SafePrompt
Driven by an internal or external SOC of your choice. The SafePrompt agent raises and logs alerts for non-invasive visibility of AI usage, malicious domains and SaaS.
Belgian publisher · On-prem / appliance · SOC-driven · Non-invasive GDPR approach
Generative AI (ChatGPT, Claude, Copilot) speeds up your teams. It also creates Shadow AI and Shadow SaaS: unapproved tools outside IT oversight. Source code, personal data and trade secrets leave every day for third-party servers, not counting malicious domains visited from the browser.
The limits of traditional security tools
Proxies and firewalls act too late: either they block AI (frustration) or they let textual content through without inspection. Network domain lists also struggle to keep up with daily threat pace. For GDPR and trade secrets, that is a blind spot.
The solution: SafePrompt by CNL
SafePrompt deploys a local inspection agent in the browser: DLP for prompts and files, Shadow AI / Shadow SaaS mapping, and optionally alert or block malicious domains. The product is driven by an internal or external SOC (your choice): every agent alert is logged to keep a non-invasive view of usage across the company.
From browser to the board
Browser agent
AI DLP, domains and Shadow SaaS intercepted locally before sending.
SOC (report / exposure)
Logged alerts, GDPR report mode or disclosed exposure mode.
Legal / executive reports
Fine estimates, summaries and evidence of controlled usage.
Try SafePrompt in our interactive sandbox
See how the SafePrompt agent intercepts, audits and anonymizes requests (prompts and attachments) locally in the client, in milliseconds, before they reach AI models.
- Absolute confidentiality: sensitive data never leaves the browser.
- Real-time interception: instant detection on typing or file upload.
- Multi-device: full experience on desktop and mobile.
Key capabilities
Shadow AI detection
Real-time mapping of unauthorized AI tools on your network.
Active DLP
Blocks or redacts PII, secrets and code before they leave the browser.
Malicious domains
Option: alert or block in the browser. Lists refreshed daily + SOC alert.
Shadow SaaS
Option: alert or block unauthorized SaaS, with immediate SOC escalation.
On-prem & appliance
Deploy on your servers or on a physical micro-server shipped with the licence.
Internal or external SOC
Internal or external SOC. GDPR report mode or exposure mode (disclosed to the user) for investigation.
Alert or block, with the SOC in the loop
On top of AI DLP, SafePrompt can act in the browser on two risk families. For each case: alert the user or block the page, and raise a SOC alert.
Malicious domains
- Detection in the browser (not only at the firewall)
- Domain lists updated every day
- User alert mode or page block
- Alert logged and visible to the SOC
Shadow SaaS
- Control of unauthorized SaaS and cloud services
- Stops ghost usage outside IT / security policy
- User alert mode or access block
- Alert logged for SOC governance
- Users can request access (reason + work email): the request is sent to the SOC
Non-invasive visibility of enterprise usage
SafePrompt is managed by an internal or external SOC, depending on your organization. All agent alerts are logged to keep a clear view, without intrusive monitoring of work content, on:
- AI usage: Shadow AI, risky prompts, data-leak attempts
- Malicious domains: flagged or blocked access, history for the SOC
- Shadow SaaS: unauthorized cloud services detected, alerted or blocked
Two SOC modes for AI alerts
For AI, the SOC has two escalation levels. The choice depends on criticality and legal framework:
Report mode (default · GDPR)
- AI alerts are reported only (metadata, risk type, timestamp)
- Prompt and file content is not exposed in the SOC
- Fits a non-invasive, GDPR-respectful approach
- Enough for governance and day-to-day operations
Exposure mode (critical use cases)
- Available for high-risk contexts (investigation, review)
- The prompt and/or files are visible in the SOC alert
- Enables detailed SOC review and investigation
- GDPR obligation: this mode must be clearly disclosed to the user (transparency)
The SOC also uses this data to estimate possible GDPR fine costs if SafePrompt had not been in place (personal-data exposure, leaks to third-party AI/SaaS), and to generate reports for legal or commercial / executive teams.
GDPR fine estimation
- “Without SafePrompt” scenarios based on real alerts
- Personal-data exposure / leaks to AI and third-party SaaS
- Order of magnitude of financial risk (fines)
- Quantified argument for leadership
Legal & executive reports
- Report exports for the legal team
- Summaries usable in committee / board
- Evidence of controlled usage (AI, domains, SaaS)
- Non-invasive view, without reading business content (except disclosed exposure mode)
Goal: a non-invasive view by default, with an optional transparent exposure mode for critical cases, driven by the SOC, useful for security as well as legal and business.
Compliance & regulated sectors
Built for the strictest international requirements.
Frequently asked questions about SafePrompt
Short answers for CISOs, security, DPOs and leadership.
Does SafePrompt replace my DLP or firewall?
No. SafePrompt complements your stack by acting in the browser, where file/email DLP and network filtering do not see AI prompts, Shadow SaaS or some web access.
Who drives alerts: internal or external SOC?
Both are possible. You choose an internal SOC or an external SOC depending on your organization. All agent alerts are logged for a clear view of usage.
Does the SOC read prompt content?
By default, no. Report mode only sends metadata (non-invasive GDPR approach). Exposure mode can make the prompt or files visible for investigation and must be clearly disclosed to the user.
Does SafePrompt cover ChatGPT, Copilot and Claude?
Yes. The agent protects generative AI usage in the browser (prompts and files), with anonymization or blocking according to policy.
What does the malicious domains / Shadow SaaS option do?
On top of AI DLP, SafePrompt can alert or block malicious domains (daily lists) and unauthorized SaaS, with a SOC alert. On SaaS block or alert, users can request access with work email and reason: the request is sent to the SOC.
How do I request access to a blocked SaaS?
From the alert or block screen, the user clicks Request access, explains why the tool is needed and leaves a work email. The SOC receives the request for validation.
How do I get a demo or a quote?
Use the sandbox, request a quote from this page, or contact loic.netten@cybernetten.be.
BLOG RESOURCES (SEO)
Technical reads on AI DLP, Shadow AI / GDPR and browser protection.