BEHEST GUARD · ON-DEVICE · FOR macOS · EARLY ACCESS
See the AI leaving your Mac.
A local tool that shows you which AI services your Mac is talking to, how much data they're moving, and — from your tools' own logs — what it's costing you. It runs entirely on your machine. No cloud, no account, no telemetry. Open-source, launching soon.
Request early access
We'll email you when Behest Guard is ready, plus occasional product updates. Early testers build from source (macOS + Rust).
By requesting access you agree to our privacy policy.
What is Behest Guard?
Behest Guard is an on-device macOS tool that discovers which AI services your Mac talks to and estimates their token spend from local logs or an optional inspecting proxy. It runs 100% locally — no cloud, no account, no telemetry — the front door to the Behest AI Token FinOps platform.
How Behest Guard works
Three honest capabilities — nothing to route, no keys, no config on your tools.
Discover what's talking to AI.
Guard watches the connections leaving your Mac and names the AI services behind them — per app, per process — with connection counts and data volumes. Nothing to route, no keys, no config on your tools.
See the spend, from your own logs.
For tools that keep local usage logs — Claude Code today — Guard reads the token counts already on your disk and turns them into an estimated cost using published list prices. No interception required.
Want exact numbers? Turn on the local proxy.
Opt in and Guard runs a local inspecting proxy for your AI endpoints only, giving you exact, provider-reported token counts per model and per request. It streams through untouched (about 22 microseconds of overhead on a published benchmark), installs a local certificate, and it's two commands to enable, one to revoke. Off by default.
What Guard doesn't do
The honest scope. We document the gaps rather than paper over them.
It observes; it doesn't enforce.
Behest Guard is observe-only — there are no budgets or blocks. Acting on spend is the enterprise platform's job, below.
One Mac, not a fleet.
Guard runs on a single machine with no backend and no central dashboard. Fleet-wide attribution and governance live in the platform.
Estimates, not your invoice.
Dollar figures from local logs are list-price estimates, not your negotiated billing — a useful signal, not an accounting record.
It can't see everything.
Traffic over QUIC or encrypted DNS, certificate-pinned apps, and AI services it doesn't yet recognize are gaps — we document them rather than paper over them.
One Mac today. Your whole AI bill tomorrow.
Behest Guard is where AI cost control starts — local, on-device, and yours. When you're ready to attribute spend across teams, put budgets and governance on every model call, and act on them in real time, that's the Behest AI Token FinOps platform — the control plane Guard is the front door to.