SafePrompt
Local DLP extension + SOC console. SafePrompt protects prompts, files, transfers, SaaS, extensions and phishing, with logged alerts and non-invasive visibility.
Belgian company · Sovereignty · On-prem / appliance · GDPR-minded
Generative AI (ChatGPT, Claude, Copilot) speeds up your teams. It also creates Shadow AI, Shadow SaaS and uncontrolled browser extensions. Code, personal data and secrets leave via prompts, files or WeTransfer, not counting phishing and malicious domains.
The limits of traditional security tools
Proxies and firewalls act too late: either they block AI (frustration) or they let text and attachments through without fine-grained inspection. Network lists also struggle with phishing, ghost SaaS and add-ons. For GDPR and trade secrets, that is a blind spot.
The solution: SafePrompt by CNL
SafePrompt deploys a 100% local inspection extension: DLP for prompts and files (OCR included), NomAI for person names, Shadow AI / SaaS / Extensions, transfer DLP (WeTransfer, MEGA…), multi-feed anti-phishing, and an SOC console (File, Fleet, Policy, Board). Optional SOAR API (Wazuh, n8n…). Every alert is logged for a non-invasive view.
From browser to the board
Browser extension
AI DLP, files, transfers, SaaS, extensions and phishing intercepted locally.
SOC console
Alerts, agent fleet, policies, GDPR report mode or disclosed exposure mode.
Board & SOAR
GDPR risk view, executive reports, exports and API for Wazuh / automation.
Try SafePrompt in our interactive sandbox
See how the SafePrompt agent intercepts, audits and anonymizes requests (prompts and attachments) locally in the client, in milliseconds, before they reach AI models.
- Absolute confidentiality: sensitive data never leaves the browser.
- Real-time interception: instant detection on typing or file upload.
- Multi-device: full experience on desktop and mobile.
Key capabilities
Prompt & file DLP
Blocks or redacts PII, secrets and code in prompts and attachments (PDF, Office, OCR).
NomAI
Local person-name detection (dedicated router), with Block / Log / Ignore policies.
Business codes
Exact business terms (references, internal codes) forced into anonymisation in prompts.
Tools Box
In-extension toolkit: redact / anonymise text or a file before sharing.
Shadow AI
Maps unauthorized AI tools and applies per-LLM-domain policies.
Shadow SaaS
SaaS catalogue: observe, alert or block cloud services outside policy.
Shadow Extensions
Inventory and governance of browser extensions (allow / deny / enforce) from the SOC fleet.
Transfer DLP
Controls uploads to WeTransfer, SwissTransfer, MEGA, Dropbox and other file-sharing sites.
Anti-phishing
Multi-source feeds (OpenPhish, URLhaus, PhishTank…) with alert or block in the browser.
SOC console & Board
Alert queue, policies, agent fleet, GDPR risk for executives and Excel exports.
SOAR API
M2M tokens for Wazuh, n8n or Shuffle: SaaS, extensions, domains and DLP.
On-prem & fleet
Self-hosted stack, SOC-signed CRX, GPO / MDM / Munki deployment.
Alert or block, with the SOC in the loop
On top of AI DLP, SafePrompt acts in the browser across several risk families. For each case: alert or block, and raise a SOC alert.
Domains & phishing
- Detection in the browser (not only at the firewall)
- Multi-source anti-phishing feeds, enriched lists
- User alert mode or page block
- Alert logged and visible to the SOC
Shadow SaaS
- Control of unauthorized SaaS and cloud services
- Stops ghost usage outside IT / security policy
- User alert mode or access block
- Alert logged for SOC governance
- Users can request access (reason + work email): the request is sent to the SOC
Shadow Extensions
- Inventory of extensions installed across the fleet
- Allow / deny policies synced from the SOC
- Enforce available by agent groups
- Board visibility and exports for reporting
Transfer DLP
- Coverage for WeTransfer, SwissTransfer, MEGA, Dropbox…
- Observe / warn / block modes by policy
- Complements DLP outside the AI chat
- Alerts centralized in the SOC console
Non-invasive visibility of enterprise usage
SafePrompt is managed by an internal or external SOC. All extension alerts are logged for a clear view, without intrusive monitoring of work content, on:
- AI usage: Shadow AI, NomAI, risky prompts, data-leak attempts
- Browser: phishing, domains, Shadow SaaS, Extensions, file transfers
- Board: GDPR risk dashboard, Excel exports, SOAR API
Two SOC modes for AI alerts
For AI, the SOC has two escalation levels. The choice depends on criticality and legal framework:
Report mode (default · GDPR)
- AI alerts are reported only (metadata, risk type, timestamp)
- Prompt and file content is not exposed in the SOC
- Fits a non-invasive, GDPR-respectful approach
- Enough for governance and day-to-day operations
Exposure mode (critical use cases)
- Available for high-risk contexts (investigation, review)
- The prompt and/or files are visible in the SOC alert
- Enables detailed SOC review and investigation
- GDPR obligation: this mode must be clearly disclosed to the user (transparency)
The Board · GDPR risk module estimates fine exposure if SafePrompt had not been in place, and builds reports for legal or the executive committee. The SOAR API connects Wazuh or your playbooks.
GDPR fine estimation
- "Without SafePrompt" scenarios based on real alerts
- Personal-data exposure / leaks to AI, SaaS and transfers
- Order of magnitude of financial risk (fines)
- Quantified argument for leadership
Legal & executive reports
- Board dashboard and SOC Excel exports
- Summaries usable in committee / board
- Evidence of controlled usage (AI, domains, SaaS, extensions)
- Non-invasive view, except disclosed exposure mode
Goal: a non-invasive view by default, with an optional transparent exposure mode for critical cases, driven by the SOC, useful for security as well as legal and business.
Compliance & regulated sectors
Built for the strictest international requirements.
Frequently asked questions about SafePrompt
Short answers for CISOs, security, DPOs and leadership.
Does SafePrompt replace my DLP or firewall?
No. SafePrompt complements your stack by acting in the browser, where file/email DLP and network filtering do not see AI prompts, Shadow SaaS or some web access.
Who drives alerts: internal or external SOC?
Both are possible. You choose an internal SOC or an external SOC depending on your organization. All agent alerts are logged for a clear view of usage.
Does the SOC read prompt content?
By default, no. Report mode only sends metadata (non-invasive GDPR approach). Exposure mode can make the prompt or files visible for investigation and must be clearly disclosed to the user.
Does SafePrompt cover ChatGPT, Copilot and Claude?
Yes. The agent protects generative AI usage in the browser (prompts and files), with anonymization or blocking according to policy.
What do domains, SaaS, extensions and transfers cover?
On top of AI DLP (NomAI, business codes, Tools Box), SafePrompt can alert or block phishing / risky domains, Shadow SaaS, Shadow Extensions and uploads to WeTransfer / MEGA / Dropbox…, with a SOC alert. On SaaS block, users can request access (work email + reason).
How do I connect SafePrompt to Wazuh or a SOAR?
Via the SOAR API (M2M tokens): SaaS, extensions, domains and DLP preventions for Wazuh, n8n, Shuffle or your playbooks.
How do I request access to a blocked SaaS?
From the alert or block screen, the user clicks Request access, explains why the tool is needed and leaves a work email. The SOC receives the request for validation.
How do I get a demo or a quote?
Use the sandbox, request a quote from this page, or contact loic.netten@cybernetten.be.
BLOG RESOURCES (SEO)
Technical reads on AI DLP, Shadow AI / GDPR and browser protection.