Goes through
Tidy up this agenda for Thursday's planning meeting
Ordinary work isn't touched. Most pastes go through without anyone noticing.
Prism DLP checks every paste, upload and message before ChatGPT, Claude, Copilot or any of 95 other AI tools receives it. Ordinary work goes straight through. What shouldn't leave is taken out or stopped, and the person is told why.
Goes through
Tidy up this agenda for Thursday's planning meeting
Ordinary work isn't touched. Most pastes go through without anyone noticing.
Sent without the personal data
Refund [EMAIL_1] on card [CARD_1], order 88213
The person sees what was found, then sends it with those parts taken out, or continues with a reason your team can read.
Stopped
Paste blocked: this contains a secret key, and gemini.google.com isn't approved for it.
Your security team sees who, where and why. Never the key.
Websites in Chrome and Edge, plus desktop apps and command-line tools on Macs. Set each one to allowed, warn, block or work accounts only, and add any we haven't listed. Prism also shows you which ones are in use, by whom and for how long.
ChatGPTClaudeGeminiMicrosoft Copilot (consumer)Microsoft 365 CopilotPerplexityDeepSeekMistral Vibe (Le Chat)GrokPoeMeta AICharacter.AIYou.comPiDuck.aiQwen ChatKimiZ.ai (GLM)DoubaoERNIE Bot (Wenxin)Tencent YuanbaoRekaVeniceMonicaMerlinAbacus ChatLLMTypingMindOpenRouterLMArenaGensparkManusFelo
Phindv0BoltLovableReplitBlackbox AIJulesDevinFirebase Studio
JasperCopy.aiWritesonicRytrQuillBotGrammarlyWordtuneDeepLHIX AI
Gemini Notebook (NotebookLM)ElicitConsensusSciSpacesciteLinerChatPDFHumata
OtterFirefliesFathomtl;dvRead AIGranola
MidjourneyLeonardoIdeogramRunwayPikaLumaKlingSoraSunoUdioElevenLabsKreaAdobe FireflySynthesiaHeyGenGammaBeautiful.aiDescriptHiggsfield
Google AI StudioOpenAI PlatformClaude Developer PlatformAzure AI FoundryGroqCloud
ChatGPT for MacClaude for MacCursor
Claude CodeCodex CLIGemini CLIAiderCursor CLIopencodeGoose
The same site can be your company's ChatGPT workspace or someone's personal account, with very different terms for your data. Prism reads which account is signed in on ChatGPT, Claude, Gemini, Grok and Perplexity, so you can allow one and stop the other. For a personal account it records only the email domain, never the address.
Prism swaps detected values for placeholders before anything is stored, queued or logged. Your security team can see that a card number went to an AI tool, who sent it and why, without Prism ever holding the number.
Pasted
Refund jane.doe@example.com on card 4242 4242 4242 4242, order 88213.
Stored
Refund [EMAIL_1] on card [CARD_1], order 88213.
Every organisation starts in Observe. When you're happy with what Prism catches, switch on warnings, then blocking. One setting in the console, no redeploy.
Record every match and interrupt no one, while you check what Prism finds.
Show people what was found and let them continue with a reason.
Block critical matches outright and warn on the borderline ones.
Prism installs through the tools you already manage devices with. Staff don't install, sign in or configure anything. See the rollout
{
"apiUrl": { "Value": "https://api.prism-dlp.com" },
"apiKey": { "Value": "pk_…" }
}Read security and privacy and the privacy policy, or send us your security questionnaire.
No. Most pastes, uploads and messages go straight through. Prism steps in only when something sensitive is in them, and you choose per AI tool whether it's allowed, gets a warning, is blocked, or is allowed only from work accounts.
The event: who, which AI tool, what kind of data was found and what happened, with any reason the person gave. Detected secrets and personal data are replaced with placeholders before anything is stored, so the original values are never kept.
Google Chrome and Microsoft Edge on any computer, through the Prism extension, and Macs through the Prism agent, which also covers AI desktop apps, AI command-line tools and files copied to USB drives or cloud folders. A Windows agent is next.
By IT, with the tools you already use: the extension is force-installed through Google Admin or Chrome policy, and the Mac agent is a signed, notarised package you push with Jamf or another MDM. There's nothing for staff to set up.
Yes, and they should. Prism tells people exactly what it found and why when it steps in, and we give you a staff notice to send before rollout that explains what's checked and what isn't.
In the UK and EU: the database in London and the service in the EU. Each organisation's data is isolated from every other's. We don't sell data, use it for advertising, or use it to train AI models.
We set up your organisation in Prism, you deploy it to a pilot group in Observe mode, and after a couple of weeks we go through what it found together. The pilot is free.
Deploy to a pilot group in Observe mode and see what's going into AI tools before you decide anything.