# Gensee > Gensee protects what AI agents access, execute, and change. Its enterprise product, Gensee Crate Enterprise, is the safety and security control plane for autonomous AI. Gensee Personal supports individual developers with isolated workspaces for delegated coding tasks. ## Gensee Crate Enterprise Page: https://www.gensee.ai/ Architecture: https://www.gensee.ai/#architecture Customer scenarios: https://www.gensee.ai/use-cases.html Product FAQ: https://www.gensee.ai/crate-faq.html The platform direction brings task identity and authority, system-level execution controls, code/package/tool inspection, repair and independent validation, application-effect controls, delegation and lineage, connected evidence, containment, supported recovery, and enterprise administration together. The central principle is continuity of control: restrictions should persist as a task moves from tool calls to generated code, package installation, subprocesses, delegated agents, and supported application changes. A scanner verdict supplies evidence, not permission to take a business action. Approval applies to the actual artifact and its relevant dependencies. Delegation does not multiply the original task's authority. Customers include operations/support, analytics, finance, and engineering teams with agents already performing consequential work. The homepage explains protection generally: scope access, inspect and repair artifacts, constrain execution and delegation, then validate outputs and govern business actions. Customer scenarios include a support agent handling a refund request within defined customer, operation, and amount limits. Employee benefit: preauthorized work proceeds inside reusable boundaries, with fewer unnecessary interruptions and safer alternatives when possible. Security benefit: tiered screening, task context, correlated findings, and focused human review. Model confidence alone does not justify discarding high-risk evidence. The architecture describes platform direction, not universal release coverage. Coverage must be scoped by OS, harness, runtime, application integration, and execution path. Inaccessible vendor-hosted execution needs an accessible integration or resource-side control. Local recovery cannot undo sent messages, remote transactions, or disclosed data. The console walkthrough uses the actual console and synthetic source reports and employee responses. It demonstrates investigation, not verified preventive blocking across every proposed platform layer. ## Supported harnesses and deployment Gensee Crate Enterprise supports Claude Code, Codex, Claude Cowork, ChatGPT Work, Cursor, VS Code Copilot, Antigravity, Omnigent, and Databricks Agent Bricks. Available protections depend on the harness, operating system, and application connectors. Deployment supports Mac (macOS), Windows, and Linux, on endpoints and in cloud environments. Endpoint control governs local files, commands, and tools. Cloud agent control constrains cloud agents, processes, and delegated work. Central control combines policy management, activity logs, and investigation in one dashboard. Compatibility: https://www.gensee.ai/#compatibility Deployment: https://www.gensee.ai/#deployment-title ## Agent Detection and Response (ADR) ADR focuses on detecting and responding to risky AI agent behavior. Gensee connects agent activity with task context, policy, and evidence for investigation and response. Execution controls add prevention at supported boundaries; recovery applies only to supported local state. Homepage answer: https://www.gensee.ai/#adr-faq Guide: https://www.gensee.ai/blogs/ai-agent-security-and-adr.html ## Existing benchmark evidence Results: https://www.gensee.ai/#benchmarks AgentCanary preliminary internal defense rates (baseline → Gensee): memory poisoning 75.0% → 93.8%; long-horizon tasks 65.4% → 100.0%; prompt injection 77.8% → 93.5%. Internal adapted harness, not official leaderboard results. ADR-Bench recall: 73.8% → 92.9%; false-positive rate: 13.8% → 11.5%; accuracy: 84.5% → 89.1%. The baseline is the recorded internal configuration, not Uber's production system. Reported runtime overhead: 0.6%–1.2%, 10–400 ms/request. These are configuration-specific results, not guarantees for all deployments. ## Research, backing, and design partners Gensee was co-founded by UC San Diego professor Yiying Zhang and former Google engineering leader Shengqi Zhu. It is backed by Two Small Fish Ventures. Its design partners include Databricks (Omnigent), Uber (ADR), and Eigent AI (CAMEL-AI); design partnerships do not imply paying-customer relationships. - Research roots: https://cseweb.ucsd.edu/~yiying/ - Investment announcement: https://twosmallfish.vc/why-we-invested-in-genseeai - Omnigent integration: https://github.com/omnigent-ai/omnigent/releases/tag/v0.14.0 - ADR contribution: https://github.com/uber/ADR/pull/44 - Eigent AI and CAMEL-AI: https://www.eigent.ai/about ## Personal Gensee Personal offers isolated workspaces for individual developers delegating coding tasks. Developers can explore, revise, merge, or discard supported local changes. Page: https://www.gensee.ai/crate-personal.html ## Links - Contact: https://www.gensee.ai/contact.html - About: https://www.gensee.ai/about.html - Research and blog: https://www.gensee.ai/blog.html - Personal/cloud help: https://www.gensee.ai/faq.html Legacy /defense-for-ai.html, /ai-for-defense.html, and /crate-enterprise.html now redirect to the unified enterprise homepage. ## Use Cases articles Full-length, illustrative guides to workflow boundaries and evaluation. These are not customer incident reports or measured deployment results. Category: https://www.gensee.ai/blog.html?category=use-cases - Legal AI Citation Verification: Finding a Case Is Only the First Step: https://www.gensee.ai/blogs/legal-ai-citation-verification.html - AI Agents in Finance: Reconcile the Invoice Without Changing the Payee: https://www.gensee.ai/blogs/finance-ai-agents-invoice-reconciliation.html - Agent Detection and Response for Customer Support: From Order Tracking to Refunds: https://www.gensee.ai/blogs/customer-support-agent-detection-response.html - One AI Assistant, Two Contexts: Keeping Company Data Out of Personal Projects: https://www.gensee.ai/blogs/ai-assistants-work-personal-data-boundaries.html - When an AI Agent Changes a Production Schedule: Controlling Manufacturing Workflows: https://www.gensee.ai/blogs/manufacturing-ai-agent-workflow-security.html - AI-Powered Onboarding Without Overexposing Employee Data: https://www.gensee.ai/blogs/hr-ai-agent-onboarding-data-security.html - When a Sales Agent Turns a Draft Into a Commitment: https://www.gensee.ai/blogs/sales-ai-agents-proposals-crm-security.html - Securing Healthcare Scheduling Agents: Patient Context, Permissions, and Messages: https://www.gensee.ai/blogs/healthcare-scheduling-ai-agent-security.html - Five Days, One Data Leak: Company Notes to Personal WhatsApp: https://www.gensee.ai/blogs/company-notes-obsidian-personal-whatsapp-ai-risk.html ## Education & Learning guides Category: https://www.gensee.ai/blog.html?category=education-learning - Agent Detection and Response (ADR): A Practical Guide: https://www.gensee.ai/blogs/agent-detection-and-response-guide.html - AI Agent Runtime Monitoring: A SOC Operations Guide: https://www.gensee.ai/blogs/ai-agent-runtime-monitoring.html - AI Agent Runtime Policy Design: A Practical Guide: https://www.gensee.ai/blogs/ai-agent-runtime-policy-design.html - AI Agent Runtime Security: The Systems Guide: https://www.gensee.ai/blogs/ai-agent-runtime-security-systems-guide.html - AI Agent Runtime Tracing: What It Is and Why It Matters: https://www.gensee.ai/blogs/ai-agent-runtime-tracing.html - AI Agent Security Vendors Compared by Defense Layer: https://www.gensee.ai/blogs/ai-agent-security-vendors-compared.html - AI Coding Agent Evaluation Framework for Enterprises: https://www.gensee.ai/blogs/ai-coding-agent-evaluation-framework.html - Auditing MCP Tool Calls: What to Record and Why: https://www.gensee.ai/blogs/auditing-mcp-tool-calls.html - What Claude Code Can Reach on a Developer Laptop: https://www.gensee.ai/blogs/claude-code-laptop-access.html - Claude Code Security Guide: Permissions, Sandbox, and Evidence: https://www.gensee.ai/blogs/claude-code-security-guide.html - Codex Security: What It Scans and Where It Stops: https://www.gensee.ai/blogs/codex-security-appsec-runtime-scope.html - Cursor Security for Enterprise AI IDEs: https://www.gensee.ai/blogs/cursor-security-enterprise-ai-ides.html - Cursor vs Codex Security: A Date-Stamped Comparison: https://www.gensee.ai/blogs/cursor-vs-codex-security.html - Enterprise AI Agent Runtime Security Checklist: https://www.gensee.ai/blogs/enterprise-runtime-security-checklist.html - Enterprise Security for Coding Agents: https://www.gensee.ai/blogs/enterprise-security-coding-agents.html - MCP Permission Design: Scoping Tools the Right Way: https://www.gensee.ai/blogs/mcp-permission-design.html - MCP Security Best Practices for Coding Agents: https://www.gensee.ai/blogs/mcp-security-best-practices.html - Observe, Warn, Block: Choosing Enforcement Modes: https://www.gensee.ai/blogs/observe-warn-block-enforcement-modes.html - Runtime Defense for AI Coding Agents: What It Takes: https://www.gensee.ai/blogs/runtime-defense-ai-coding-agents.html - Runtime Forensics for AI Coding Agents Explained: https://www.gensee.ai/blogs/runtime-forensics-ai-coding-agents.html - Runtime Security Benchmark for Coding Agents: A Methodology: https://www.gensee.ai/blogs/runtime-security-benchmark-coding-agents.html - Runtime Security vs PR Review: Closing the Coverage Gap: https://www.gensee.ai/blogs/runtime-security-vs-pr-review.html - Runtime Security vs Sandboxing for AI Coding Agents: https://www.gensee.ai/blogs/runtime-security-vs-sandboxing.html - Runtime Tracing: Processes, Files, Network, Effects: https://www.gensee.ai/blogs/runtime-tracing-processes-files-network-effects.html - Sidecar Architecture for Agent Runtime Security: https://www.gensee.ai/blogs/sidecar-architecture-agent-runtime-security.html - How to Build a Threat Model for AI Coding Agents: https://www.gensee.ai/blogs/threat-model-ai-coding-agents.html