execution was observed — as three separate facts. A decision to block is not the same as a block that happened, and the record says which.
Evaluates and records across supported integrations. Intercepts on supported surfaces. Integrations differ in what they can enforce, and the dashboard shows which of yours can intercept and which only observe.
Platform coverage
Govern AI usage across browser, IDE, coding-agent, and autonomous execution surfaces.
ChatGPT
Claude
GitHub Copilot
Cursor
Claude Code
VS Code
Browser AI tools
Coding agents
MCP / external tools
Live product demo
Watch a sensitive paste trigger detection, enforcement, and dashboard logging in real time.
How it works
No workflow changes required.
Audit visibility
Track AI usage, investigate risky activity, and maintain audit visibility across your organization.
Who it's for
Especially valuable for organizations adopting coding agents and AI-assisted development workflows.
Free tools
Two ways to find out where you stand, neither of which needs an account.
For developers & AppSec
Find common AI-agent governance gaps in your repository — coding-agent configuration, commands, MCP and tool access, sensitive resources, and auditability.
$ git clone https://github.com/oconeesoftware/oconee-scan
$ cd oconee-scan
$ npm install && npm run build
$ node dist/cli/index.jsFor security & AI governance leaders
Benchmark your organization's readiness across visibility, action authorization, coding agents, MCP and tool governance, and audit evidence.
Take the Free AssessmentSecurity & trust
Review Oconee Runtime's approach to security, data handling, privacy, and enterprise evaluation.
Pricing
Visibility
$750/month
10 users included
Control
$1,500/month
25 users included · $50/additional user
Engineering Enforcement
$3,000/month
75 users included · $40/additional user
Governance
From $7,500/month
250 users included · $30/additional user
Each tier adds onto the one below it.
| Feature | Starter | Growth | Growth+ | Enterprise |
|---|---|---|---|---|
| Detection | ||||
| Prompt visibility | Included | Included | Included | Included |
| Sensitive data detection | Included | Included | Included | Included |
| AI activity logging | Included | Included | Included | Included |
| Session visibility | Included | Included | Included | Included |
| Policy controls | ||||
| Allow / warn / block | Not included | Included | Included | Included |
| Policy management | Not included | Included | Included | Included |
| Tool governance | Not included | Included | Included | Included |
| Repo sensitivity controls | Not included | Included | Included | Included |
| Context-aware policy (repository, environment, resource) | Not included | Included | Included | Included |
| Repository & environment context registry | Not included | Included | Included | Included |
| Action-type governance | Not included | Included | Included | Included |
| Enforcement | ||||
| Command enforcement | Not included | Not included | Included | Included |
| File mutation controls | Not included | Not included | Included | Included |
| Credential blocking | Not included | Not included | Included | Included |
| High-risk action alerts | Not included | Not included | Included | Included |
| Real-time prompt blocking (Copilot Chat) | Not included | Not included | Included | Included |
| Claude Code pre-execution enforcement | Not included | Not included | Included | Included |
| Coding-agent action classification | Not included | Not included | Included | Included |
| Dependency install governance | Not included | Not included | Included | Included |
| MCP & tool-call governance | Not included | Not included | Included | Included |
| Guarded model access (VS Code) | Not included | Not included | Included | Included |
| Audit visibility | ||||
| AI activity feed | Included | Included | Included | Included |
| Session timeline | Included | Included | Included | Included |
| Slack alerts | Included | Included | Included | Included |
| Policy violations | Not included | Included | Included | Included |
| Risk severity | Not included | Included | Included | Included |
| Repo sensitivity | Not included | Included | Included | Included |
| Command detection | Not included | Not included | Included | Included |
| Enforcement logs | Not included | Not included | Included | Included |
| Decision context on every decision | Not included | Included | Included | Included |
| Enforcement coverage (which integrations can intercept) | Not included | Included | Included | Included |
| Historical decision evidence (policy version & winning rule) | Not included | Not included | Included | Included |
| Extended audit retention | Not included | Included | Included | Included |
| Coverage | ||||
| Browser AI tools (ChatGPT, Claude) | Included | Included | Included | Included |
| IDE workflows (VS Code, Cursor, GitHub Copilot) | Not included | Not included | Included | Included |
| Coding agents (Claude Code) | Not included | Not included | Included | Included |
| MCP / external tools | Not included | Not included | Not included | Included |
| Security & privacy | ||||
| Organization-scoped isolation | Included | Included | Included | Included |
| Encrypted telemetry | Included | Included | Included | Included |
| Secure audit retention | Included | Included | Included | Included |
| Minimal performance overhead | Included | Included | Included | Included |
| No model training on customer data | Included | Included | Included | Included |
| Policy-based enforcement architecture | Not included | Included | Included | Included |
| Enterprise governance & compliance | ||||
| SSO / SAML | Not included | Not included | Not included | Included |
| SIEM export | Not included | Not included | Not included | Included |
| GDPR / compliance tooling | Not included | Not included | Not included | Included |
| PHI detection (healthcare) | Not included | Not included | Not included | Included |
| Custom detection patterns | Not included | Not included | Not included | Included |
| Policy templates | Not included | Not included | Not included | Included |
| Exception requests & review | Not included | Not included | Not included | Included |
| Inline enforcement pre-check | Not included | Not included | Not included | Included |
| Custom branding | Not included | Not included | Not included | Included |
| Organization-wide governance scope | Not included | Not included | Not included | Included |
Enterprise adds SSO, SIEM export, compliance tooling (GDPR/PHI), and organization-wide governance scope on top of every Growth+ capability. Contact sales for custom retention, compliance, and deployment requirements.
Security & privacy
organization-scoped isolation
encrypted telemetry
secure audit retention
minimal performance overhead
no model training on customer data
policy-based enforcement architecture
Get started
Detect risk immediately. Enforce policies before sensitive data leaves your organization.
Install in minutes. · No credit card required.