Evidence tier Source Confirmed · 4 captures on record
What the publisher says
As described on AWS Marketplace.
Bay is the single control plane for all agentic activity on the endpoint. AI agents now act, decide, and adapt on their own across enterprise devices, and security teams cannot see which agents are running, what they can reach, or how to stop a harmful action before it completes. Traditional endpoint tools watch OS-level events; they cannot see agent-level decisions, local MCP servers, or the prompt-to-action chain behind them.
Bay closes that gap with an agentless platform that deploys through your existing MDM or EDR in under 5 minutes, with no persistent agent, proxy, or kernel driver.
Show the rest of the publisher’s description (8 more lines)
Built on AWS, the platform:
- Discovers every AI agent, MCP server, browser and IDE extension, package, and skill across the fleet, surfacing shadow AI on 100% of deployments and mapping every user, permission, and credential into a contextual entity graph with 200+ built-in detection rules, risk-scored findings, and guided remediation.
- Scans every component for malicious indicators, typosquats, CVEs, and risky permissions, with centralized approve and block controls across the agentic supply chain.
- Monitors every agent action in real time with full context, human versus autonomous, the complete prompt-to-action chain, and timestamps, closing the audit gap for SOC 2, ISO 27001, and SOX.
- Builds tailored, session-aware policies with Lighthouse, Bay's AI policy-building agent, which learns each team's workflows and risk appetite so enforcement fits from day one, with no baselining period, and adjusts automatically as people change teams. Pre-built templates and IdP-mapped group policies included.
- Enforces in real time on the endpoint: Bay evaluates the full session, not one action at a time, and returns Allow, Ask, or Deny on every agentic tool call locally, in under 4ms, without SIEM lag.
- Connects to your stack through Bay's MCP/API interface: query findings, manage policies, and pull Bay data into your own AI agents, copilots, and workflows.
By combining discovery, posture management, supply chain control, and real-time enforcement, Bay takes security teams from no visibility into agentic activity to full governance and prevention, with dedicated onboarding and customer success support from day one. The result: your organization gets to say yes to AI agents and scale AI adoption without scaling risk.
Highlights
Highlighted by the publisher on AWS Marketplace.
Agentless, full visibility: deploy through your existing MDM or EDR in under 5 minutes and discover every agent, MCP server, extension, package, and skill, plus who runs it and what it can reach
Auto-calibrated policies: Lighthouse learns your workflows, risk appetite, and how each team actually works, so policy fits from day one without weeks of baselining
Runtime enforcement: Bay Enforcer weighs the full session, not one action at a time, and returns Allow, Ask, or Deny on the device in under 4 ms.
Agent build and provenance
See the full provenance
The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.
Plans and pricing as listed
1 listed- Units
Refund terms
As stated by the publisher on AWS Marketplace.
No refunds
Sources
Linked repositories
Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.
Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.

