Methodology

How we rate AI tools.

The Northbeams catalogue tracks 10,000+ AI tools and refreshes every morning. Here is how a tool gets seen, and how it gets sorted.

Four surfaces of signal.

In the browser
In-page detection spots chatbots and AI features as they load, tab by tab.
On the desktop
The desktop app watches outbound connections and process names for AI apps on Mac and Windows.
In the terminal
The same app sees coding agents and CLI tools: Cursor, Claude Code, Aider, Cline, Windsurf.
Across MCP
The MCP Gateway sees which servers an agent can reach, and governs each call.
At the network
DNS-layer signals catch AI domains, including newly registered ones, the day they appear.
On the device
Classification runs on the laptop. Only labels, counts, and a hashed snippet leave it.
Three buckets

Sanctioned, unknown, or high-risk.

Every tool lands in one of three buckets so you can set policy fast. You decide what sanctioned means for your team; Northbeams keeps the list current.

  • Sanctioned: tools you have approved for defined teams and uses
  • Unknown: seen in your fleet, no policy set yet
  • High-risk: categories that commonly carry source, secrets, or regulated data, or process where data handling is opaque
Category, not verdict. These profiles describe the category of risk a tool carries, not a judgment of any vendor. Northbeams shows you who uses what, and you set the policy. The public coverage scorecard shows what we catch, misses included.

See your tools, sorted.

One install. Your shadow AI mapped by Monday.

Start your free trial Book a demo