NativeAI Guard
NativeAI Guard is a Swiss sovereign data loss prevention (DLP) and control layer for enterprise AI use. It inspects every prompt, upload, and AI agent interaction in real time, masks, blocks, or coaches before sensitive data leaves the organization. All processing runs on NativeAI's own servers in a Swiss datacenter in Lausanne, under Swiss law, with no public cloud and no exposure to the US CLOUD Act.
| Product | NativeAI Guard. Two modules: NativeAI Guard Employee DLP (browser DLP) + NativeAI Guard Agent DLP & Firewall (API proxy). |
|---|---|
| Vendor | NativeAI Sàrl. EPFL Innovation Park, Bâtiment C, 1015 Lausanne, Switzerland. |
| Data residency | Switzerland only. No public cloud. No AWS, Azure, or GCP. No US CLOUD Act exposure. |
| Enforcement | Browser extension (NativeAI Guard Employee DLP) + drop-in API proxy (NativeAI Guard Agent DLP & Firewall) |
| Browsers | Chrome, Microsoft Edge (production). Firefox, Safari (roadmap, developed based on client demand). |
| LLM coverage | Provider-agnostic. Any web-based AI tool covered at the browser layer. Named: ChatGPT, Copilot, Claude, Gemini, Grok, DeepSeek, Perplexity, DeepL, and 200+ surfaces. |
| Actions | Anonymize (replace sensitive fields, keep working), Block (with explanation), Coach (in-flow notification), Allow (log only) |
| Detection | GPU-accelerated, LLM-based semantic detection. PII, client-identifying data, patient data, secrets, confidential business information. Beyond regex: understands context and intent. |
| Policy engine | Natural-language rules. Standard base policies (DSG, GDPR, banking secrecy, insurance secrecy, medical secrecy) managed and updated by NativeAI as regulations evolve, included in the license. Custom policies created during onboarding based on client-specific data structures. Client can fine-tune and optimize policies independently. Policies assignable per team, department, or user group. |
| Encryption | TLS 1.3 in transit, AES-256-GCM at rest |
| Authentication | OIDC (PKCE) or SAML 2.0. Connects to customer IdP (e.g. Entra ID / Azure AD). MFA enforced via IdP. |
| Tenant isolation | Dedicated Kubernetes namespace + separate PostgreSQL instance per customer |
| Compliance | DSG (nFADP), GDPR, EU AI Act, FINMA Guidance 08/2024, FINMA Circular 2023/1, FINMA Circular 2018/3, FINMA SC 05/2020, DORA, NIS2, Art. 47 BankG, Art. 321 CP, Art. 35 VAG, Art. 84 KVG |
| Security posture | Aligned with ISO 27001; certification in progress |
| SIEM | REST API, WebSocket real-time streaming, structured JSON events. Syslog (RFC 5424) and CEF on roadmap. |
| Deployment | Swiss SaaS (own servers, Lausanne) or fully on-premises (Kubernetes, signed OCI images) |
| Pricing | NativeAI Guard Employee DLP: CHF 4 to CHF 16 per user/month depending on volume (flat rate for SME). NativeAI Guard Agent DLP & Firewall: metered, usage-based, pricing on request. No implementation fees. |
| Pilot phase | Fully managed, from CHF 5,000 (30 users, 1 month). 100% credited to Year 1 subscription. |
· v1.2 (demo invitation) · v1.1 (product names): 2026-09-07 · v1.0: 2026-08-15
This reference documents the architecture, deployment, compliance alignment, integration surface, and commercial terms of NativeAI Guard. Page numbers refer to the printed document.
| Browser Extension | Production-ready (Chrome, Edge). Intercepts outbound content (prompts, emails, file uploads, web forms) in the browser before it leaves the endpoint. Provider-agnostic: any web-based AI tool is automatically covered. |
|---|---|
| Policy Engine | Production-ready. GPU-accelerated content analysis. Processes content transiently in GPU memory (milliseconds). Detects PII, evaluates natural-language policies, anonymizes where needed. |
| Desktop Agent | In development (Windows). Extends protection to desktop applications (ChatGPT desktop app, Claude desktop app). Enforcement path validated in the conformance lab. Additional platform support developed based on pilot requirements and client demand. |
| API Proxy | Production-ready. Drop-in proxy between internal systems (agents, RAG pipelines, chatbots, voice agents) and LLM APIs. Primary component for NativeAI Guard Agent DLP & Firewall. |
By default, the Policy Engine processes content transiently in GPU memory with zero persistence. For industries where compliance requires a full record of AI interactions, NativeAI Guard offers optional persistent storage of prompt content and AI responses. The customer controls which mode applies.
| Transient (default) | Content processed exclusively in volatile GPU memory. Memory actively nulled after analysis. No writing to disk, database, logs, or cache. |
|---|---|
| Audit metadata (always) | Policy decision, timestamp, user ID, target domain, enforcement action, triggered policy rule. No prompt content stored in this layer. |
| Persistent (optional) | Full prompt content and AI responses stored, encrypted at rest (AES-256-GCM). Customer-controlled retention period. Enables full audit trail and forensic reconstruction. Available for compliance-driven industries. |
| Admin | Full access: policy configuration, user management, audit logs, system settings |
|---|---|
| Analyst | Audit log access, incident investigation, policy review. No administrative changes. |
| Viewer | Read-only access to dashboards and audit logs |
Authentication: OIDC (PKCE) or SAML 2.0, connected to the customer's existing identity provider (e.g. Entra ID / Azure AD). MFA enforced via IdP.
Compliance policies are not one-size-fits-all. Different departments handle different types of sensitive data and face different regulatory obligations. NativeAI Guard allows administrators to define distinct policy sets and assign them to specific teams, departments, or user groups.
| Group-level policies | Define separate compliance policies per team, department, business unit, or user group. Each group can have its own detection rules, enforcement actions, and allowed AI tools. |
|---|---|
| Example: claims | An insurance company's claims team handles medical data (Art. 321 CP, Art. 84 KVG). Their policy blocks all patient identifiers, diagnosis codes, and treatment details. Enforcement action: Block. |
| Example: HR | HR handles employee PII, salary data, and performance reviews. Their policy detects and anonymizes employee names, compensation figures, and performance assessments. Enforcement action: Anonymize. |
| Example: legal | Legal handles client-privileged communications and M&A data. Their policy blocks content matching privileged communication patterns or deal-related terminology. Enforcement action: Block. |
| IdP group sync | User groups sync from the customer's identity provider (Entra ID / Azure AD). When an employee moves departments in the IdP, their policy assignment updates automatically. |
| Policy inheritance | Organization-wide baseline policies apply to all users. Team-specific policies layer on top, adding stricter rules where needed. No team can be less restrictive than the baseline. |
| Chrome (extension) | Production-ready. Primary supported browser. |
|---|---|
| Edge (extension) | Production-ready. Chromium-based; fully supported. |
| Firefox (extension) | Roadmap. Developed based on client demand. |
| Safari (extension) | Roadmap. Developed based on client demand. |
| Windows Desktop Agent | In development. Extends protection to native desktop apps (ChatGPT, Claude desktop). |
| macOS Desktop Agent | Roadmap. Developed based on pilot requirements and client demand. |
| Linux Desktop Agent | Roadmap. Developed based on pilot requirements and client demand. |
The Browser Extension covers all operating systems (macOS, Linux, Windows) independently. The Desktop Agent is not required for a pilot phase.
NativeAI Guard is provider-agnostic. The Browser Extension operates at the browser layer, which means any web-based LLM service is automatically covered. Named providers currently used by enterprise customers:
NativeAI Guard operates at the browser layer, so every web-based surface where an employee can type, paste, or upload data is protected automatically. The tools named below are examples, not a complete list. Coverage is not restricted to these products: any comparable web service is covered by the same rules, and the list grows with pilot requirements and client demand.
The categories above are illustrative. Any web surface that accepts typed, pasted, or uploaded content falls under the same policy engine, whether or not the product is named here.
| Container runtime | Kubernetes v1.25+ with OCI image support |
|---|---|
| GPU | NVIDIA H100 or H200 GPU nodes for the Policy Engine. Multiple GPU nodes required depending on user count and throughput. This is the primary cost driver for on-premises deployments: customers who do not already operate GPU infrastructure should factor in the hardware investment. |
| Storage | Persistent storage for audit logs (PostgreSQL). Capacity depends on retention period and user count. |
| Network | Outbound connectivity for browser extension communication. All data stays in-perimeter. |
| Security | Restricted Pod Security Standards, default-deny Cilium NetworkPolicies, namespace-bound AES-256-GCM encrypted secrets |
| Delivery | Signed OCI images. Source code never shared. Updates delivered as new image versions. |
Detailed infrastructure sizing is provided during the pilot scoping based on the customer's user count, throughput requirements, and retention policy.
NativeAI Guard creates auditable evidence that AI usage complies with applicable regulations. The following frameworks are addressed:
NativeAI Guard streams structured security events to any SIEM, SOC, SOAR, XDR, or incident management platform. The relevant connector is built and delivered as part of the pilot phase.
| REST API | Production-ready. Structured JSON audit events for all policy decisions. |
|---|---|
| WebSocket | Production-ready. Real-time event streaming. |
| Syslog (RFC 5424) | Roadmap. UDP/TCP, TLS-wrapped. Developed based on client demand. |
| CEF | Roadmap. Standard format accepted by Splunk, Sentinel, QRadar, ArcSight, Elastic, and others. Developed based on client demand. |
| Webhook | Production-ready. For SOAR/ticketing integration (Jira, ServiceNow, PagerDuty). |
| Policy Engine latency | Low hundreds of milliseconds per request. GPU-accelerated, transient GPU memory processing. |
|---|---|
| Browser Extension | No measurable impact on browser performance in normal operation. |
| Availability target | Custom SLA for Enterprise tier. |
| Auto-scaling | Automatic. Policy Engine scales horizontally based on request volume. |
| Updates | Continuous, zero-downtime deployments (ArgoCD) |
|---|---|
| Service levels | Response times, patching windows, and availability commitments are agreed per customer and set out in the service agreement. |
| Security Advisors | Marc-Etienne Cortesi (former CISO Baloise, Director Swiss Financial Sector Cyber Security Centre), Alexander Bösch (Deputy CSO SIX Group) |
| Pilot support | Dedicated Success Manager + weekly status calls |
| Priority partner access | Direct access to the engineering team |
Predictable, per-user pricing. No per-request meters, no consumption-based billing, no hidden fees.
| SME (up to 150 users) | CHF 28,800 flat per year. Core DLP detection, custom policy development, advanced threat analytics, AI governance dashboard, email support. |
|---|---|
| Professional (150 to 2,500) | CHF 16 to CHF 4 per user per month (volume-dependent). All SME features plus SIEM integration, dedicated Customer Success Manager. |
| Enterprise (2,500+) | CHF 4.00 per user per month (volume floor). All Professional features plus on-premises deployment option, 24/7 SOC support, custom SLA. |
NativeAI Guard Agent DLP & Firewall is priced on a metered, usage-based model. The volume of traffic between AI agents varies significantly by use case, making per-user pricing impractical. Pricing is scoped individually based on the customer's architecture and expected throughput.
| Pricing model | Metered, usage-based. Billed according to the volume of API traffic inspected by the proxy. |
|---|---|
| Quote | Custom quote on request. Contact NativeAI for a tailored pricing proposal based on your agent architecture and expected traffic volume. |
| Pilot phase | Included in the standard pilot engagement. Traffic profiling during the pilot period informs the production pricing quote. |
| Fully managed pilot phase | From CHF 5,000. NativeAI runs everything: implementation, policy configuration, deployment, monitoring, reporting. |
|---|---|
| Standard scope | Up to 30 users for one month. The base price of CHF 5,000 covers this scope. |
| Extensions | Expanding the pilot phase to more users (e.g. 100 or 300) or extending the duration beyond one month increases the pilot fee. Contact us with your requirements to receive a quote for the pilot phase. |
| Duration | Standard: one month passive observation. Optional second month with active blocking and anonymization (priced as extension). |
| Deliverable | Report on data leaks found, shadow-AI visibility, AI usage transparency, and cost efficiency analysis. |
| Pilot fee credit | 100% of the pilot fee is credited toward the Year 1 subscription. |
NativeAI Guard occupies the AI DLP / LLM Firewall category. It protects the AI prompt layer that legacy DLP and network security tools were not designed for. The following comparison reflects the state of these product categories as of August 2026.
| Capability | NativeAI Guard | Legacy DLP (Purview, Forcepoint, Symantec, Trellix) | Cloud AI DLP (Nightfall, Cyberhaven, Harmonic) | Platform AI security (Cisco, Palo Alto, Check Point) |
|---|---|---|---|---|
| LLM prompt-layer DLP | Yes | Partial (Edge-only for Purview) | Yes | Partial (bolted on) |
| Agentic AI / XPIA protection | Yes | No | Partial | Partial |
| Swiss data sovereignty | Yes (own servers, CH) | No (US cloud) | No (US cloud) | No (US cloud) |
| US cloud exposure | No | Yes | Yes | Yes |
| Natural-language policy engine | Yes | No (static rules) | Partial | No |
| PII anonymization (not just block) | Yes | No (block/audit) | Partial | No |
| Browser coverage (Chrome + Edge) | Yes | Edge only (Purview) | Yes | Varies |
| Provider-agnostic LLM coverage | Yes | Restricted | Yes | Varies |
| SIEM/SOC integration | Yes | Yes | Partial | Yes |
| Predictable pricing | Per-user, flat | Per-user + PAYG add-ons | Per-user | Platform bundle |
| On-premises option | Yes (Kubernetes) | Yes | No | Varies |
| No vendor lock-in | Yes (independent) | Microsoft ecosystem | Yes | Platform lock-in |
Some of the categories below do the same job as NativeAI Guard, so a buyer chooses one of them. Others cover different surfaces and are meant to run alongside it. This section states which is which, and where the boundary falls.
| AI DLP and LLM firewalls | Cyberhaven, WitnessAI, Nightfall AI, Aurascape, Harmonic Security, nexos.ai, NeuralTrust, Noma Security, Portal26, Strac, Vallum AI, Lasso Security, Lumia Security, Polymer, Credal.ai, ZeroDrift. Same surface and same job as NativeAI Guard. The differences are Swiss jurisdiction, a natural-language policy engine, and anonymization that leaves the prompt usable instead of blocking it. |
|---|---|
| Platform AI security | Cisco AI Defense (Robust Intelligence), Palo Alto (Protect AI), Check Point Infinity (Lakera), SentinelOne (Prompt Security), Cato Networks (Aim Security), F5 (CalypsoAI), CrowdStrike (Pangea), Zscaler (SplxAI), Proofpoint (Acuvity), Tenable (Apex), Snyk (Invariant Labs), Veeam (Securiti.ai). Each of these bought its AI layer. NativeAI Guard replaces that layer only: their firewall, endpoint and SASE products are untouched. A multi-vendor security stack rarely wants its AI controls locked to a single platform. |
As of August 2026, NativeAI is the only Swiss-headquartered, AI-native pure-play in this category. Lakera and Invariant Labs, the two other Swiss entrants, were both acquired by foreign companies in 2025.
| Legacy DLP, CASB and SSE | Microsoft Purview, Forcepoint DLP, Symantec DLP (Broadcom), Trellix DLP, Fortinet DLP, Acronis DeviceLock, Netskope. These enforce on structured channels: email, file shares, endpoints, network traffic, and the Microsoft-native surface. NativeAI Guard enforces on free-form prompt content at the browser layer, across Chrome and Edge, provider-agnostic. Purview does reach unmanaged AI tools through In Transit Protection, though only in Edge for Business, on a consumption meter, using static rules. The practical split: keep them for the structured channels, add NativeAI Guard for the prompt layer. |
|---|---|
| Enterprise AI platforms | Langdock and comparable sanctioned in-house assistants. A platform is a destination: it governs what happens inside it. NativeAI Guard sits on the path and inspects content before it leaves the browser, whatever the destination. A platform is structurally blind to the traffic that never enters it, which is where shadow AI lives. |
| AI red-teaming and model security | HiddenLayer, Cranium AI, Adversa AI, Mindgard. These test and harden models before deployment. NativeAI Guard enforces policy at runtime, on live traffic. Different phase of the lifecycle, no overlap in function. |
1015 Lausanne, Switzerland
nativeai.ch · linkedin.com/company/nativeai-ch
Swiss AI member · La Forge, EPFL Innovation Park