Solution: Embedded

Build agent controls into your platform

Embed Qpoint into your product to monitor, govern, and secure the agents your customers run, without building the runtime layer yourself

✓Single binary✓Event stream✓Plugin hooks✓Policy API
Why embed Qpoint

Your product needs an agent layer

Your customers run agents on employee laptops and on Linux servers, and they expect your product to see what those agents do, set rules for them, and stop any actions that break them. So you're deploying an endpoint monitor and building a governance layer for hosted agents. Qpoint already does both, and ships as one binary you can bundle.

What you're building

An agent inventory across employee endpoints and hosted agents, a record of every action, policies that hold at runtime, and evidence your customers can hand to their auditors. All inside your product, under your name.

Why the usual tools fall short

Endpoint agents were built to watch a person. Network tools were built to watch traffic. Cloud security was built to watch apps on a multi-tenant service. None of them recognize an agent, so none of them can say what it accessed or stop it before it acts.

What Qpoint already does

It runs underneath the agent and understands every file read, tool call, and outbound request as an agent action. It audits and decides inline, in real time, on the endpoint and on the host. The same binary, packaged for your product.

How it works

Visibility, policy, and enforcement as building blocks

Use the components that your product needs. Each component works on its own, and shares the same binary and the same session model.

Event stream

Structured events for every session: agent, process, file, tool call, request, and token usage. Stream them into your product over gRPC or OTLP.

session.startfile.readtool.callhttp.request

Plugin hooks

Run code at each decision point to log, tag, rewrite, or block. Use the built-in plugins or configure custom ones tailored to your product.

on_file_readon_tool_callon_request

Policy API

Push rules and policies directly from your product. Qpoint enforces them on every node, per customer or per workspace.

PUT /v1/policies/{tenant}
Integration

How Qpoint fits into your stack

Add the binary where your agents run, then connect your product to it. Nothing changes inside the agent itself.

Package. Bundle the Qpoint binary into your sensor or agent deployed to endpoints or hosts.
Identify. Tag each session with tenant and workspace identifiers so every event maps to a customer.
Configure. Apply your policies and security model with built-in or custom plugins.
Run. Start Qpoint, subscribe to the event stream, and forward events to your SIEM or control plane.
// integration.ts · illustrative
import { Qpoint } from "@qpoint/sdk";

const qp = new Qpoint({ controlPlane: "https://qpoint.internal:7443" });

// tag each session with your tenant
await qp.sessions.label(sessionId, {
  tenant: "acme", workspace: "ws_812"
});

// configure the plugins that apply your policy
await qp.plugins.set("acme", [
  { name: "audit-log",     config: { destination: "siem" } },
  { name: "secrets-guard", config: { block: ["~/.ssh/**", "**/.env"] } },
]);

// stream events into your audit log
for await (const ev of qp.events.subscribe({ tenant: "acme" })) {
  auditLog.write(ev);
}
Partnering

Common questions

The particulars depend on what you're building. These are the questions that come up first.

Can we white-label it?

Yes. The binary, the service, and every user-facing string take your name. Nothing in your product indicates a third-party component.

How is it licensed?

Under a commercial partner license written for bundling. You sign and notarize the binary with your own certificates and distribute it with your product.

Where does the data go?

The Qpoint binary runs in your infrastructure, and events go only to the destinations you configure. None of it reaches Qpoint.

Do we change our agent?

No. Qpoint runs underneath the agent, at the OS level. You add the binary to your image and connect to the API.

What does support look like?

Early partners work directly with our engineering team, from the first integration through launch.

How do we get started?

Talk to us. We'll walk through your product and scope the integration together. Contact us

Solutions

Run Qpoint wherever your agents run

Laptops, servers, and other people's products. One binary, one event stream, deployed where the agents are.

Get Started

Seconds, not sprints

Qpoint deploys as a single binary directly on the endpoint. No gateways to route through, no enterprise infrastructure to provision, no SDK integration to schedule.

Install, run, and start seeing every AI agent on the machine — in under a minute.

$ curl -fsSL qpoint.io/install | sh