Blog

Powering Every Builder with Security Context: Pi Integrates with Claude’s Compliance API

Pi now integrates with Claude’s Compliance API for a complete record of Claude Code sessions across your organization. And through Sloane, Pi’s agent running natively in the session, your organization’s security context reaches the coding agent while decisions are still being made, not after they reach review.

Claude and Pi logos side by side, separated by a vertical rule, on a soft blue gradient

In brief

  • Pi now connects to Claude’s Compliance API, for a complete record of Claude Code sessions across your organization, not just the ones from developers who installed Pi.
  • Through Sloane, Pi’s agent running natively in the session, your team’s gates reach the coding agent while decisions are still being made, not in a review days later.
  • Session by session, Pi shows which gates fired, whether the agent followed them, and where a developer chose otherwise and why.
  • Pi reads only Claude Code sessions and your organization’s user list, never Claude chats, projects, or files.

Most of the security decisions in AI-written code are made in the first few minutes of a task, by an agent, with nobody watching.

That has always been the cheap moment to get something right. Every hour after it, the fix costs more and the people who could have made it are further away. Coding agents have compressed that moment to almost nothing. A developer describes a task; the agent reads the repo, picks the libraries, touches the sensitive code, and pushes. By the time a pull request appears, a hundred small decisions have been made and the agent has moved on.

Security sees the PR. It does not see how the PR came to exist.

Today, we’re announcing Pi’s integration with Claude’s Compliance API, giving Pi a complete record of Claude Code sessions across your organization and bringing your security team’s context into those sessions through Sloane, while decisions are still being made.

The rearview mirror problem

The industry’s answer so far is visibility: collect the sessions, build the dashboard, flag the risky ones. Pi does that too. But visibility alone is a rearview mirror. By the time it shows you the wrong turn, the agent has taken a hundred more and no one was there to argue.

Pi works where the turn is made. Your security team sets gates that define which code deserves a pause and what the agent should know before it continues. That might be the security playbook for a sensitive part of the system, advisory data on a dependency, an existing ticket that should be attached, or a reviewer who should be offered a look. Sloane carries those gates into every Claude Code session, and when one matches, the agent gets the context it was missing and keeps going. The developer is asked only when a decision needs a human. Nothing is blocked, nothing is proxied, and nothing sits between the developer and Claude.

Picture it. An agent reaches for a rendering library with a known vulnerability. Before the change lands, it learns which version is safe and which library the team already approved, and switches. A few minutes later it edits authentication code, and the developer is asked to confirm and link the ticket. By the time the pull request is opened, those security decisions have already been addressed.

One session, start to finish: two concerns raised at design, fixed as the code was written, verified, and merged 14 minutes later.

Visibility shows you what the agent built. Pi gives the agent the security context to make better decisions as it builds, and proves it.

What developers gain

Security context arrives inside the tool developers already use, at the moment it is useful. Not a separate dashboard to check. Not a PR comment three days later asking why the ticket is missing, why that version was chosen, or why the pattern differs from the one the team settled on last year. Those questions get answered while the change is being written, mostly by the agent, using your organization’s own playbooks, advisory data, and review process.

Fewer surprises at the pull request. Less rework after it. And developers can see what is recorded about their work.

What security teams gain

The whole picture. Claude’s Compliance API hands Pi every Claude Code session in your organization, not just the ones from developers who installed something.

Proof your controls were applied. Session by session, Pi shows which gates fired, whether the agent followed them, and where a developer chose otherwise and why.

How early each flaw was handled: of 96 flaws across 1,244 sessions, 46 were caught at planning, 33 were fixed inside the session, and 17 had a fix ready before merge.

Evidence, not just policy. When an auditor asks how AI-written code is governed, you show them what was asked, what was built, and who decided what, with nothing reconstructed after the fact.

Scoped on purpose

Pi reads only Claude Code sessions and your organization’s user list, never Claude chats, projects, or files. The Compliance API can delete data; Pi never does. Session content is held only long enough to build the record. What remains is the evidence itself.

Why it matters

Every other security control your organization owns was built for a world where a person wrote the code and a person could be asked about it. Coding agents broke that assumption. Security teams now have a choice: watch the agent from a distance, or be in the room when it decides. Pi and Claude’s Compliance API together make the second one possible: guidance while the code is written, and a record you can stand behind afterward.

Get started

Pi’s integration with Claude’s Compliance API is available now for Claude Enterprise organizations. If your developers build with Claude Code, Pi puts your security team’s judgment into the first few minutes of every task, and hands them the record of everything that followed.

Powering Every Builder with Security Context: Pi Integrates with Claude’s Compliance API
All Posts
Partners

Powering Every Builder with Security Context: Pi Integrates with Claude’s Compliance API

Pi now integrates with Claude’s Compliance API for a complete record of Claude Code sessions across your organization. And through Sloane, Pi’s agent running natively in the session, your organization’s security context reaches the coding agent while decisions are still being made, not after they reach review.

Yoni Ramon
Yoni Ramon
CPO, Co-founder
Share this post
Table of contents
Overview