ESC
DIGITAL SOVEREIGNTY & AI SECURITY

SafePrompt

Driven by an internal or external SOC of your choice. The SafePrompt agent raises and logs alerts for non-invasive visibility of AI usage, malicious domains and SaaS.

Belgian publisher · On-prem / appliance · SOC-driven · Non-invasive GDPR approach

Generative AI (ChatGPT, Claude, Copilot) speeds up your teams. It also creates Shadow AI and Shadow SaaS: unapproved tools outside IT oversight. Source code, personal data and trade secrets leave every day for third-party servers, not counting malicious domains visited from the browser.

The limits of traditional security tools

Proxies and firewalls act too late: either they block AI (frustration) or they let textual content through without inspection. Network domain lists also struggle to keep up with daily threat pace. For GDPR and trade secrets, that is a blind spot.

The solution: SafePrompt by CNL

SafePrompt deploys a local inspection agent in the browser: DLP for prompts and files, Shadow AI / Shadow SaaS mapping, and optionally alert or block malicious domains. The product is driven by an internal or external SOC (your choice): every agent alert is logged to keep a non-invasive view of usage across the company.

From browser to the board

01

Browser agent

AI DLP, domains and Shadow SaaS intercepted locally before sending.

02

SOC (report / exposure)

Logged alerts, GDPR report mode or disclosed exposure mode.

03

Legal / executive reports

Fine estimates, summaries and evidence of controlled usage.

Try SafePrompt in our interactive sandbox

See how the SafePrompt agent intercepts, audits and anonymizes requests (prompts and attachments) locally in the client, in milliseconds, before they reach AI models.

  • Absolute confidentiality: sensitive data never leaves the browser.
  • Real-time interception: instant detection on typing or file upload.
  • Multi-device: full experience on desktop and mobile.

Key capabilities

Shadow AI detection

Real-time mapping of unauthorized AI tools on your network.

Active DLP

Blocks or redacts PII, secrets and code before they leave the browser.

Malicious domains

Option: alert or block in the browser. Lists refreshed daily + SOC alert.

Shadow SaaS

Option: alert or block unauthorized SaaS, with immediate SOC escalation.

On-prem & appliance

Deploy on your servers or on a physical micro-server shipped with the licence.

Internal or external SOC

Internal or external SOC. GDPR report mode or exposure mode (disclosed to the user) for investigation.

BROWSER OPTION

Alert or block, with the SOC in the loop

On top of AI DLP, SafePrompt can act in the browser on two risk families. For each case: alert the user or block the page, and raise a SOC alert.

Malicious domains

  • Detection in the browser (not only at the firewall)
  • Domain lists updated every day
  • User alert mode or page block
  • Alert logged and visible to the SOC

Shadow SaaS

  • Control of unauthorized SaaS and cloud services
  • Stops ghost usage outside IT / security policy
  • User alert mode or access block
  • Alert logged for SOC governance
  • Users can request access (reason + work email): the request is sent to the SOC
SOC OPERATIONS

Non-invasive visibility of enterprise usage

SafePrompt is managed by an internal or external SOC, depending on your organization. All agent alerts are logged to keep a clear view, without intrusive monitoring of work content, on:

  • AI usage: Shadow AI, risky prompts, data-leak attempts
  • Malicious domains: flagged or blocked access, history for the SOC
  • Shadow SaaS: unauthorized cloud services detected, alerted or blocked

Two SOC modes for AI alerts

For AI, the SOC has two escalation levels. The choice depends on criticality and legal framework:

Report mode (default · GDPR)

  • AI alerts are reported only (metadata, risk type, timestamp)
  • Prompt and file content is not exposed in the SOC
  • Fits a non-invasive, GDPR-respectful approach
  • Enough for governance and day-to-day operations

Exposure mode (critical use cases)

  • Available for high-risk contexts (investigation, review)
  • The prompt and/or files are visible in the SOC alert
  • Enables detailed SOC review and investigation
  • GDPR obligation: this mode must be clearly disclosed to the user (transparency)

The SOC also uses this data to estimate possible GDPR fine costs if SafePrompt had not been in place (personal-data exposure, leaks to third-party AI/SaaS), and to generate reports for legal or commercial / executive teams.

GDPR fine estimation

  • “Without SafePrompt” scenarios based on real alerts
  • Personal-data exposure / leaks to AI and third-party SaaS
  • Order of magnitude of financial risk (fines)
  • Quantified argument for leadership

Legal & executive reports

  • Report exports for the legal team
  • Summaries usable in committee / board
  • Evidence of controlled usage (AI, domains, SaaS)
  • Non-invasive view, without reading business content (except disclosed exposure mode)

Goal: a non-invasive view by default, with an optional transparent exposure mode for critical cases, driven by the SOC, useful for security as well as legal and business.

Compliance & regulated sectors

Built for the strictest international requirements.

RGPD HIPAA EU AI Act SOC 2 ISO 27001 HDS PCI-DSS
USE CASES

Healthcare, finance, SMEs: concrete use cases

SafePrompt adapts to your sector constraints — see how the agent addresses specific stakes in healthcare, finance and SMEs.

See use cases
FAQ

Frequently asked questions about SafePrompt

Short answers for CISOs, security, DPOs and leadership.

Does SafePrompt replace my DLP or firewall?

No. SafePrompt complements your stack by acting in the browser, where file/email DLP and network filtering do not see AI prompts, Shadow SaaS or some web access.

Who drives alerts: internal or external SOC?

Both are possible. You choose an internal SOC or an external SOC depending on your organization. All agent alerts are logged for a clear view of usage.

Does the SOC read prompt content?

By default, no. Report mode only sends metadata (non-invasive GDPR approach). Exposure mode can make the prompt or files visible for investigation and must be clearly disclosed to the user.

Does SafePrompt cover ChatGPT, Copilot and Claude?

Yes. The agent protects generative AI usage in the browser (prompts and files), with anonymization or blocking according to policy.

What does the malicious domains / Shadow SaaS option do?

On top of AI DLP, SafePrompt can alert or block malicious domains (daily lists) and unauthorized SaaS, with a SOC alert. On SaaS block or alert, users can request access with work email and reason: the request is sent to the SOC.

How do I request access to a blocked SaaS?

From the alert or block screen, the user clicks Request access, explains why the tool is needed and leaves a work email. The SOC receives the request for validation.

How do I get a demo or a quote?

Use the sandbox, request a quote from this page, or contact loic.netten@cybernetten.be.

BLOG RESOURCES (SEO)

Technical reads on AI DLP, Shadow AI / GDPR and browser protection.

Quote request

Describe your need. I will get back to you within 24 hours at the address you provide.