Startups

Using AI for everything is correct. Seeing none of it is not.

The usage that makes a small team fast is the usage nobody has visibility into. Itzal runs on the laptop, detects before submission, and needs no security team to operate.

LOG ONLY · 14 DAYS customer email · support draft access key · pasted config unreleased figures · investor update customer email · debugging SHORT, SPECIFIC, SLIGHTLY ALARMING
Built for Seed to Series B B2B SaaS Fintech and health startups Remote-first teams Teams with no security hire

The threat

Everyone is technical, so everyone pastes.

In a company of thirty there is no approval queue between an idea and a chat window, which is the advantage. It also means the exposure is not concentrated in one department where a policy could catch it.

  1. Debugging with production data

    The failing record is pasted because the failing record is the bug.

    Trips GDPR / CCPA

  2. Drafting a customer email or QBR

    The account is pasted so the draft is specific rather than generic.

    Trips Internal

  3. Preparing an investor update

    Unreleased figures are pasted to be turned into prose.

    Trips Internal

  4. Pasting a config or an env file

    The fastest way to ask why a service will not start.

    Trips Internal

Be careful with the last one. Our built-in key patterns match an AKIA access-key ID and a PEM private-key header, and nothing else — a pasted .env with a production password and a third-party token produces no event today. Secrets you actually hold are a custom pattern rule, not an assumption.

What the detectors actually match

What’s specific here

What a team with no security hire can run.

The constraint that matters at this size is not budget. It is that nobody has a day a week to tune a DLP, so anything requiring one will be switched to log-only and forgotten.

  1. 01

    Start log-only and look at it once

    Two to four weeks of log-only on the whole company, then read the report. At thirty people that is a short list, and it tells you which two behaviours are worth a rule.

  2. 02

    Write rules for what you actually hold

    A customer-ID format, an internal project codename, a classification header. A pattern rule runs in the agent inside the deadline and can block; a rule described in words runs after the send and reports.

  3. 03

    Code detection is not built, and we say so

    There is a codeDetection setting in the product's framework model and no capture path behind it yet. Large pasted code blocks are not flagged as a category today, and a vendor telling you otherwise has not read their own docs.

  4. 04

    The boundary protects you too

    Findings leave the device; text does not. That means adopting this does not create a new place your customers'' data is stored, which is the question your first enterprise buyer will ask.

What crosses the network boundary

What it does here

Someone pastes a production record. Itzal stops it.

Nobody is going to stop using AI tools at a company this size, and a policy that pretends otherwise just moves the usage somewhere you cannot see. Itzal checks the text in the instant before it is sent.

The email is a pattern and the access-key ID is one of the two key formats that are built in. Your team gets a record saying what kind of value it was; the message itself never goes anywhere.

Illustration. The data shown is invented.

An engineer pastes a production record into an AI chat tool. Itzal checks the text on their own laptop, finds a customer email and an access-key ID, masks both, blocks the send, and reports an event that contains no readable customer data and no usable credential.
How it works, end to end

Rollout

Two weeks of log-only, then one afternoon of rules.

The constraint at this size is attention, not budget. This rollout is designed to need a total of about a day from one person, spread over six weeks.

  1. 00

    Roll it to everyone, log only

    No pilot group. At thirty people the whole company is the pilot, and a subset would just mean the interesting behaviour happened somewhere you were not looking.

    Before the clockPrerequisite
  2. 01

    Log-only, the whole company

    Nothing is blocked and nobody has to be told to change anything. The output is a short list of what actually leaves, which is the thing worth reading.

    2–4 weeksLog only
  3. 02

    Read it once, write two rules

    The report is usually short and specific. A customer-ID format and a project codename cover most of it, and both are pattern rules that can block.

    1–2 weeksLog only
  4. 03

    Warn

    Warn rather than block first, even here. The dismissal rate tells you whether the two rules were right before anyone is stopped mid-sentence.

    2–4 weeksWarn
  5. 04

    Block, and leave it

    Enforcement on the two or three rules that earned it. The point of this shape is that it does not need revisiting until the company changes.

    OngoingBlock

If every phase runs to its minimum How far it slides if they all run long

The full deployment guide

Straight answers

We are thirty people. Is this overkill?

The question is usually asked the other way round by the first enterprise customer who sends a security questionnaire. What this gives a small team is an answer to “what stops your engineers pasting our data into ChatGPT” that is a control rather than a policy document.

Will it flag source code?

Not as a category. codeDetection exists in the product''s framework model with no capture path behind it, and it is listed as not built. What does fire on a pasted file is whatever else is in it — an email, a customer ID, an AKIA key — or a custom rule you write.

Do we need someone to run it?

Run log-only for two to four weeks, read the report once, and write rules for the two things it surfaces. The deployment stages and what each is for are set out on the deployment page.

More questions, answered

Start log-only, and look at it in a month.

A working demo on a laptop you trust. At this size the first report is usually short, specific and slightly alarming.