Stop sensitive data reaching AI tools, without stopping people using them.

Prism DLP checks every paste, upload and message before ChatGPT, Claude, Copilot or any of 95 other AI tools receives it. Ordinary work goes straight through. What shouldn't leave is taken out or stopped, and the person is told why.

Three pastes, three outcomes Examples
  1. claude.aiTidy up this agenda for Thursday's planning meeting
  2. chatgpt.comRefund jane.doe@example.com on card 4242 4242 4242 4242, order 88213
  3. gemini.google.comWhy does this fail? AWS_SECRET_ACCESS_KEY=wJalr••••••••

Goes through

Tidy up this agenda for Thursday's planning meeting

Ordinary work isn't touched. Most pastes go through without anyone noticing.

Sent without the personal data

Refund [EMAIL_1] on card [CARD_1], order 88213

The person sees what was found, then sends it with those parts taken out, or continues with a reason your team can read.

Stopped

Paste blocked: this contains a secret key, and gemini.google.com isn't approved for it.

Your security team sees who, where and why. Never the key.

The AI tools people actually use. All 98 of them.

Websites in Chrome and Edge, plus desktop apps and command-line tools on Macs. Set each one to allowed, warn, block or work accounts only, and add any we haven't listed. Prism also shows you which ones are in use, by whom and for how long.

Chat assistants

ChatGPTClaudeGeminiMicrosoft Copilot (consumer)Microsoft 365 CopilotPerplexityDeepSeekMistral Vibe (Le Chat)GrokPoeMeta AICharacter.AIYou.comPiDuck.aiQwen ChatKimiZ.ai (GLM)DoubaoERNIE Bot (Wenxin)Tencent YuanbaoRekaVeniceMonicaMerlinAbacus ChatLLMTypingMindOpenRouterLMArenaGensparkManusFelo

Building and coding

Phindv0BoltLovableReplitBlackbox AIJulesDevinFirebase Studio

Writing and translation

JasperCopy.aiWritesonicRytrQuillBotGrammarlyWordtuneDeepLHIX AI

Research

Gemini Notebook (NotebookLM)ElicitConsensusSciSpacesciteLinerChatPDFHumata

Meeting notes

OtterFirefliesFathomtl;dvRead AIGranola

Images, video and audio

MidjourneyLeonardoIdeogramRunwayPikaLumaKlingSoraSunoUdioElevenLabsKreaAdobe FireflySynthesiaHeyGenGammaBeautiful.aiDescriptHiggsfield

Developer platforms

Google AI StudioOpenAI PlatformClaude Developer PlatformAzure AI FoundryGroqCloud

Mac apps

ChatGPT for MacClaude for MacCursor

Command-line tools

Claude CodeCodex CLIGemini CLIAiderCursor CLIopencodeGoose

Work accounts in, personal accounts out

The same site can be your company's ChatGPT workspace or someone's personal account, with very different terms for your data. Prism reads which account is signed in on ChatGPT, Claude, Gemini, Grok and Perplexity, so you can allow one and stop the other. For a personal account it records only the email domain, never the address.

chatgpt.comWork accounts only
Company workspace
Checked as normal
Personal account gmail.com
Stopped: personal account on chatgpt.com

We keep the evidence, not the secret

Prism swaps detected values for placeholders before anything is stored, queued or logged. Your security team can see that a card number went to an AI tool, who sent it and why, without Prism ever holding the number.

Pasted

Refund jane.doe@example.com on card 4242 4242 4242 4242, order 88213.

Stored

Refund [EMAIL_1] on card [CARD_1], order 88213.

Start quiet, then tighten

Every organisation starts in Observe. When you're happy with what Prism catches, switch on warnings, then blocking. One setting in the console, no redeploy.

  1. Observe Week 1

    Record every match and interrupt no one, while you check what Prism finds.

  2. Warn Then

    Show people what was found and let them continue with a reason.

  3. Enforce When ready

    Block critical matches outright and warn on the borderline ones.

Rolled out by IT, invisible until it matters

Prism installs through the tools you already manage devices with. Staff don't install, sign in or configure anything. See the rollout

  • Chrome and Edge: force-installed by Google Admin, Chrome policy or your MDM.
  • Macs: a signed, notarised package and a configuration profile, pushed with Jamf or any MDM.
  • Alerts where you work: Slack, Microsoft Teams, Splunk, signed webhooks or the Events API. Integrations guide
Google Admin · Policy for extensions
{
  "apiUrl": { "Value": "https://api.prism-dlp.com" },
  "apiKey": { "Value": "pk_…" }
}

Built to pass your own security review

Cyber Essentials Plus
Certified, with ISO 27001 certification underway.
UK and EU hosting
Database in London, service in the EU. Each organisation isolated.
Redacted before storage
Secrets and personal data never reach our database.
Not for training
We don't sell data, advertise with it, or train AI models on it.

Read security and privacy and the privacy policy, or send us your security questionnaire.

Questions IT and security teams ask

Does Prism stop people using AI tools?

No. Most pastes, uploads and messages go straight through. Prism steps in only when something sensitive is in them, and you choose per AI tool whether it's allowed, gets a warning, is blocked, or is allowed only from work accounts.

What does Prism store?

The event: who, which AI tool, what kind of data was found and what happened, with any reason the person gave. Detected secrets and personal data are replaced with placeholders before anything is stored, so the original values are never kept.

Which computers and browsers does it cover?

Google Chrome and Microsoft Edge on any computer, through the Prism extension, and Macs through the Prism agent, which also covers AI desktop apps, AI command-line tools and files copied to USB drives or cloud folders. A Windows agent is next.

How is it deployed?

By IT, with the tools you already use: the extension is force-installed through Google Admin or Chrome policy, and the Mac agent is a signed, notarised package you push with Jamf or another MDM. There's nothing for staff to set up.

Will staff know it's there?

Yes, and they should. Prism tells people exactly what it found and why when it steps in, and we give you a staff notice to send before rollout that explains what's checked and what isn't.

Where is our data hosted?

In the UK and EU: the database in London and the service in the EU. Each organisation's data is isolated from every other's. We don't sell data, use it for advertising, or use it to train AI models.

What does a pilot involve?

We set up your organisation in Prism, you deploy it to a pilot group in Observe mode, and after a couple of weeks we go through what it found together. The pilot is free.

Try Prism on your own team, free

Deploy to a pilot group in Observe mode and see what's going into AI tools before you decide anything.