Monitors every major AI surface
“Your network DLP sees the tunnel. We detect what's inside.”
AI chats are invisible to your security tools. AIovert makes them visible.
Every paste into ChatGPT without a DPA is also a GDPR Article 28 breach, with exposure up to €20M or 4% of global turnover.
- Unapproved processor: every paste breaches Art. 28.
- The breach clock: starts the moment data leaves (Art. 33).
- Audit evidence: export the log when asked.
Deploy. Comply. Prove.
- Deploy in minutes: Google Workspace or Intune. Up to 23 AI tools covered instantly.
- Comply automatically: 29 data types detected on-device, under 5ms. Mapped to GDPR, EU AI Act, DORA.
- Prove to auditors: DPIA templates in 4 languages. Audit logs export to CSV, JSON, SIEM.
This text contains an NHS number and an IBAN. Every paste into ChatGPT sends your data to a third party you have no contract with.
Block the leak. Log the compliance evidence.
- Guard blocks: the paste is cancelled on-device. Nothing leaves the browser.
- Work continues, masked: one click pastes a safe copy with placeholders, re-checked before it goes out.
- Employees learn: an in-the-moment explanation, so incidents drop without punitive friction.
- Monitor logs: every event tagged with severity, user, tool, and regulation. Export to CSV, JSON, or SIEM.
You can't protect what you don't know exists.
Employees use AI tools you never approved. Shadow AI Discovery maps every domain: first seen, users, data types leaked.
- New tool flags: alerted within 14 days of first use.
- Full exposure map: events, users, and data types per tool.
The only AI DLP with a built-in Compliance Hub.
Every template, mapping, and report your auditor will ask for. Pre-built, pre-filled, four languages.
Business tier, from €975/mo. One DPIA template alone saves €5K to €10K in legal time.
Zero raw data. Ever.
Classification runs entirely inside the employee's browser. What reaches our servers is never the text that was typed or pasted.
Stays inside the browser
What AIovert receives
Field
Example
DataType label
NHS_NUMBER, IBAN, EU_NATIONAL_ID
AI tool domain
chatgpt.com
SHA-256 hash
one-way, deduplication only
User email
for risk scoring
Timestamp
client + server
One audit finding costs more than a decade of protection.
The question isn't whether you can afford AIovert. It's whether you can afford the incident that makes the regulator knock.
$4.4M
Average data breach cost
241
Days to identify and contain a breach
40 h
Compliance prep per quarter
Average breach cost and the 241-day mean time to identify and contain a breach are industry benchmarks from IBM's Cost of a Data Breach Report 2025, not AIovert measurements.
Without AIovert
With AIovert
No record of what employees paste into AI tools
Every prompt classified in under 5ms, on-device
72h GDPR clock starts the moment data leaves
Tamper-evident audit log, always ready (Art. 32)
40+ hours of manual DPO prep per audit
8 h/week back for your security team
Breaches take 241 days on average to identify and contain
Pays for itself after one avoided fine
What's actually at stake when data reaches an LLM.
Six vectors organisations consistently underestimate.
GDPR violations
Unvetted sub-processor (Art. 28). No technical control (Art. 32). 72h breach clock (Art. 33).
EU AI Act · August 2026
Transparency duties apply (Art. 50) and regulators gain enforcement powers, including over the AI literacy duty (Art. 4). No evidence without monitoring.
DORA · Financial services
ICT risk management (Art. 9). IBAN and policy number detection built in.
LLM training exposure
Inputs can be retained for fine-tuning. No way to retrieve it once sent.
Intellectual property
Source code and trade secrets can become training data. Invisible to network DLP.
Contracts and client data
Deal terms and patient records carry confidentiality and Art. 9 obligations.
Built for regulated industries.
29 data types, validated checksums, sector-specific patterns.
Financial services
IBAN, SWIFT, policy numbers
DORA Article 9 ready
Healthcare
NHS numbers, patient records, health IDs
GDPR Art. 9 + NIS2
Legal
Privilege markers, contracts, NDAs
Professional secrecy + Art. 28
Insurance
Policy numbers, claims, underwriting records
EIOPA + DORA Art. 9
SaaS and tech
API keys, JWT, private keys, crypto wallets
SOC 2 + GDPR Art. 32
Why Forcepoint, Symantec, and Microsoft Purview do not cover AI.
Same blind spot every time: they watch the wire, not the browser.
Network DLP (Forcepoint, Symantec)
Sees the tunnel, not the prompt inside.
Endpoint DLP
Watches files and USB. Not browser pastes.
CASB / SSE
Sees app connections, not text content.
Microsoft Purview
E5 licensing, 6-month rollout, generic policies only.
The gap AIovert closes: Detection runs in-browser, before data touches the network. Your DLP keeps working; AIovert covers what it can't.
AI data loss prevention, answered.
What AIovert is, how on-device blocking works, and what it means for compliance.
AIovert is an EU-based, on-device browser DLP tool that classifies and blocks sensitive data before it is entered into consumer AI tools such as ChatGPT, Claude and Gemini. It covers 23 AI tools, logs compliance evidence for GDPR, the EU AI Act, and DORA, and the raw content never leaves the browser.
The extension classifies what an employee pastes, types, or uploads on-device, in under 5 milliseconds, across 29 sensitive data types. Guard cancels a risky paste before it reaches the AI tool and offers a one-click masked copy so work continues; Monitor logs every event with severity, user, tool, and regulation tags.
No. Classification happens entirely in the browser, and the raw content is never stored, transmitted, or logged. Only the classification label (for example SSN or API_KEY), the AI tool's domain, the action, a timestamp, and a one-way SHA-256 hash used for deduplication ever leave the device.
23 AI tools out of the box, including ChatGPT, Claude, Gemini, Microsoft Copilot, Perplexity, Grok, Mistral, DeepSeek, and Poe. Business and Enterprise plans can add custom surfaces on top.
About 15 minutes. The extension is force-installed via Google Workspace Admin or Microsoft Intune: no proxy, no SSL inspection, no certificates, and no action required from employees.
Yes. Every blocked or logged event is mapped to GDPR, EU AI Act, and DORA provisions, and the Compliance Hub provides pre-built DPIA templates in four languages, a GDPR Article 32 report, and audit logs exportable to CSV, JSON, or a SIEM.
Per seat, billed annually: Starter €15/seat/mo (2-seat minimum), Growth €29/seat/mo (5-seat minimum), Business €65/seat/mo (15-seat minimum). Month-to-month pricing is also available at €18/€35/€78. No setup fees, cancel anytime. See /pricing for the full breakdown.
Entirely in the EU (Frankfurt region). The dashboard, audit logs, and event data never leave the EU, and the raw content of what an employee typed or pasted is never transmitted or stored anywhere, only the classification label, domain, action, timestamp, and a one-way hash.