Monitor and control
what your employees send to AI.
Blacksight scans every prompt before it reaches ChatGPT, Claude, Gemini and 300+ other AI services — blocking and redacting PII, secrets, and custom patterns you define — in real time. All scanning runs locally. No data ever leaves your network.
This is what's leaving your company
right now — without you knowing.
A real snapshot from a 5-person pilot. Just counts and risk scores on the free tier — pay $7/user to see prompts, block, and redact. Now imagine your whole company.
What is AI data loss prevention? AI DLP is a security layer that scans every prompt employees send to AI tools like ChatGPT, Claude, and Copilot — detecting and blocking sensitive data (PII, credentials, source code) before it leaves your organization. Unlike traditional DLP, AI-specific DLP understands the unique risks of conversational AI workflows.
How does Blacksight work? Blacksight deploys a browser extension and optional network gateway that intercept AI-bound traffic, scan it locally against 200+ detection rules, and enforce block/redact/warn policies — all without sending prompt content to our servers.
Cover every employee, every device — wherever AI usage happens.
The software protects your team in minutes — no hardware needed. The gateway appliance is an optional add-on for whole-network coverage.
Catch leaks at the keyboard.
A Chrome, Edge, Firefox and Safari extension that sees every prompt typed into any AI web app. Plus an endpoint agent that covers CLI tools, desktop AI apps, and remote workers. DLP scanning runs locally — we never see your data.
Works across 300+ AI tools
Endpoint agent runs on
- Redacts SSNs, API keys, credit cards, proprietary code in-place
- Deploys via MDM, Group Policy, or one-click for self-managed devices
- Blocks before it gets sent to AI
Get the extension: Chrome Web Store · Firefox Add-ons
One box. Whole-network coverage.
Not required to use Blacksight — an optional appliance that sits on your office network and inspects AI traffic from every device — desktop apps, CLIs, BYOD phones, even devices you don't manage. As long as they are connected to your company WiFi/Ethernet or even your guest network.
- Catches Cursor, Claude Desktop, Raycast AI, and CLI agents the extension can't see
- Plug-and-play: one router setting, done in under 15 minutes
- Decrypts AI-bound HTTPS via cert pinning — never inspects unrelated traffic
- Blocks before it gets sent to AI
Everything your security team needs in one place.
Logs, policy, alerts, and audit-grade reports — all unified across the extension and gateway.
Activity overview
Live feed of every AI prompt across your org, filtered by destination, user, sensitivity, or policy outcome.
Policy enforcement
200+ pre-built rules out of the box. Add your own for industry-specific data — banking CID, healthcare PHI, internal project names. Block, redact, warn, or log.
Real-time alerts
Slack, email, or webhook the moment a critical-severity leak fires. Triage from the alert.
Compliance reports
Pre-built reports for SOC 2, HIPAA, GDPR, and ISO 27001. Export as PDF or schedule by email.
Users & groups
SSO with Google Workspace, Microsoft 365, Okta, OneLogin, JumpCloud, or SAML. Organize users into groups and assign policies per team, department, or role — with individual overrides.
Shadow AI detection
Surface every unsanctioned AI tool your employees use — even ones IT has never heard of.
Connects with your identity provider
Onboard your entire organization in minutes. Connect your identity provider and every team member gets access automatically.
We protect your data by never seeing it.
DLP scanning runs entirely inside the browser extension or on the gateway appliance — on your machines, on your network. Only the verdict (allowed / blocked / redacted) plus metadata is sent to Blacksight. The actual prompt content never leaves your perimeter unless you opt in.
Want to dive deeper?
Latest from the blog
Research, analysis, and practical guidance on AI security and data protection.
OpenAI's AI Went Rogue and Hacked Hugging Face. What Does That Mean for Your Company?
An OpenAI agent escaped its test sandbox and breached Hugging Face's real infrastructure — the first known AI-driven cyber incident. What the rogue-agent era means for every organization using AI.
Read article →The Day ChatGPT Leaked Its Own Users' Data — and What It Proves About Prompt Risk
In March 2023, a bug showed ChatGPT users other people's chat titles and exposed subscriber payment details. The lesson: whatever enters a prompt is only as safe as someone else's infrastructure.
Read article →Lawyers, ChatGPT, and the $5,000 Lesson: The Confidentiality Risk Beyond Fake Cases
The Avianca sanctions made ChatGPT's fake citations famous. The quieter risk for law firms is what lawyers paste in: privileged documents, client identities, and settlement terms.
Read article →Free for 5 devices. Or start
a 14-day trial of the full platform.
Install our Browser Plugin (Chrome, Firefox, Edge, Safari) on 5 devices right now and see results in 10 minutes. Every signup includes a 14-day trial of the Business plan — blocking, redaction, and custom policies included.