AI data loss prevention

Let your team use AI. Keep your data out of it.

Your people paste work into ChatGPT, Claude and Gemini every day. Sometimes that work contains a customer, a patient, a card number or a password. Itzal catches it on their own laptop, before it is sent — and never sees the message itself.

ON THE LAPTOP mTLS RECORD
The message stays left of the line. Only its shape crosses.
Policy mapped to HIPAA GDPR CCPA PCI DSS FERPA GLBA SOX Your own rules

What it does

Someone pastes something they shouldn't. Itzal stops it.

Banning AI tools doesn't work — people move to their phones and you lose sight of it entirely. Itzal takes the opposite approach. It sits on the laptop, watches the box people type into, and checks the text for anything sensitive in the instant before it is sent.

If it finds something, it warns the person or blocks the send outright. Your security team gets a record saying what kind of data it was. The message itself never goes anywhere.

Illustration. The data shown is invented.

An employee pastes a customer record into an AI chat tool. Itzal checks the text on their own laptop, finds a social security number and a card number, masks both, blocks the send, and reports an event to your console that contains no readable customer data.

How it works

Three things happen, all of them on the laptop.

01

It watches the box people type into

A browser extension sees text on its way into an AI tool — the ones you've approved and the ones you haven't. Windows, Mac and Linux, deployed through the MDM you already run.

A browser window on an AI chat tool. A customer record containing a name, a social security number and a card number has been typed into the message box, and an Itzal badge in the toolbar reads "watching".
02

It checks the text where it already is

A small program on the same machine looks for personal details, health information, card numbers, passwords and keys — plus anything you define yourself. Nothing is uploaded anywhere to be checked.

Three detection layers — known patterns, context, and your own rules — drawn inside a boundary marked "this device", sitting above a dashed network line labelled mTLS that the message never crosses.
03

It acts, then reports what type

Your rules decide: allow it, warn the person, or block the send outright. Either way your console gets the category, the risk and the outcome — never the words themselves.

The same message with the social security number and card number highlighted in red, the send button disabled, and a warning reading "Hold on — this looks like a patient record" offering to edit the message.

See it working

Fifteen seconds, start to finish.

A message being typed, the check running on the laptop, the block landing, and the record arriving in the console — the whole path, end to end.

A message containing a name, a social security number and a payment card is
                    typed into an AI chat tool. Itzal checks it on the laptop, highlights the two
                    sensitive values, masks them, blocks the send, and delivers a record to the
                    console containing the finding types and the action taken but none of the
                    message text.
Every value shown is invented — the card number deliberately fails its checksum. A demo asset carrying a real record is the exact failure this product exists to prevent.

The console

What your security team actually sees.

Counts, categories, trends, and the rule that fired. Filter by team, framework or destination; export what an auditor asks for.

There is no transcript to open, because one was never collected. The most sensitive screen in the product is, by construction, not very sensitive at all. More about the console.

The Itzal console overview: 2,417 events in thirty days, 311 blocked before
                    send, 1,842 devices reporting, and zero message content stored. A bar chart
                    breaks findings down by framework, a panel lists which capture surfaces are
                    binding and which are uncovered, and a table of recent events shows masked
                    snippets only.
Demo data throughout. Northwind Health is not a customer.

Who it's for

Two people have to say yes.

Tools like this usually fail because one of them wasn't asked. The business wants the risk gone without slowing anyone down; IT wants one more thing to run that doesn't page them at 3am. Here is the honest answer for each.

If you run the business

Fewer nasty surprises, without banning anything.

You keep the productivity and lose the exposure — and you never have to defend a decision to read your employees' messages, because nobody did.

  • Staff carry on using the AI tools that make them faster
  • "Is our customer data going into AI?" gets an evidenced answer, not a guess
  • The answer is ready before a regulator, client or insurer asks for it
  • Legal, HR and the works council can approve it — there is no surveillance to object to
  • You find out which teams need training, not which people to blame

If you run IT or security

One agent, one extension, nothing new to babysit.

It deploys the way everything else you own deploys, reports into the tools you already watch, and tells you when it isn't working instead of going quiet.

  • Signed packages through Intune, Jamf or whichever MDM you already run
  • No appliance, no proxy, no traffic to route through us
  • Events land in Splunk, Sentinel, Google SecOps, Elastic or plain syslog
  • Mutual TLS only — there is no unencrypted path, including in development
  • If a check runs slow it gets out of the way and flags itself, rather than freezing someone mid-sentence
  • Start with one team; coverage is measured per device, never assumed

The boundary

Protection that doesn't require surveillance.

Every other way of doing this asks you to choose: watch your people, or protect the company. Itzal refuses the trade — the check happens where the data already legitimately lives.

What crosses the network

  • The type of data found, and how many.
  • Which rule or framework it broke.
  • Where it was going, and whether that tool is approved.
  • A masked snippet, the risk score, and what was actually done.

What never leaves the laptop

  • The message your employee typed or pasted.
  • The AI tool's reply.
  • The contents of any attached file.
  • The sensitive value itself — in any reversible form. The snippet is masked, not encrypted and not hashed, so there is no key that turns it back. Not one we hold, and not one that exists.

Why teams trust it

Four promises we can actually keep.

It runs on the device

Nothing is uploaded to be scanned. The engine is already where the data is.

Masked, not hashed

There is no key anywhere that reverses a masked value. Including ours.

It acts in time

Warns or blocks before the message is sent — not in a report the next morning.

It publishes its gaps

What Itzal cannot see is written down, in public, before you ask.

Unusual, on purpose

We publish what we don't cover.

Zero detections and perfect coverage look identical on a dashboard. So we write down the places Itzal doesn't watch — file uploads, pasted images, coding assistants, mobile — in the product, in your console, and on a page anyone can read.

A team sizing its other controls around our claim deserves an accurate claim. See exactly what we cover.

Straight answers

Does Itzal read my employees' conversations?

No. The check runs in a small program on the endpoint, and the raw text is never transmitted, stored off the device, or written to a log. Administrators see data types, counts and risk scores. They never see the message.

Can it stop something, or only report it?

Both. Itzal can log quietly, warn the employee inline, or block the send outright — set per framework and per destination, so an approved tool and a personal account are treated differently.

Is deploying this legal where we operate?

That depends on jurisdiction and needs your counsel, not a vendor's reassurance. Several US states and most EU member states require advance written notice for endpoint monitoring. What we know, and what we don't.

See it on your own hardware.

A working demo, not a deck. Bring a policy you care about and a laptop you trust.