Early access — design partners wanted

An Enterprise AI Data Firewall That Enforces Your Policy on Every Employee Prompt.

Redaction, risk scoring, and audit logging — across browsers, desktop apps, and APIs.

See the demo

Per-seat pricing · Design partners get preferred terms.

Browser extension · Desktop agent · API gateway

Charcoal lines passing through a precise policy boundary and emerging ordered
Live inspection
Prompt

Summarize the attached term sheet for the Meridian acquisition

BLOCKEDPolicy: M&A / material non-public information
Logged · Attributed to user & device · Exported to SIEM

The Controls Didn't Keep Up with the Adoption.

Shadow AI Is the New Shadow IT

Employees paste contracts, source code, customer records, and deal terms into ChatGPT, Claude, Copilot, and a hundred tools you've never heard of. Traditional DLP was built for files and email, not conversations.

Your AI Policy Is a PDF

Most organizations have an acceptable-use policy for AI. Almost none can enforce it at the moment someone hits Enter.

You Can't Answer the Question

When a regulator, a customer, or your own board asks “what has gone into these models,” the honest answer today is “we don't know.” That answer has a cost.

A rule nobody can enforce is a liability, not a control.
Most

Of AI use at work happens in tools IT never approved

One prompt

Is all it takes to move regulated data outside your boundary

No record

Is the usual answer when someone asks what went into the models

Shaped by conversations with security leaders about what they actually needed — not what vendors wanted to sell them.

David Cosgrove, founder of PolicyGuardrail.AI

Built by Someone Who's Spent 30 Years Inside the Enterprise.

PolicyGuardrail is built by David Cosgrove, a technology and digital consultant with three decades serving enterprise clients, including Fortune 20 companies. It's a product of Executive Committee Group LLC (XCG), Connecticut, USA. Every early-access inquiry goes directly to the founder — you'll hear back from David, not a queue.

Enforcement at the Point of Use. Not Alerts after the Fact.

Three steps from “we hope people behave” to “we know what happened.”

Connect

Deploy where your people use AI: a browser extension for web tools, a desktop agent for native apps and clipboard, and an API gateway for programmatic access. Pilot in monitor-only mode before you enforce anything.

Write Policy in Plain Language

Your policy reads like your policy: “Never send customer account numbers to any external AI.” “Engineers may use AI for code, but never with production credentials.” PolicyGuardrail translates intent into enforcement and includes templates for PII, PHI, PCI, secrets, source code, and material non-public information.

Enforce, Redact, and Record

Prompts and responses are inspected in real time. Low-risk content goes through. Sensitive fields can be redacted so the work still gets done. True violations are blocked with a message that tells the user why. Decisions are logged with user, device, policy, and outcome, and can be streamed to your SIEM.

POLICY  Customer PII — external AI
SCOPE   All users · All external models
RULE    Redact names, phone numbers, account and claim IDs.
        Block if more than 25 records appear in one prompt.
ACTION  Redact → allow · Block on threshold · Notify security
WRITTEN BY  Compliance team, not engineering

The goal isn't to stop people from using AI. It's to make the safe path the easy path. Intelligent redaction means the large majority of everyday AI use goes through untouched or with sensitive fields masked — productivity stays, exposure goes.

Already Have an AI Policy? Upload It.

Most organizations wrote an AI acceptable-use policy and filed it away. PolicyGuardrail reads your existing policy document and converts it into enforceable rules — the same PDF that sits in your handbook becomes redaction, blocking, and logging at the moment someone hits Enter.

  • Upload your policy as PDF or Word
  • Review the rules PolicyGuardrail extracts, edit in plain language
  • Deploy to the browser extension in monitor mode first

Policy-to-rules is the core of our early access build.

Policy extraction
Acceptable-Use-Policy.pdf
Extracted rules

RULE Never send customer account numbers to external AI → Redact + notify

RULE No client documents in unapproved tools → Block

No AI Policy Yet? Most Companies Don't.

We've built a fill-in-the-blanks AI acceptable-use policy template — the same structure PolicyGuardrail enforces. Design partners work through it with us as part of onboarding: adapt it to your organization, then enforce it with one click.

Ask about the policy template →

What It Does

Real-Time Inspection

Prompts and responses, both directions, scored before anything leaves your boundary.

RISK SCORE87 / 100
MATCHED · M&A term sheet · Deal codename

Intelligent Redaction

Mask sensitive fields and let the rest of the sentence through, so the work still gets done.

Draft an email to [NAME] at [PHONE] about claim [CLAIM_ID]
REDACTED · 3 fields masked · Prompt delivered

Plain-Language Policy

Rules written by compliance, readable by everyone, enforced by the firewall.

Risk Scoring

Every interaction scored by content, user, destination, and context so you can tune enforcement instead of guessing.

Smart Model Routing

Send sensitive workloads to approved or private models automatically; let low-risk traffic use whatever tool the employee chose.

Audit Trail & Reporting

Attributed, exportable, board-ready. Answer “what went into the model” in one query.

Designed to Fit Common Stacks.

Browser Extension

Available now in early access

Inspects prompts in ChatGPT, Claude, Gemini, and Microsoft Copilot without network changes.

Desktop Agent

Planned

Windows and macOS. Native apps, clipboard, and IDE plugins.

API Gateway

Planned

Proxy for programmatic AI access with token-level controls and usage analytics.

Command Center

Real-time dashboard, policy management, SIEM integration, audit logs. One place to see all AI traffic across the organization.

How It Deploys

Cloud

Fastest start. Managed by PolicyGuardrail.

Private Cloud

Your tenant, your region, your retention policy.

On-Premise

Behind your firewall. Kubernetes or bare metal. Air-gapped deployments can be discussed for government and highly regulated environments.

Planned Integrations

Designed for SSO via Okta and Microsoft Entra · SIEM export to Splunk and Microsoft Sentinel · Compatible with OpenAI, Anthropic, Google, Microsoft Copilot, and self-hosted models

Pilot Plan: 4–6 Weeks

  1. Discovery and SSO
    Align on data classes, users, and policy scope.
  2. Monitor mode
    See real traffic without blocking anything.
  3. Enforcement rollout
    Turn on redaction and blocks by group.
  4. Tuning and go-live
    Adjust thresholds and hand off to your team.

Where we are.

Built in the open with design partners. Here’s what’s real today and what’s next.

Real Today

  • Browser extension for ChatGPT, Claude, Gemini, and Microsoft Copilot.
  • Command Center with live dashboard, policy management, and audit logs.
  • Upload an existing AI policy and extract enforceable rules automatically.
  • Per-seat pricing with preferred terms for design partners.

Next Up

  • Desktop agent for Windows and macOS native apps and clipboard.
  • API gateway for programmatic AI access with token-level controls.
  • SSO via Okta and Microsoft Entra; SIEM export to Splunk and Sentinel.
  • On-premise and air-gapped deployment options for regulated environments.

Built for the People Who Get the Call.

Security / CISO

You can't block AI and you can't ignore it. PolicyGuardrail is designed to give visibility into AI interactions, enforcement you control, and evidence when someone asks.

Legal & Compliance

Privilege, retention, data residency, and sector rules don't pause because a tool is convenient. Write the policy once in plain language and apply it consistently across prompts.

Engineering & Platform

One governed gateway instead of guardrails bolted onto every app. Production secrets and customer data can be kept away from third-party models, while developers keep the tools they like.

Designed to Be Trusted with the Traffic It Inspects.

  • Inspection can be deployed inside your boundary; retention is configurable to your policy.
  • Encrypted in transit and at rest.
  • Customer data is not used to train models.
  • Audit access to what PolicyGuardrail records about your organization.

Controls Mapped to

GDPR · HIPAA · PCI DSS

Policy templates and controls mapped to these frameworks. Documentation is being prepared; if you have questions, reach out.

Ask about security and compliance

See It Inspect, Redact, and Block in Real Time.

Try the live demo now.

See the demo

Questions Security Teams Ask First

Purview is strong inside the Microsoft estate — Microsoft 365, Copilot, and files you own. It does not sit between your employee and ChatGPT, Claude, Gemini, or the long tail of AI tools they signed up for with a work email. PolicyGuardrail is vendor-neutral and enforces at the prompt, so the same policy applies wherever the text is going. Teams typically run both: Purview for Microsoft data estate, PolicyGuardrail for AI egress.

Questions or Early-Access Interest?

Reach out if you'd like to learn more or explore a design partnership with PolicyGuardrail.AI.

Every inquiry goes straight to our founder. You'll hear back from David Cosgrove directly.