Skip to content

Detect and Respond

AI Guardian

Shows you which AI tools your staff use, what they send to them, and gives you the controls to do something about it.

Audience
Security and governance
Headline
AI tools discovered
Sources
Proxy, cloud, identity, code
Output
Findings and policy

What it does

Inside AI Guardian

Discover and govern AI usage across the organization: detection, inspection, and enforcement.

Shadow AI discovery

Every AI tool reached from your network or through a corporate identity, including the ones nobody told you about.

Prompt inspection

What actually left in a prompt. Sensitive data, credentials, and source code detected in content rather than guessed from a domain.

Threat chains

Related AI events linked into one narrative, so a slow exfiltration across many sessions reads as a single story.

Prompt injection detection

Injection attempts against your own AI-facing applications, mapped to MITRE ATLAS techniques.

Per-user risk

Behavioural baselines per user, so an unusual volume or an unusual destination stands out without blanket blocking.

Policy and enforcement

Allow, warn, or block per tool, per group, per data class. Applied through the controls you already run.

How it works

See, decide, act.

Every agent follows the same three movements. What differs is what it reads, what it scores, and what waits for a person.

  1. See

    Every AI destination reached

    Forward-proxy traffic, cloud AI service calls, identity events, and code-assistant usage, read together.

    • Netskope and Zscaler web transactions
    • Azure OpenAI and OpenAI usage
    • GitHub Copilot activity
    • Entra ID app consents
  2. Decide

    Content inspected, behaviour scored

    Prompts and uploads are inspected for sensitive content, checked for injection, and weighed against that user's own baseline.

    • Personal data detected in a prompt
    • Credentials or keys in a paste
    • Source code leaving for an unapproved model
    • Volume far outside a user's normal
  3. Act

    Governed, not just observed

    Findings open with a severity and a framework mapping. Policy decides whether a destination is allowed, warned on, or blocked.

    • Block an unapproved destination for a group
    • Warn the user in the moment
    • Open a finding for review
    • Map to ISO 42001 and the OWASP LLM Top 10
1 / 3

Governance

How AI Guardian is governed

What always waits for a person differs meaningfully between agents, so it is stated per agent rather than as a platform-wide generality.

What it does on its own

Discovers destinations, inspects content, scores behaviour, opens findings, and applies policies you have already approved.

What always waits for a person

Creating or widening a block policy, and any enforcement affecting a whole group, requires an administrator.

What it records

Every detection with the engine that produced it, its framework mapping, the policy applied, and who changed that policy.

Alert Navigator

Detect and Respond · v2.0

Alert triage that separates true from false positives, groups related alerts into cases, and opens the ticket.


  • Pending triage
  • True positives
  • Tickets opened

Phishing Remediation

Detect and Respond · v2.0

Multi-source phishing triage with enrichment, mailbox scoping, and analyst-gated remediation.


  • Awaiting decision
  • Incidents handled
  • Actions reversed

Book a demo

See AI Guardian on your own data.