
Flint AI
Flint AI is a free AgentOps suite from SandboxAQ: Flint AI CLI scans Python agent code and runs adversarial evaluations, while Switch puts people and agents in shared Slack, Teams, Discord, Mattermost or Telegram rooms.
What is Flint AI?
Flint AI is a family of three products published by SandboxAQ, whose legal entity is SB Technology, Inc. The publisher positions it as an AgentOps platform built on one idea, stated on its About page: agents should earn trust through evidence, not promises.
Flint AI CLI is live and free. It installs with pip install flintai-cli and exposes two commands. flintai scan reads an agent's Python source in three layers - file discovery, static analysis with bandit, opengrep, detect-secrets and pip-audit, then AI reasoning - and triages false positives. It looks for misconfigurations, risky tool access and missing guardrails, maps findings to OWASP ASI01-ASI10, scores them with CVSS v4 and produces a reliability score per agent. flintai eval sends functional and adversarial prompts (prompt injection, jailbreak, off-topic) to the running agent and grades the answers from 0.0 to 1.0; because it tests the service rather than the code, a generic HTTP adapter takes it beyond the recognized frameworks - Google ADK, Google GenAI, the Anthropic and OpenAI SDKs, OpenAI Agents SDK, LangGraph, CrewAI, AutoGen, HuggingFace Transformers and smolagents. Prerequisites are Python 3.11+ and an LLM API key from OpenAI, Anthropic or Google Gemini.
Switch is also live, free and open source. It creates a shared room where people and agents work together, so context, decisions and work history survive handoffs. It connects to Slack, Microsoft Teams, Discord, Mattermost and Telegram, and an existing channel can be turned into a room. Switch Console, a desktop application for macOS, Windows and Linux distributed through GitHub releases, installs and drives the server and the agent connectors; the internals are documented, from the Matrix substrate and collaboration bridge to the agent protocol, local runtime and permission model.
Flint AI Platform is announced as coming soon, behind an early-access waitlist: agent discovery through a GitHub Action, Python and TypeScript SDKs routing LLM traffic, runtime guardrails, auto-fix pull requests, CI/CD integration, a dashboard and a documented HTTP API.
The whole thing is very young: the domain was registered on 15 June 2026 and first archived on 24 June 2026.
What it does
- Scan an agent's Python source code for security risks and automatically triage the false positives
- Run adversarial evaluations - prompt injection, jailbreak, instruction adherence, factual accuracy - and obtain a 0.0 to 1.0 score
- Map findings to OWASP ASI01-ASI10 and score them with CVSS v4
- Put people and agents in one shared room on Slack, Microsoft Teams, Discord, Mattermost or Telegram
- Install Switch Console to connect an agent without writing a connector
- Wire the scan into a CI/CD pipeline
- Estimate the economic value of your agents with the browser-side ROI calculator
When to use Flint AI / When not to
A quick filter to help you decide if Flint AI is the right fit.
When to use Flint AI
- Python developers who must prove an agent is safe before shipping it to production
- Security and AppSec teams that want findings mapped to OWASP ASI and scored with CVSS v4
- Teams running several agents and losing context, decisions and history at every handoff
- Engineering organizations that refuse vendor lock-in and want a framework- and model-agnostic toolchain
- Zero-budget teams: both live products are free and you only bring your own LLM API key
When not to use Flint AI
- Teams whose agents are not written in Python: the static scan only recognizes Python frameworks
- Buyers who need a paid plan, an SLA or contractual support: the live products are free and delivered AS IS (EULA section 8)
- Organizations that cannot self-host: Switch requires running your own server and holding admin rights on the messaging platform
- Teams that need the hosted side today: runtime guardrails, auto-fix pull requests and the dashboard belong to Flint AI Platform, still announced as coming soon and not publicly open
- Non-technical or mobile-first users: everything runs through a terminal, a server or a chat connector, with no no-code interface and no mobile app
How to use Flint AI
A typical end-to-end flow, from setup to results.
- Install the CLI with pip install flintai-cli, on Python 3.11 or newer
- Run flintai init to create ~/.flintai/.env, then add your LLM provider key and the GENERATOR_MODEL variable
- Run flintai scan on the agent repository and read the report: findings, severities, OWASP ASI mapping and CVSS scores
- Run flintai eval against the running agent, using an evaluation configuration file
- Wire the command into your pipeline with the CI/CD integration guide; the quickstart claims first install to first scan in less than 10 minutes
- For Switch, install Switch Console from the .dmg, .exe, .AppImage or .deb build
- Add a server - either started by the Console or an existing one - then configure the agent providers and check that they reach Switch
- Onboard your agents, then create a room or convert an existing channel, and pick a connector: Slack, Microsoft Teams (the only one that requires Switch to be publicly reachable), Discord, Mattermost (one bot account per agent) or Telegram
- Run a smoke test with one human, one agent and one task, addressing the agent by mention inside the room
- For the announced Platform, take the workspace API key from Settings then Data sources, add the GitHub Action for discovery and wrap the Python or TypeScript SDK around your LLM clients; a free 20-minute live onboarding runs every Wednesday
Pros & Cons
Pros
- Free with no usage limits on both live products
- Local-first CLI: no backend, no account system, source code stays on your machine
- Framework- and model-agnostic, with the customer's own LLM API key
- Findings tied to recognized references: OWASP ASI and CVSS v4
- Dense documentation, including product internals and a machine-readable llms.txt
- DPA, data-handling page and subprocessor list published without an account
- Open source / source-available code on GitHub, with a Discord server, a subreddit and a free weekly live onboarding with the engineering team
Cons
- Flint AI Platform - the part carrying runtime guardrails, auto-fix pull requests and the dashboard - is not open yet
- The static scan covers Python only
- Indirect cost: you must bring your own LLM key and pay that provider for the calls
- Switch requires self-hosting a server and admin rights on the messaging platform, and Microsoft Teams demands public exposure of the server
- No published price and no pricing page, so the Platform's business model remains unknown
- Legal documents are pooled at SandboxAQ group level, with no Flint AI legal notice and no postal address published anywhere
- SOC 2 Type II and ISO 27001 are only being pursued, not obtained, on a product whose domain dates from June 2026 and whose maturity is still to be established
Pricing & Plans
Both live products are free. Flint AI CLI is free with no usage limits and no trial period, and Switch is free, open source and self-hosted from GitHub releases, so there is no entry price, no minimum-seat tier and no free plan to convert. Flint AI Platform is announced as coming soon with no published price, reachable only through an early-access waitlist, and the site carries no pricing page at all (full 12-URL sitemap verified). One indirect cost must be stated: the user supplies their own LLM API key and pays that provider for the calls the CLI makes; the publisher notes that Gemini 2.5 Flash has a free tier. No promotion, discount code or struck-through price is published.
- live - free
- no usage limits
- bring your own LLM API key
- live - free
- open source
- self-hosted
- announced as coming soon - early access by waitlist
- no published price
Data, GDPR & hosting
A consolidated view of how Flint AI handles your data.
GDPR overview
GDPR implementation is documented in concrete terms. A Data Processing Addendum, last updated 9 July 2026, is published in the documentation and readable without an account; it invokes Article 28 and sets explicit roles - customer as Controller, SandboxAQ as Processor. Transfers outside the EEA rely on the 2021 Standard Contractual Clauses, module 2, with a UK IDTA addendum. Personal data breaches are notified within 72 hours. Subprocessor changes are announced 30 days ahead, with 15 days to object. Customers may audit once a year, on 30 days' notice and at their own cost, or accept third-party reports instead. Access, rectification, erasure, restriction, portability and objection rights are listed and exercised at privacy@sandboxaq.com, with personal data deleted within 30 days of termination. Two gaps: no Article 27 EU representative is designated and no DPO is named. The privacy notice is the group's, issued by SB Technology, Inc. d/b/a SandboxAQ.
Who owns the data?
Under the SandboxAQ EULA (section 7c), the licensee retains all intellectual property rights in the Customer Data it uploads or inputs and in the outputs the software generates for it; Usage Data is the stated exception. SandboxAQ receives a non-exclusive, worldwide, royalty-free, sublicensable and transferable license, limited to the License Period and to the sole purpose of providing the software. In the DPA, the customer is Controller and SandboxAQ is Processor. For the CLI, the publisher states there is no backend, no telemetry server and no account system: source code never leaves the machine. On exit, an export can be requested in writing within 30 days, followed by a deletion certificate on request.
Reuse rights
The licensee owns the outputs and may reuse them without asking permission, within the EULA's use restrictions and its ban on Prohibited Data (secrets, health data, payment cards, identity numbers, GDPR special categories). On the publisher's side, Flint AI Platform collects names, emails and user IDs, encrypted API keys, session tokens, repository metadata, code snippets (typically 100-500 characters), commit information, agent prompts, LLM responses, model identifiers, guardrail violations, IP addresses, session IDs and trace IDs; the publisher states it never captures whole source files, only snippets showing where agents are used. EULA section 7(b) lets SandboxAQ keep anonymized Usage Data in perpetuity to develop, maintain and improve its products and services. With the CLI, file discovery, static analysis (bandit, opengrep, detect-secrets, pip-audit) and the PII, secrets, toxicity and Garak detectors all run locally; only what is sent to the configured LLM provider leaves the machine - code snippets, import chains, file contents, findings with their context, adversarial prompts and the responses to be judged. Anonymous CLI telemetry is opt-in, asked at first launch, and never includes code, file paths, prompts, model responses, findings or API keys. Nothing published states whether customer data is used to train models.
Data retention & training
Hosting summary
The published subprocessors are Amazon Web Services and Google Cloud Platform, both listed as located in the 'United States, European Union'. The United States is designated as the primary infrastructure location; the European Union applies only when an EU region is chosen, and 'when available'. Data is encrypted in transit with TLS 1.2 or above and at rest with AES-256 or equivalent, and API keys are encrypted before storage. Access controls follow least privilege, with RBAC and mandatory MFA for production access. Network protections listed are firewalls, segmentation, intrusion detection, DDoS protection and 24/7 monitoring. Any change of subprocessor is notified 30 days in advance. The CLI is a separate case: it runs on the user's own machine and the publisher stores nothing, so the only outbound flow is what goes to the LLM provider whose key the user supplies. Transfers outside the EEA are covered by the 2021 Standard Contractual Clauses, module 2, with a UK IDTA addendum.
Things to keep in mind
Risks and trade-offs to weigh before adopting Flint AI.
- Flint AI Platform is announced as coming soon: do not read its runtime guardrails and auto-fix promises as features you can rely on today
- You supply your own LLM API key, so code snippets, import chains, file contents and adversarial prompts leave for that third-party provider, outside Flint AI's control and outside its data-protection commitments
- The CLI product page claims there is no telemetry server, while the documentation describes optional anonymous telemetry requested at first launch (FLINTAI_TELEMETRY_CONSENT): check the setting yourself rather than trusting the marketing line
- The legal documents are the SandboxAQ group's, hosted on sandboxaq.com rather than being a Flint AI privacy policy, and no postal address is published anywhere, on the tool's site or the publisher's
- SOC 2 Type II and ISO 27001 are announced as pursued, so no security certification is held today; two dead links were also observed on the site, 'Your Privacy Choices' and a 'Download Switch Console' button, both pointing at an empty anchor
- Microsoft Teams requires the Switch server to be publicly reachable, which is not a neutral security decision, and every connector demands admin rights on the messaging platform
- A clean scan and a 0.0 to 1.0 score can lull a team into false confidence: they measure what the tools test, not the agent's behavior in the real world, and the domain was only registered in June 2026, so expect frequent changes
Setup & Integrations
Technical difficulty
Low for the CLI, higher for Switch. A Python developer installs the CLI with pip, fills one .env file and supplies an API key from OpenAI, Anthropic or Google Gemini (or a local model via litellm or ollama); Python 3.11+ is required, and the quickstart claims under 10 minutes to a first scan. Switch is sysadmin work: install the Console, run a server, configure agent providers, register the agents and connect the messaging platform with admin rights - and with Teams, expose the server publicly. Quickstarts, tutorials, troubleshooting pages, a Discord and a free weekly live onboarding are available.
Deployment
Integrations
Behind Flint AI
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Frequently asked questions
What does Flint AI do?
What do I need to run the CLI?
Does my code leave my machine?
Is Flint AI paid?
Which frameworks does the scan recognize?
Which messaging platforms does Switch support?
What is the difference between the CLI and the Platform?
Is there a Data Processing Addendum?
Who publishes Flint AI, and is there a minimum age?
Should you pick Flint AI?
Flint AI enters with almost no friction: two of its three products are live, free and open, and the only real cost is the LLM API key you bring. The CLI gives a Python agent a defensible safety story before production - static analysis, adversarial evaluations, findings mapped to OWASP ASI and scored with CVSS v4 - while Switch answers a different problem, keeping people, agents, decisions and history in one room across Slack, Teams, Discord, Mattermost and Telegram. Both are documented in unusual depth, down to the internals and a machine-readable llms.txt, and the legal material - DPA, data-handling page, subprocessor list - is public without an account.
The reservations are just as clear. The most ambitious brick, Flint AI Platform, with its runtime guardrails, auto-fix pull requests and dashboard, is still announced as coming soon behind an early-access waitlist, so none of it should be counted as available today. No price is published anywhere, which leaves the future business model open. The static scan covers Python only. The legal identity is pooled at SandboxAQ group level, with no postal address published and no Article 27 EU representative designated. SOC 2 Type II and ISO 27001 are described as pursued, not obtained. And the product is very young: the domain was registered in June 2026 and first archived a few days later.
What lowers the risk is the publisher. SandboxAQ spun out of Alphabet in 2022 and has raised more than USD 950 million at group level, so a short-term disappearance is unlikely - though nothing guarantees the longevity of this particular product line. The natural audience is technical teams moving agents from demo to production, willing to self-host, work in a terminal, and re-check the facts as a fast-moving young product keeps changing.
- Choosing a selection results in a full page refresh.
- Opens in a new window.