Not “stop AI”
Banning the tools moves the work to personal phones and removes the only visibility you had. The goal is safe use, not no use.
About
That is the whole product in one sentence, and it is why the company is called what it is.
The name
itzal
it‑SAHL /iˈtsal/ Basque
Basque stress varies by dialect and is not strongly phonemic; the second-syllable stress above follows standard euskara batua. If you are recording anything, have a native speaker say it.
Why that word
When one of your people pastes a customer record into an AI tool, what reaches your security console is not the message. It is the outline of it: what kind of data was in there, how much, which rule it broke, and what was done about it.
Enough to act on. Nothing to leak. A shadow is cast by the thing, follows it exactly, and carries none of it away — and we could not find a more accurate description of a redacted event record than that.
It is also, we will admit, a good name for a product whose entire claim is that it sees without taking.
The objective
Most security companies describe an ambition broad enough that no outcome could ever contradict it. Here is ours, narrow enough to fail:
Make it possible to use AI at work without anyone having to read what your people write.
Banning the tools moves the work to personal phones and removes the only visibility you had. The goal is safe use, not no use.
A control that requires surveillance to function fails the works council, the DPO, and eventually the people it monitors.
A vendor asking to hold your sensitive data so it can protect your sensitive data has moved the risk, not removed it.
Detect on the device, act before the send, and report a shape rather than a substance. Everything else is downstream of that.
The trade-off
A DLP tool for AI usage has an obvious shortcut: send the prompt somewhere with a big model and let it decide. It works, it is easier, and it means the content you were trying to protect now sits in a second vendor’s systems with its own retention window and its own breach surface.
We chose detection on the endpoint, redaction before the record exists, and no mechanism to retrieve the original text — because a product that protects data by collecting more of it is solving the wrong problem.
That constraint is not free. Tuning is slower, because we cannot look at what we got wrong. Some surfaces stay uncovered longer. No heavy model fits inside an endpoint budget. The full trade-off, stated plainly.
Commitments
Each one would make the product easier to build or easier to sell. They are written down here so that breaking one is visible rather than gradual.
Not now, not later
The questions we answer best are the ones about what the product cannot do. Those have the shortest answers.