Products / 02 · NativeAI Guard Agent DLP & Firewall

Your AI talks to the outside world. NativeAI Guard protects it while it does.

Real-time protection for the AI you run: internal agents and RAG pipelines, autonomous workflows, customer-facing chatbots and voice agents. Every prompt and every response is inspected before the agent acts on the input or delivers the output.

Capabilities
Between your AI and everything it touches
Inside your perimeter
Your AIinternal agents · RAG · chatbots · voice
with access to:
CRM · HR records · patient data
contracts · financials
NativeAI Guard inspectsAPI PROXY · CH
in: hidden instruction in web page → stripped (XPIA)
in: caller jailbreak attempt → blocked
out: response contains customer data → withheld
every prompt + every response → logged, SIEM-streamed
Outside · untrusted
Untrusted inputsweb pages · documents · emails
External userscustomers · callers · attackers
External AILLM APIs · third-party agents
These attacks happen at the prompt and data layer, invisible to firewalls, proxies and every traditional security tool. NativeAI Guard is built for exactly this layer.

Capabilities

Inspect the input. Inspect the output. Control for security.

Prompt injection (XPIA) blocking
Agents that cannot be turned against you

Web pages, documents and emails your RAG pipeline ingests can contain hidden adversarial instructions the agent would otherwise execute. NativeAI Guard detects and blocks them before the agent acts.

Jailbreak detection
Guardrails that hold under pressure

Callers and external users probe your agents to bypass their rules, extract data, trigger unauthorized actions or pull out system prompts. NativeAI Guard stops the bypass attempt, not just the known pattern.

Response inspection
Nothing leaves without a check

Every agent output is inspected before delivery. A response that contains another customer's data, a system prompt or sensitive internal content is withheld, data exfiltration prevented at the last line.

Toxic output filtering
Your AI always stays polite

Harmful, abusive or legally risky content is filtered out of customer-facing agents before it reaches a customer, with continuously updated detection models, without disrupting live workflows.

Seen in the field

Agent risk is already a reality.

The jailbroken voice agent

A caller talks your customer-service voice agent into reading out another customer's details. No exploit, no malware, just a conversation. Voice agents in banking and insurance are the most rewarding target.

NativeAI Guard: jailbreak detection on the way in, response inspection on the way out, the customer data never reaches the caller.
The infected document

Your RAG pipeline ingests a web page (or a supplier PDF) with instructions hidden in the content. The agent obediently redirects, leaks context or rewrites its own rules. This is XPIA, and it is invisible to traditional tools.

NativeAI Guard: adversarial instructions are stripped from ingested content before the agent ever sees them.
The manipulated chatbot

Air Canada's chatbot was talked into promising an unauthorized discount, and a court held the airline to it. A customer-facing agent that can be talked into commitments is a commercial risk, not just a security risk.

NativeAI Guard: policy limits on what agents may promise or disclose, enforced outside the model, where prompts cannot reach.
"

AI-to-AI interaction without a human in the loop is my biggest concern.

CISO · Swiss cantonal administration

Compliance mapping

Built for the regulatory framework.

EU AI ACT 9 · 14 · 15Risk management, human oversight, robustness and cybersecurity for high-risk AI
DORA 7 · 9 · 28Incident prevention and third-party risk, LLM providers are ICT third parties
NIS2 ART. 21 · 23Supply-chain security and incident reporting for AI attack vectors
ART. 47 / 321 / 35An agent that discloses customer or patient data triggers the same criminal statutes as a human

Policy engine

The same policies that protect your employees protect your agents.

An agent is one more actor sending data to a model, only faster and with nobody to pause and think first. It reads from your systems, calls a model, acts on the answer. The rule that stops an employee pasting a customer file into ChatGPT is the same rule that stops an agent putting the same record into a prompt. You only have to define it once, in plain language.

Written once, in one place

Your policies live in a single console. You do not maintain one rulebook for employees and a second, quietly diverging one for your automation.

Enforced on both surfaces

The browser extension covers your employees, the API proxy covers your agents. Same detection engine, same policy language, same actions.

One audit trail, not two

Human and agent activity land in the same log, so the question of who sent which data to which model has one answer instead of two systems to reconcile.

A policy written as a sentence, enforced as code.

And most of them are already written, by us.

01

The regulatory baseline is included in the product

The obligations under the Swiss DSG, GDPR and the EU AI Act that apply to everyone are covered from day one. Written by us, reviewed with security and compliance practitioners, and not left as an exercise for the customer.

02

A pack for your industry, on top

Banking secrecy, medical secrecy, insurance secrecy, plus public-sector and critical-infrastructure duties. The industry-specific cases are already modeled, so you start from a working set rather than a blank page.

03

We keep them current, as part of our service.

When a regulation changes, we update the standard policies and you receive them. Keeping up with the law is our job, not another item on your security team's list. It is included in the subscription.

Managed by us

The attack side is not a policy you have to write.

Everything above concerns data leakage: what your agents may send, and to which model. Traffic in the other direction is inspected too, and that part is entirely ours to run. Prompt injection blocking, jailbreak protection and filtering of harmful outputs are built in, tuned by us, and adapted as the attacks change. We follow the research coming out of academia and from other vendors continuously, because this field moves in weeks rather than years, and improvements reach you as part of the service. There is nothing here for your team to configure and no rulebook of your own to maintain.

In onboarding

Your own rules come from the documents you have already written.

Hand us your data protection regulations, your information classification policy, your internal AI directive, plus a few examples of how your data is structured and which systems your agents are allowed to reach. We turn them into customer-specific policies alongside the standard set and tune the detection to your systems, so you start from a working configuration rather than an empty one. That is the groundwork, and it is where our work ends and yours begins: every policy we deliver can be edited in your admin interface, and you write new ones there yourself, in the same plain language, without waiting on us.

Deployment

Swiss-hosted or entirely inside your perimeter.

Most customers start on our Swiss infrastructure because it is faster to prove the value. Regulated environments that cannot send anything outside their own network run NativeAI Guard on their own hardware.

01

Swiss SaaS

Our servers, our datacenter, Lausanne

  • The API proxy runs in our datacenter in Lausanne. Point your agent traffic at it, and inspection starts immediately.
  • No infrastructure work on your side, and no change to your agent code beyond the endpoint.
  • Every prompt, every tool call and every response stays inside Switzerland, under Swiss law.

Best for: proving the value quickly, and for organizations for whom processing in Switzerland is already sufficient.

02

On-Premises

Your hardware, your network, your keys

  • Runs in your own Kubernetes cluster, on hardware you control, inside your network perimeter.
  • No prompt, no log and no policy ever leaves your environment, not even to us.
  • Suited to security policies that forbid any external processing.

Best for: classified data, air-gapped networks and policies that prohibit any external processing.

Identical in both
  • Same detection engine and policy language
  • Full audit log, SIEM export and SOC integration
  • No US cloud, no hyperscaler, in either case
  • You can start on SaaS and move to on-prem

Common questions

Frequently asked questions

Our agents call the model APIs directly from backend code, not through a browser. Can you see that traffic at all?

Yes, and this is exactly the case the browser extension is not built for. NativeAI Guard runs as a drop-in API proxy between your systems and the model providers. You point the agent at the proxy instead of the provider endpoint, and inspection starts, with no change to the agent logic. This is the channel that most commonly has no controls on it at all, because neither your proxy nor your CASB sees it, and this information never flows through a browser.

Does this protect against prompt injection and jailbreaks, or only against data leaving?

Both directions. Inbound, we inspect what reaches the model, including indirect injection carried in retrieved documents and web content that an agent ingests without a human ever reading it. Outbound, we inspect what the model produces before it acts or is returned. For an autonomous agent the input is as dangerous as the output, which is why we treat neither as trusted.

How do you identify and authenticate an agent?

Through API keys today, scoped per agent, with the full audit trail attached to the key. Registry-based agent identity and governance, where each agent carries a verifiable identity independent of its access key, is on the roadmap. It got there because a cybersecurity architect at a large industrial company walked us through what agent identity has to look like at their scale, and that is exactly the kind of input that shapes what we build next.

What does inspection do to latency?

Inspection runs in the low hundreds of milliseconds and happens inside Switzerland, so no round trip leaves the country to perform it. For an interactive agent that is generally not perceptible against model response times, but the honest answer is that it depends on your policy set and payload size, and it is one of the things a pilot phase measures on your own traffic rather than on ours.

Where do the alerts go? We do not want another dashboard.

Into the tools your SOC already runs. Events stream out to your SIEM, and one-way export into Microsoft Sentinel is the pattern most Swiss customers ask for, because they build their own alert rules there. Incident routing into ticketing systems such as Jira and ServiceNow is on the roadmap. We do ship dashboards of our own, but if you prefer other tools, you can stream the audit log data into the tool of your choice. Our dashboards cover two things a SIEM will not show you on its own: AI governance, meaning which tools are in use, by which parts of the organization and what is being sent to them, and the AI-specific threats, meaning prompt injection and jailbreak attempts, blocked exfiltration, and policy overrides with the justifications given. That is the view management, a data protection officer or an auditor usually asks for.

Put a guard between your AI and the world.

A 45-minute session with the founders, online. We run an injection attempt against an agent and show you what stops it. In the pilot phase that follows, you test NativeAI Guard with your own agents, your own traffic and your own use cases.