ESC
DIGITAL SOVEREIGNTY & AI SECURITY

SafePrompt

Local DLP extension + SOC console. SafePrompt protects prompts, files, transfers, SaaS, extensions and phishing, with logged alerts and non-invasive visibility.

Belgian company · Sovereignty · On-prem / appliance · GDPR-minded

Generative AI (ChatGPT, Claude, Copilot) speeds up your teams. It also creates Shadow AI, Shadow SaaS and uncontrolled browser extensions. Code, personal data and secrets leave via prompts, files or WeTransfer, not counting phishing and malicious domains.

The limits of traditional security tools

Proxies and firewalls act too late: either they block AI (frustration) or they let text and attachments through without fine-grained inspection. Network lists also struggle with phishing, ghost SaaS and add-ons. For GDPR and trade secrets, that is a blind spot.

The solution: SafePrompt by CNL

SafePrompt deploys a 100% local inspection extension: DLP for prompts and files (OCR included), NomAI for person names, Shadow AI / SaaS / Extensions, transfer DLP (WeTransfer, MEGA…), multi-feed anti-phishing, and an SOC console (File, Fleet, Policy, Board). Optional SOAR API (Wazuh, n8n…). Every alert is logged for a non-invasive view.

From browser to the board

01

Browser extension

AI DLP, files, transfers, SaaS, extensions and phishing intercepted locally.

02

SOC console

Alerts, agent fleet, policies, GDPR report mode or disclosed exposure mode.

03

Board & SOAR

GDPR risk view, executive reports, exports and API for Wazuh / automation.

Try SafePrompt in our interactive sandbox

See how the SafePrompt agent intercepts, audits and anonymizes requests (prompts and attachments) locally in the client, in milliseconds, before they reach AI models.

  • Absolute confidentiality: sensitive data never leaves the browser.
  • Real-time interception: instant detection on typing or file upload.
  • Multi-device: full experience on desktop and mobile.

Key capabilities

Prompt & file DLP

Blocks or redacts PII, secrets and code in prompts and attachments (PDF, Office, OCR).

NomAI

Local person-name detection (dedicated router), with Block / Log / Ignore policies.

Business codes

Exact business terms (references, internal codes) forced into anonymisation in prompts.

Tools Box

In-extension toolkit: redact / anonymise text or a file before sharing.

Shadow AI

Maps unauthorized AI tools and applies per-LLM-domain policies.

Shadow SaaS

SaaS catalogue: observe, alert or block cloud services outside policy.

Shadow Extensions

Inventory and governance of browser extensions (allow / deny / enforce) from the SOC fleet.

Transfer DLP

Controls uploads to WeTransfer, SwissTransfer, MEGA, Dropbox and other file-sharing sites.

Anti-phishing

Multi-source feeds (OpenPhish, URLhaus, PhishTank…) with alert or block in the browser.

SOC console & Board

Alert queue, policies, agent fleet, GDPR risk for executives and Excel exports.

SOAR API

M2M tokens for Wazuh, n8n or Shuffle: SaaS, extensions, domains and DLP.

On-prem & fleet

Self-hosted stack, SOC-signed CRX, GPO / MDM / Munki deployment.

BROWSER PROTECTION

Alert or block, with the SOC in the loop

On top of AI DLP, SafePrompt acts in the browser across several risk families. For each case: alert or block, and raise a SOC alert.

Domains & phishing

  • Detection in the browser (not only at the firewall)
  • Multi-source anti-phishing feeds, enriched lists
  • User alert mode or page block
  • Alert logged and visible to the SOC

Shadow SaaS

  • Control of unauthorized SaaS and cloud services
  • Stops ghost usage outside IT / security policy
  • User alert mode or access block
  • Alert logged for SOC governance
  • Users can request access (reason + work email): the request is sent to the SOC

Shadow Extensions

  • Inventory of extensions installed across the fleet
  • Allow / deny policies synced from the SOC
  • Enforce available by agent groups
  • Board visibility and exports for reporting

Transfer DLP

  • Coverage for WeTransfer, SwissTransfer, MEGA, Dropbox…
  • Observe / warn / block modes by policy
  • Complements DLP outside the AI chat
  • Alerts centralized in the SOC console
SOC OPERATIONS

Non-invasive visibility of enterprise usage

SafePrompt is managed by an internal or external SOC. All extension alerts are logged for a clear view, without intrusive monitoring of work content, on:

  • AI usage: Shadow AI, NomAI, risky prompts, data-leak attempts
  • Browser: phishing, domains, Shadow SaaS, Extensions, file transfers
  • Board: GDPR risk dashboard, Excel exports, SOAR API

Two SOC modes for AI alerts

For AI, the SOC has two escalation levels. The choice depends on criticality and legal framework:

Report mode (default · GDPR)

  • AI alerts are reported only (metadata, risk type, timestamp)
  • Prompt and file content is not exposed in the SOC
  • Fits a non-invasive, GDPR-respectful approach
  • Enough for governance and day-to-day operations

Exposure mode (critical use cases)

  • Available for high-risk contexts (investigation, review)
  • The prompt and/or files are visible in the SOC alert
  • Enables detailed SOC review and investigation
  • GDPR obligation: this mode must be clearly disclosed to the user (transparency)

The Board · GDPR risk module estimates fine exposure if SafePrompt had not been in place, and builds reports for legal or the executive committee. The SOAR API connects Wazuh or your playbooks.

GDPR fine estimation

  • "Without SafePrompt" scenarios based on real alerts
  • Personal-data exposure / leaks to AI, SaaS and transfers
  • Order of magnitude of financial risk (fines)
  • Quantified argument for leadership

Legal & executive reports

  • Board dashboard and SOC Excel exports
  • Summaries usable in committee / board
  • Evidence of controlled usage (AI, domains, SaaS, extensions)
  • Non-invasive view, except disclosed exposure mode

Goal: a non-invasive view by default, with an optional transparent exposure mode for critical cases, driven by the SOC, useful for security as well as legal and business.

Compliance & regulated sectors

Built for the strictest international requirements.

RGPD HIPAA EU AI Act SOC 2 ISO 27001 HDS PCI-DSS
USE CASES

Healthcare, finance, SMEs: concrete use cases

SafePrompt adapts to your sector constraints: see how the agent addresses specific stakes in healthcare, finance and SMEs.

See use cases
FAQ

Frequently asked questions about SafePrompt

Short answers for CISOs, security, DPOs and leadership.

Does SafePrompt replace my DLP or firewall?

No. SafePrompt complements your stack by acting in the browser, where file/email DLP and network filtering do not see AI prompts, Shadow SaaS or some web access.

Who drives alerts: internal or external SOC?

Both are possible. You choose an internal SOC or an external SOC depending on your organization. All agent alerts are logged for a clear view of usage.

Does the SOC read prompt content?

By default, no. Report mode only sends metadata (non-invasive GDPR approach). Exposure mode can make the prompt or files visible for investigation and must be clearly disclosed to the user.

Does SafePrompt cover ChatGPT, Copilot and Claude?

Yes. The agent protects generative AI usage in the browser (prompts and files), with anonymization or blocking according to policy.

What do domains, SaaS, extensions and transfers cover?

On top of AI DLP (NomAI, business codes, Tools Box), SafePrompt can alert or block phishing / risky domains, Shadow SaaS, Shadow Extensions and uploads to WeTransfer / MEGA / Dropbox…, with a SOC alert. On SaaS block, users can request access (work email + reason).

How do I connect SafePrompt to Wazuh or a SOAR?

Via the SOAR API (M2M tokens): SaaS, extensions, domains and DLP preventions for Wazuh, n8n, Shuffle or your playbooks.

How do I request access to a blocked SaaS?

From the alert or block screen, the user clicks Request access, explains why the tool is needed and leaves a work email. The SOC receives the request for validation.

How do I get a demo or a quote?

Use the sandbox, request a quote from this page, or contact loic.netten@cybernetten.be.

BLOG RESOURCES (SEO)

Technical reads on AI DLP, Shadow AI / GDPR and browser protection.

Quote request

Describe your need. I will get back to you within 24 hours at the address you provide.