Build agent controls into your platform
Embed Qpoint into your product to monitor, govern, and secure the agents your customers run, without building the runtime layer yourself
Your product needs an agent layer
Your customers run agents on employee laptops and on Linux servers, and they expect your product to see what those agents do, set rules for them, and stop any actions that break them. So you're deploying an endpoint monitor and building a governance layer for hosted agents. Qpoint already does both, and ships as one binary you can bundle.
What you're building
An agent inventory across employee endpoints and hosted agents, a record of every action, policies that hold at runtime, and evidence your customers can hand to their auditors. All inside your product, under your name.
Why the usual tools fall short
Endpoint agents were built to watch a person. Network tools were built to watch traffic. Cloud security was built to watch apps on a multi-tenant service. None of them recognize an agent, so none of them can say what it accessed or stop it before it acts.
What Qpoint already does
It runs underneath the agent and understands every file read, tool call, and outbound request as an agent action. It audits and decides inline, in real time, on the endpoint and on the host. The same binary, packaged for your product.
Visibility, policy, and enforcement as building blocks
Use the components that your product needs. Each component works on its own, and shares the same binary and the same session model.
Event stream
Structured events for every session: agent, process, file, tool call, request, and token usage. Stream them into your product over gRPC or OTLP.
Plugin hooks
Run code at each decision point to log, tag, rewrite, or block. Use the built-in plugins or configure custom ones tailored to your product.
Policy API
Push rules and policies directly from your product. Qpoint enforces them on every node, per customer or per workspace.
How Qpoint fits into your stack
Add the binary where your agents run, then connect your product to it. Nothing changes inside the agent itself.
// integration.ts · illustrative import { Qpoint } from "@qpoint/sdk"; const qp = new Qpoint({ controlPlane: "https://qpoint.internal:7443" }); // tag each session with your tenant await qp.sessions.label(sessionId, { tenant: "acme", workspace: "ws_812" }); // configure the plugins that apply your policy await qp.plugins.set("acme", [ { name: "audit-log", config: { destination: "siem" } }, { name: "secrets-guard", config: { block: ["~/.ssh/**", "**/.env"] } }, ]); // stream events into your audit log for await (const ev of qp.events.subscribe({ tenant: "acme" })) { auditLog.write(ev); }
Common questions
The particulars depend on what you're building. These are the questions that come up first.
Can we white-label it?
Yes. The binary, the service, and every user-facing string take your name. Nothing in your product indicates a third-party component.
How is it licensed?
Under a commercial partner license written for bundling. You sign and notarize the binary with your own certificates and distribute it with your product.
Where does the data go?
The Qpoint binary runs in your infrastructure, and events go only to the destinations you configure. None of it reaches Qpoint.
Do we change our agent?
No. Qpoint runs underneath the agent, at the OS level. You add the binary to your image and connect to the API.
What does support look like?
Early partners work directly with our engineering team, from the first integration through launch.
How do we get started?
Talk to us. We'll walk through your product and scope the integration together. Contact us
Run Qpoint wherever your agents run
Laptops, servers, and other people's products. One binary, one event stream, deployed where the agents are.
Seconds, not sprints
Qpoint deploys as a single binary directly on the endpoint. No gateways to route through, no enterprise infrastructure to provision, no SDK integration to schedule.
Install, run, and start seeing every AI agent on the machine — in under a minute.