Policy before provider

Give AI a job—not unrestricted access to your data.

Shield puts a privacy boundary in front of model calls. Define the route, region, retention, budget, and redaction policy, then preserve auditable metadata without turning raw prompts into analytics.

Versioned agentsPre-dispatch redactionBudget controlsBring your own keys
01
Agent policy

Version the rules with the agent.

Draft an agent with its prompt policy, allowed regions, retention requirement, and monthly budget. A draft stays inert until it is deliberately published.

02
Protected dispatch

Detect sensitive values before the model call.

Shield applies the selected PII policy first, routes only through an eligible model, and returns the redaction categories alongside the response.

03
Auditable activity

Keep the metadata that improves control.

Run status, route, token usage, cost, and redaction count remain visible while raw prompts and answers stay out of run analytics.

04
AI exposure audit

Ask providers what they currently return about you.

Connect your own OpenAI, Anthropic, Perplexity, or Google key. Run providers separately, inspect structured claims, and follow citations from web-grounded answers.

Straight answers

Before you start

Who pays for provider usage?

Your connected provider account is billed directly for BYOK exposure audits. Shield never displays the full key after it is encrypted.

Can I use only one provider?

Yes. Each provider is independently connected, tested, and selectable.

Are raw prompts stored in run history?

No. Run analytics retain operational metadata rather than raw prompt and response text.

Put a boundary in front of the model

Build an agent with rules you can inspect.

Create the policy first, then publish and run only through an eligible route.