
Endpoint AI observability: see every AI agent, trace its work, track AI spend.

Endpoint AI observability: see every AI agent, trace its work, track AI spend.
The Entire Cybersecurity Market, One Prompt Away
Connect your AI assistant to ... tools and ... vendors. Ask anything about the cybersecurity market.
Origin Technology builds an endpoint AI observability platform. A light user-mode sensor runs on employee laptops and records what AI agents do there, such as Claude Code, Cursor, Codex, Copilot, local models and MCP servers. Origin keeps an inventory of every agent, model and MCP server on the fleet, including personal and unapproved ones. It ties each one to a person through Microsoft Entra and other identity providers. It rebuilds each session as a trace, from the first prompt through every tool call, file read, command, network request and outcome. On top of that record, Origin flags risky activity: credential material in prompts, sensitive file reads, unexpected egress, destructive commands, sandbox escape requests, unapproved models and poisoned tool descriptions. It also groups AI work by team and project and tracks token spend and cost per workflow. Buyers are CISOs, for AI governance, and CIOs, for AI adoption and spend. The company was founded as Prelude Security (incorporated as Prelude Research, Inc.), which sold security control validation, continuous control monitoring and an endpoint memory-protection agent. On 2026-07-27 it renamed itself Origin and moved the whole company to Origin. Prelude customers are supported until their current contracts end. Investors include Sequoia Capital, Insight Partners and Brightmind Partners, which led an additional $16M in September 2025. The team comes from Elastic, SpecterOps, Tanium and Microsoft.