LLM-based inspection understands what employees mean, not just what matches a pattern: summaries stripped of identifiers, context that still carries meaning, documents inside uploads, multi-turn conversations.
Products / 01 · NativeAI Guard Employee DLP
Let your employees use AI. With NativeAI Guard as the safety net for sensitive data.
Real-time DLP for ChatGPT, Claude, Gemini, Copilot, DeepL and every shadow-AI app your employees discover next. Inspected and enforced in Switzerland, before anything leaves your control.
How it works
Four ways data leaves the company.
2,400 rows
password-protected
Capabilities
Visibility first. Then enforcement.
Sensitive fields become tags ([PERSON], [IBAN], [DIAGNOSIS]) so work continues at full speed while the real data stays inside the company. Blocks are reviewable and overridable in seconds, with audit trail.
Who sent what, when, to which model, and what NativeAI Guard did about it. Your records of processing for all AI usage, DSG Art. 12 and GDPR Art. 30, produced automatically. YAML/API export for auditors.
"Client-identifying data never leaves the company, health data is anonymized", written exactly like that, enforced like code. Your DPO can read every rule. Feed in a compliance document and NativeAI Guard drafts the matching rules. Starter packs per industry included.
When NativeAI Guard intervenes, employees see why (which policy, which data category) right in their workflow. Security awareness training, delivered at exactly the moment it matters.
Every AI tool in use (including the ones IT never approved) with users, frequency and data categories. The management report you cannot produce today.
Every prompt is already classified for DLP; the same data shows which purposes drive the most AI usage across the company. We also compare the model chosen against the task and flag where a lighter, cheaper model would have done the job just as well, with an estimate of what routing to the optimal model would save.
top purpose: contract drafting, 21%
est. savings from model routing: CHF 4,200/mo
Covered channels
Built for the AI assistants. Extended to every channel through which data leaves the company.
The product is designed around the AI tools your employees use in their daily work. Along the way, customer data can leak into a database you do not control. Inspection, however, sits in the browser itself and not in per-site integrations, which is why coverage is not a list of supported websites. In a supported browser, every web surface your employees can reach is inspected under the same policies. That is decisive, because an employee whose document upload to ChatGPT was blocked will, under pressure to deliver, email the document to themselves.
These four are simply where we tune and verify detection first. Any other assistant reachable in the browser is already covered by the same rules, and your own internal models are covered through the API proxy.
Because inspection happens at the browser layer, coverage is not a catalogue of individual websites. Whole categories are covered under the same policies, including the services nobody has named yet.
Delivered through the browser extension, for Chrome and Edge today. Inside a supported browser, interception is universal, and each category remains a policy target in its own right: the same rulebook can allow one category, anonymize in the next and stop an upload in a third.
Seen in the field
The workarounds that other DLP tools do not cover.
A user removes the "confidential" label from a Purview-classified file and uploads the now "public" content to an LLM. Classification-based DLP sees nothing wrong. The policy held; the intent did not.
An analyst summarizes a client dossier in their own words, no name, no IBAN, no account number. Regex-based DLP sees no pattern and lets it through. The full context of the relationship leaves the company anyway.
The corporate ChatGPT quota runs out mid-deadline; the employee logs into their personal account and keeps pasting the same customer data. Same URL, same interface, but the data processing agreement, audit rights and deletion guarantees just evaporated.
Legal translates contracts, HR translates employment contracts, Finance translates audit reports, through DeepL, daily, in four-language Switzerland. Nobody classifies a translator as an AI risk. Whole documents leave the company, unmonitored.
Fits your stack
Layer 2 on top of Purview. Not a replacement.
Your existing DLP solution protects structured channels: mail, endpoints, SharePoint. NativeAI Guard covers what it cannot inspect: the LLM prompt layer, the web surface, the AI apps outside the Microsoft perimeter. Delivered as a browser extension, with a Windows desktop agent in development; a drop-in API proxy covers internal systems. Swiss SaaS or fully on-premises, and events flow into the SIEM and ticketing tools your SOC already runs.
Purview protects structured channels. NativeAI Guard protects the LLM prompt layer that Purview cannot inspect.
Security Architect · Swiss Financial Market Infrastructure
Compliance mapping
Every capability maps to an obligation.
Policy engine
Describe what to protect. In plain language.
Write the rule the way you would explain it to a colleague. Our own language model turns it into an enforceable policy, which you then refine. No classification trees, no regex, no labeling project. Write a sentence, and the rule is there.
And most of them are already written, by us.
The regulatory baseline is included in the product
The obligations under the Swiss DSG, GDPR and the EU AI Act that apply to everyone are covered from day one. Written by us, reviewed with security and compliance practitioners, and not left as an exercise for the customer.
A pack for your industry, on top
Banking secrecy, medical secrecy, insurance secrecy, plus public-sector and critical-infrastructure duties. The industry-specific cases are already modeled, so you start from a working set rather than a blank page.
We keep them current, as part of our service.
When a regulation changes, we update the standard policies and you receive them. Keeping up with the law is our job, not another item on your security team's list. It is included in the subscription.
Your own rules come from the documents you have already written.
Hand us your data protection regulations, your information classification policy, your internal AI directive, plus a few examples of how your data is actually structured. We turn them into policies just for you, which cover your requirements alongside the standard policy set. You start from a working configuration rather than an empty one. Every policy we deliver can be edited in your admin interface. You can also write further rules there at any time, in your own words, without waiting on us.
Deployment
Swiss-hosted or entirely inside your perimeter.
Most customers start on our Swiss infrastructure because it is faster to prove the value. Regulated environments that cannot send anything outside their own network run NativeAI Guard on their own hardware.
Swiss SaaS
Our servers, our datacenter, Lausanne
- Browser extension, rolled out through your existing MDM or Intune. A system-level endpoint agent for desktop applications is in active development.
- Live in days, not quarters. No network re-architecture, no proxy chain to untangle.
- All inspection and logging happens on our own servers in Lausanne, under Swiss law.
Best for: proving the value quickly, and for organizations for whom processing in Switzerland is already sufficient.
On-Premises
Your hardware, your network, your keys
- Runs in your own Kubernetes cluster, on hardware you control, inside your network perimeter.
- No prompt, no log and no policy ever leaves your environment, not even to us.
- Suited to security policies that forbid any external processing.
Best for: classified data, air-gapped networks and policies that prohibit any external processing.
- Same detection engine and policy language
- Full audit log, SIEM export and SOC integration
- No US cloud, no hyperscaler, in either case
- You can start on SaaS and move to on-prem
Common questions
Frequently asked questions
We already run Microsoft Purview. Does this replace Purview, or is NativeAI Guard complementary?
We complement Purview. Purview protects the structured channels it was built for: mail, endpoints, SharePoint. It does have shadow-AI DLP, though only in Edge for Business, billed by usage and driven by static rules. The honest case for a second layer is not that Purview is weak, it is that static rules and classification labels do not catch content whose sensitivity lies in its meaning, and that the AI surface reaches well beyond the Microsoft perimeter. A head of IT security at a Swiss bank put the arithmetic plainly: static rules catch the great majority, closing the remainder inside Purview costs six figures in consulting, and buying that layer is cheaper than building it. NativeAI Guard offers digital sovereignty. An option to avoid building yet another dependency on a US company.
Which surfaces do you cover today, and which are still coming?
Today: Chrome and Edge through the browser extensions, which covers every browser-based AI tool, translation service and webmail your employees might use. A drop-in API proxy for internal systems lets you protect every AI application you have built yourself. In active development: a system-level endpoint agent for desktop applications and command-line tools such as Claude Code. On the roadmap: macOS, Firefox and Safari. The order of that roadmap is not fixed in advance: it follows what the organizations working with us actually need, and more than one item on it is there because a customer asked for it.
What happens to a prompt while you inspect it? Is it stored?
Transient processing is our standard mode. The prompt is inspected in volatile memory on our own servers in Switzerland and discarded immediately afterwards, and nothing of its content is written to disk. What persists by default is the audit entry: who sent something, when, to which model, and what NativeAI Guard did about it. Retaining the prompt content itself is an option we provide, because some of our customers need it. Banks in particular carry record-keeping duties where the content of a communication has to remain reproducible, not just the fact that it took place. Where that applies, retention of prompts is switched on deliberately.
Do you use our data to train or tune your models?
No operational data. Prompts, metadata, decisions and usage logs generated through your use of the platform are never used to train, tune or validate machine-learning models, and that is written into the data processing agreement rather than left as a policy statement. Our classification models are pre-trained on synthetic and public corpora. The one exception is explicit and consent-based: if you choose to provide an anonymized calibration dataset during onboarding to tune detection to your own documents, that use is named in the contract and happens only because you asked for it.
Is the user blocked, or can they keep working?
Both, and there is a third response that is often the better one: anonymization. Instead of stopping the request, NativeAI Guard can replace the sensitive elements (names, client numbers, patient identifiers, contract references) before the prompt reaches the model. The employee still gets a useful answer and keeps working without interruption, while the loss of sensitive data is prevented. For a large share of everyday cases this is the best solution, because a hard block turns the security team into an obstacle. That is why, wherever the data type allows it, we work with anonymization rather than blocks. Hard blocking stays reserved for the categories where no exception should be accepted. Every block is logged with the policy violation, and these entries are visible in the audit log, which several insurers have explicitly required.
What can an administrator configure?
Every domain can have its own rule, and a default rule applies automatically to all domains until you adjust it for a specific one. Each rule runs in its own mode: anonymization, policy enforcement, allow or block, so the same deployment can be strict in one place and light-touch in another. You write new rules in plain language by typing them in, and you adjust existing rules the same way. You create and manage user groups yourself, so rules can be enforced differently per team or department. The AI governance dashboard shows you at any time which rules are active and how they are being applied.
What about password-protected files, or a document whose classification label was removed before upload?
Password-protected files are intercepted at upload: the user is asked for the password so the content can be scanned in the clear before anything is sent. For Purview-classified documents, for example, we block documents marked as confidential from being uploaded, but for documents classified as non-confidential we inspect the content itself, so a file whose confidentiality marking was removed before upload is still scanned and no sensitive data leaves the company. Files encrypted with rights management, Microsoft Purview Information Protection and Azure RMS in particular, are not inspected yet. This is on our roadmap. Until it ships, such files are not quietly waved through: a policy can stop them at upload, so an uninspectable file is a decision you make rather than a gap you find later.
Book a demo
See live how NativeAI Guard stops data leaks.
A 45-minute session with the founders, online. We enter sensitive data into ChatGPT and show how NativeAI Guard anonymizes or blocks it in the same moment, based on different policies.
Then: a pilot phase that we run for you
One month on your own prompts, we run it, no changes to workflows.
The result: a risk overview of data leaks, shadow AI, AI usage and model costs, the evidence for your management that the topic is urgent.