Conduct is open today. Here's the honest version.
We built Conduct because the problem kept showing up in every conversation with engineering leaders, CTOs, CIOs, and CISOs we know. It works from day one. This is a launch note: what v1 is, what it isn't, and how to try it without committing to anything.

The problem we kept hearing
Every engineering leader, CTO, CIO, and CISO we've spoken to over the last year has said some version of the same thing. AI is already inside their team. Copilot, Cursor, Claude Code, Codex, a dozen MCP servers. and nobody can answer simple questions about it.
Which models are people using? What did the agent change last Tuesday? Did anyone paste a secret into a prompt? Is the SOC 2 control we wrote down actually being enforced, or is it a PDF in a shared drive?
None of this is hypothetical. CISOs are being asked these questions by their boards. Heads of engineering are being asked by their CISOs. The tools that introduced AI into the workflow weren't built to answer them.
That's the gap. Conduct is our attempt to fill it.
“What impressed me most about Conduct AI is that it approaches AI governance as a business capability, not just a technical feature. By bringing together cost management, security controls, and compliance oversight in a scalable architecture, it addresses a need that many enterprises are actively trying to solve.”
What Conduct is (and isn't)
Conduct is an operating layer that sits alongside the AI tools your team already uses. It does three things:
- GovernPolicies that travel with your team into Cursor, Claude Code, Copilot. Enforced at the hook level, not after the fact.
- SecureSecret scanning, prompt-injection checks, audit-grade activity feed. The evidence trail compliance teams have been improvising.
- AutomateYAML playbooks for the work that's already repeated by hand: PR triage, incident response, CI/CD recovery, security review.
What it isn't: a chat product, an IDE replacement, or a new model. It's the layer underneath the things you already pay for, making them visible and accountable.
What's in v1
We've been deliberate about what shipped today versus what we kept on the shelf. v1 is the smallest thing we'd be willing to run our own work on.
| In v1 | Not yet |
|---|---|
| ConductGuard: policy + activity feed | SSO beyond Clerk |
| 30+ starter playbooks (GitHub, Slack, CI/CD, incident) | On-prem / air-gapped install |
| Hook-level telemetry from Claude Code, Cursor, Codex, JetBrains AI Assistant | Self-serve MCP server registry |
| Agent Booster + RTK for cost & context efficiency | Custom compliance pack authoring UI |
| SOC 2, HIPAA, OWASP starter packs | Multi-region deployment |
Everything in the right column has a date or a design behind it. Nothing on this page is a roadmap promise we don't intend to keep.
How to onboard
We tried to make the first session take an afternoon, not a quarter. The shape of it:
- Sign in. Email or Google through Clerk. A workspace is created for you.
- Connect one tool. Claude Code or Cursor is enough. The hook installer is a single command; it takes about a minute.
- Pick a compliance pack or a playbook. SOC 2 if you're in audit mode, the PR-triage playbook if you want a quick visible win.
- Run something real. Watch it in the activity feed. Adjust the policy. Re-run.
That's the loop. If you don't see value by the end of the afternoon, we'd rather know than have you wait three weeks to find out.
Free evaluation, flexible partnerships
We know what it's like to be on the other side of a vendor pitch in the middle of a quarter. So:
- ·60-day free evaluation for any team with more than a handful of engineers. No credit card, no procurement gauntlet.
- ·Design-partner slots for teams that want a say in the next two quarters of roadmap. Reduced pricing in exchange for honest feedback.
- ·Open-source contributors get a workspace free, indefinitely. If you maintain something we depend on, you shouldn't be paying us.
- ·If pricing is the blocker, write to us. We've done unusual deals for teams whose problem we cared about.
Give it a chance?
We're aware there's no shortage of new entrants in this space, and we're not going to claim Conduct is the only answer. What we will say is: the problem is real, the people asking us about it are serious, and we've built something we'd be willing to put under our own production work.
If any of this resembles a problem you have, we'd like to hear from you. An afternoon is a small thing to risk against the chance of getting some of those board-level questions answered.
The Conduct team.
