Every flow.Under your control.
Agentic Cyber Intelligence. Understand every connection. Put your agents to work, with rules you control.

Tap a numbered marker for a closer look.
See the last sixty seconds
Upload and download traffic, together on one timeline. Spot a spike, then find the flow behind it.
Follow a connection all the way down
Expand an application into apps, hostnames, and individual flows. See what the traffic actually belongs to.
Every flow has a pulse
Compare upload, download, recent trends, flow counts, and round-trip time without leaving the live view.
Look at your network your way
Move between your daily briefing, action journal, and live traffic. Explore insights by app, host, or destination.
Not which app opened a socket. What the traffic is.
A carrier-grade packet intelligence engine, 1,400+ signatures, reading a passive copy of your interface. YouTube inside Chrome, a model pull inside a terminal, a miner inside a tab.
A briefing, not a dashboard.
Every day opens with a few sentences that fall out of the numbers: who moved the most, what changed, what is worth a look. Written on your Mac by Apple Intelligence or a local model, in the voice of the persona you pick.
- Seven personas: Gaia for family, Cerberus for security, Kepler for patterns, Seneca for focus, Concord for workplace, Zephyr for traffic, Vesper for privacy
- Traffic by app, direction, and hour
- Ask a follow-up in chat or by voice

Every flow, right now, by name.
The last sixty seconds as a spine, then the tree: application, app, hostname, flow. Up and down rates, trend, flow count, and round-trip time for every row. Reorder the path to read it your way.
- 1,400+ signatures, TLS and QUIC included, nothing decrypted
- Process attribution where macOS allows it
- Click any row for the flow's details, the host's ownership, and its country

Write the rules. Or let your agents handle them.
FlowRuby is FlowSense's policy language. Write rules yourself or let your agents write and manage them for you. Match apps and devices, block unwanted connections, set schedules, and label your own services by hostname.
- Scope rules by app, device, or destination
- Order exceptions, set schedules, and expire temporary rules
- Label your own services by hostname
Match an app and block its connections.
flowruby 1.1
# Check rules in order; stop at the first match.
policy_chain "main" do
position 10
mode :first_match
end
# Block a named app, rather than every connection.
policy "block-youtube" do
chain :main, position: 10
where { app == "YouTube" }
action :drop
endflowruby 1.1
policy_chain "monitoring" do
position 10
mode :match_all
end
# Match traffic without blocking it.
policy "watch-https" do
chain :monitoring, position: 10
where { proto == "tcp" && dst_port == 443 }
action :observe
note "Review HTTPS traffic before adding a block."
endflowruby 1.1
# Give a group of devices a reusable name.
# Replace this example MAC with your device's MAC.
mac_set "kids", members: %w[aa:bb:cc:dd:ee:01]
policy_chain "main" do
position 10
mode :first_match
end
# Both conditions must match: the app AND the device.
policy "kids-video" do
chain :main, position: 10
where {
app.in?(["YouTube", "Netflix"]) &&
subscriber_id.in_set?("kids")
}
action :drop
endflowruby 1.1
# Lower positions run first inside this chain.
policy_chain "main" do
position 10
mode :first_match
end
# Leave this app alone within this chain.
policy "video-exception" do
chain :main, position: 10
where { app == "YouTube" }
action :observe
end
# The exception above wins for YouTube.
policy "block-video" do
chain :main, position: 20
where { app.in?(["YouTube", "Netflix"]) }
action :drop
endflowruby 1.1
policy_chain "main" do
position 10
mode :first_match
end
# A repeating evening rule, Monday through Friday.
policy "evening-video" do
chain :main, position: 10
where { app.in?(["YouTube", "Netflix"]) }
action :drop
# 9 PM to 7 AM; times use the explicit UTC offset.
schedule days: %w[mon tue wed thu fri],
start: "21:00", end: "07:00",
utc_offset: 5
endflowruby 1.1
policy_chain "main" do
position 10
mode :first_match
end
# A one-off rule that expires automatically.
policy "focus-session" do
chain :main, position: 10
where { app == "YouTube" }
action :drop
# Example dates: replace with your own UTC window.
starts_at "2027-01-10T09:00:00Z"
expires_at "2027-01-10T11:00:00Z"
enabled true
note "Two hours of focus; created by your agent."
endflowruby 1.1
# Use an unused customer ID for your own app label.
app "Team Portal" do
id 4097
slug "team-portal"
category "custom"
end
# Relabel matching TLS traffic so policies can name it.
flow_relabel "team-portal-label" do
priority 30
where { app == "tls" && hostname == "portal.example.com" }
set_app "Team Portal"
end
policy_chain "main" do
position 10
mode :first_match
end
policy "watch-team-portal" do
chain :main, position: 10
where { app == "Team Portal" }
action :observe
endLocal models. Connected agents.
Briefings, chat, and voice run on Apple Intelligence or on a model you download from Hugging Face into the app. Local inference runs on your Mac. You can also choose connected agents, which receive conversation context and selected traffic information through their own providers. See our privacy policy for details.
- Model library with one-click download
- Voice conversation with the persona
- Claude, Codex, or any MCP client can ask what is talking to what

Pricing is on its way.
Coming soon
Pricing will be announced when FlowSense is available.