Network monitoring
The Endpoint Agent's network monitor is a local proxy that inspects AI traffic leaving the device. It decrypts HTTPS with a locally trusted certificate, runs DLP on requests and responses, and allows, blocks, or asks the user to justify each request.
Components
The network monitor installs with the agent. See Requirements for the certificate trust and driver prerequisites.
Interception modes
To point an app at the explicit proxy, set the proxy variables in its environment:
export HTTPS_PROXY=http://localhost:8443
export HTTP_PROXY=http://localhost:8080
Transparent redirection is turned on from the QuilrAI dashboard; configuration reaches the agent in real time.
DLP settings
Policy changes reach agents in real time; no restart is needed. App-level policies are set in App policies.
How a request is processed
Each request is attributed to the process that made it (audit tokens on macOS, socket-layer events on Windows), so findings show which app sent the data.
Health and observability
- Every request is logged with host, process, DLP findings, and the action taken.
- Each host has a health state (Healthy, Degraded, Unhealthy, Critical) with circuit breakers driven by passive failure tracking and active probes.
- The proxy exposes
GET /health(JSON) andGET /metrics(Prometheus) locally. - A remote kill switch can disable the proxy. New connections then get HTTP 503 while in-flight requests finish. See Agent kill switch.
DLP findings and enforcement outcomes appear in Findings and interactions.