Risk-adaptive guardrails, written as rules you can read.
Rules combine who, what and where: department, data class, destination and channel. They resolve by priority to one of five actions, and new rules run in simulation before they enforce anything.

Four conditions. Five actions.
- Department
- Any department in your directory
- Data class
- Any of the 25 classesUninspectable content
- Destination
- ChatGPTClaudeGeminiMicrosoft CopilotPerplexityDeepSeekGateway providers
- Channel
- BrowserGatewayDesktop MDM only
- Actions
- AllowLogWarnRedactBlockEvaluated by priority; the first terminal action wins. Warn can require a written justification to proceed.
Four EU templates, ready on day one.
For any organisation handling personal data
Personal data redacted before it reaches an external AI tool. Warnings on files that cannot be inspected. Everything logged.
For banks, insurers and payment firms
Hard controls on IBANs and payment cards, credentials blocked everywhere, non-EU AI blocked, payment data redacted even on the gateway.
For public bodies
Only sanctioned, EU-resident AI allowed; everything else blocked with the reason shown. Citizen identifiers redacted even on permitted tools.
For schools, colleges and universities
Student data redacted before external AI. Warnings on grades and assessments. Coaching before blocking.
Every rule change is safe to make.
Write
Build the rule in the console, as a sentence you can read back.
Simulate
Run it against live traffic in simulation. It records what it would have done and enforces nothing.
Promote
Switch it to enforce. The change is versioned, with who and when.
Distribute
Policy reaches every browser by polling with caching; revocation takes effect on the next poll, with no extension release.
See it stop real-looking data in a real browser.
A 30-minute technical walkthrough: a prompt redacted, a file stopped, the dashboard, and an evidence pack verified offline in front of you.
No slide deck. Synthetic data only.
