For regulated organisations

Run the open-source core,or let Attri run all of it for you.

The REST API and MCP server are open source for anyone to run. The full product, with device collection, Anthropic API sync, the dashboard, Teams, anomaly detection and privacy tickets, is deployed and operated by Attri inside your own cloud account.

  • 01

    In your cloud account

    Deployed in your subscription, with your data in your database.

  • 02

    Microsoft Entra sign-in

    Single sign-on, with people and admins kept separate.

  • 03

    Operated by Attri

    Attri states it holds SOC 2 Type II and offers a HIPAA BAA.

Deployment options

What each option includes.

Everything marked for an Attri deployment runs in production today. Nothing here is on a roadmap.

CapabilityOpen sourceAttri deployment
REST API and MCP serverYes · 23 endpoints, 14 toolsYes · with Entra sign-in and a ticket tool
Collects your organisation's dataNo · sample data onlyYes
Claude Desktop and Cowork collectorNoYes · macOS and Windows
Compliance API and Analytics API syncNoYes
DashboardNoYes
Microsoft Teams appNoYes
Anomaly detection and policy checksNoYes · daily
Privacy request ticketsNoYes · with Attri carrying them out
Sign-inNone built inMicrosoft Entra single sign-on
DatabaseSQLitePostgres
Where it runsYour machine or containerYour cloud account · Azure today
Who operates itYouAttri

The open-source repository is licensed under Apache 2.0. An Attri deployment is delivered as an engagement.

How an engagement runs.

  1. Scope

    Agree which Claude surfaces, machines and Microsoft tenant are in scope, and who your admins are.

  2. Deploy in your cloud

    Attri stands up the backend, Postgres database, Entra app registration and Teams app in your cloud account.

  3. Roll out and operate

    The collector goes out to laptops, the Anthropic syncs start, and Attri runs scans and carries out privacy requests.

Security model

Read-only, attributedand kept in your account.

  • Entra sign-in and roles

    People see their own activity. Admins see the organisation, enforced in the API and the database.

  • Secrets redacted on the device

    API keys, private keys, tokens and password values are removed before upload.

  • Encrypted uploads

    Each upload from a laptop is encrypted with AES-256-GCM and sent over HTTPS.

  • Read-only by design

    OpenWatch reads Claude's data. It never writes to Claude or blocks anyone.

  • Append-only evidence

    Ticket events, citations and AI policy versions are kept, not overwritten.

  • Documents by reference

    Files are recorded by name, path and size. Contents stay on the device.

Operated by Attri.

Attri is an AI consulting and engineering firm for regulated enterprises. These are Attri's own statements; read the details in its trust center.

  • SOC 2 Type II

    Stated by Attri on attri.ai.

  • HIPAA, BAA available

    Stated by Attri on attri.ai.

  • Trust center

    Policies, terms and security details.

    Visit

Procurement questions

What licence is the open-source code under?

Apache 2.0, which includes an explicit patent grant.

Which cloud providers do you deploy to?

Microsoft Azure today. If you run on AWS or Google Cloud, talk to Attri about your environment.

Which identity providers are supported?

Microsoft Entra ID. Okta, SAML and SCIM aren't supported yet.

Can one deployment serve several business units?

A deployment is tied to one Microsoft tenant. Within it, people see their own activity and admins see everyone's.

Who carries out access and erasure requests?

OpenWatch tracks them as tickets with deadlines and citations. Attri's managed-service team carries out the export or deletion.

What happens to our data if we stop?

It lives in the Postgres database inside your cloud account, so it stays with you.

Someone will ask what happened.Have the answer ready.

Run OpenWatch on sample data in minutes, or have Attri deploy it inside your cloud with live data from your organisation.