Proov / Scanner and Evidence Collection

Find what is running before it becomes risk.

Proov scans local machines, repositories, CI runners, servers, and MCP gateways for AI execution artifacts. It produces reviewable evidence that can stand alone or move into Vettd.

Proov · The scanner

From “we think we have agents” to a signed bundle in 12 minutes.

Proov runs where your agents already live — laptops, CI runners, server hosts, MCP gateways. It catalogues what's real, flags what's risky, and emits a tamper-evident bundle your auditor will recognize.

  • No agents talked to OpenAI by mistake. Egress and credential map, by host.
  • MCP-aware. Walks tools, scopes, and prompt configs — not just process lists.
  • Signed evidence bundles. SHA-256, optional org key, no PII leaves the host.
What Proov sees

A current-state assessment without a platform rollout first.

Use Proov at the start of a pilot, during vendor review, or before an audit. The scanner keeps raw evidence local and emits a compact bundle for review.

01 / SIGNAL

Local agent artifacts and prompt files

The output is designed for security, governance, and engineering reviewers who need to understand what is real before they approve more access.

02 / SIGNAL

MCP server registrations and tool scopes

The output is designed for security, governance, and engineering reviewers who need to understand what is real before they approve more access.

03 / SIGNAL

Over-broad credentials and risky egress

The output is designed for security, governance, and engineering reviewers who need to understand what is real before they approve more access.

04 / SIGNAL

Signed evidence bundles for Vettd review

The output is designed for security, governance, and engineering reviewers who need to understand what is real before they approve more access.

Downloads

Single binary, no service dependency.

Proov runs standalone on macOS, Linux, and Windows. Get the binary for your platform and start collecting evidence immediately.