SeeData protection in AI trafficx, held
Protect data in AI traffic, before and after the model.
Scan prompts and answers for your own identifiers, plant tripwires that fire on a leak, and see the AI tools in use.
One request · your identifier: support-bot to provider A, "Renew policy POL-AB-123456 for this customer". Checks: Built-in identifiers passed, Your policy format flagged, Canary marker passed. Verdict: redacted, Identifier replaced.
In short
Data protection in AI traffic in ColossalX scans each prompt and answer for sensitive identifiers, including formats only you use, and redacts or blocks them. Canary tripwires raise a critical incident the moment planted data leaks. Beside them, a tool registry, an app catalogue, telemetry and a browser sensor show and limit the AI in use.
A customer's policy number goes into a prompt, and the model provider now holds it.
ColossalX redacts it before it leaves, and plants tripwires that fire if data leaks.
How it works
From your own identifier to a redacted prompt.
One policy-number format, followed from the identifier you define to a redacted prompt, and a planted marker that catches a leak.
01 Your format added
A policy-number format is added and tried on sample text.
02 Prompt scanned
A prompt carries a policy number the model does not need.
03 Redacted before sending
The number is replaced before the prompt leaves.
04 Tripwire fires
A planted marker reaches an answer, and an incident opens.
What you see
What is redacted, what is watched, what is in use.
Your identifier is redacted in the prompt and three canaries are watched. A tripped canary opens a critical incident.
- Define your identifiers
- Scan and redact
- Plant a tripwire
- See AI in use
Read the detail, step by step4
- Define your identifiers. Add a format only you use, such as a policy number. Author a pattern for an identifier only your business uses and try it on sample text before it runs. The server refuses patterns that could take exponential time, and built-in matches win any overlap, so a custom pattern cannot unmask a card number.
- Scan and redact. Prompts and answers are scanned; a hit is redacted, blocked or flagged. Scan rules are checked on every request and response, each with an action (block, redact, flag or allow), a category and a severity. Charts show scans, detections by category and recent detections. Rules are set in a guardrail profile or the API, and the 6 presets by law sit beside your own.
- Plant a tripwire. Plant a marker in a prompt, a document or a database row. A canary can sit in an agent's system prompt, a knowledge-base document or a database row. If it ever appears in a model answer, the gateway records the trip, opens a critical incident and can block the answer. Each shows watching or tripped, can be revoked, and comes with copy-ready placement text.
- See AI in use. Registry, catalogue, telemetry and the sensor show what is in use. The tool registry allows, monitors or blocks each tool an agent can call. The app catalogue scores GenAI apps on data handling, compliance, security and terms. Telemetry charts requests, blocks, tokens and spend, with a CSV export. A browser sensor finds AI tools on laptops, and is tested never to read a prompt.
An illustrative data protection view: a policy-number format only the business uses, redacted in a prompt with the token shown in place of the number, above three canary tripwires in a system prompt, a knowledge base and a database row, one of which has tripped and opened a critical incident.
3notes
- A format only you use, redacted
- A planted marker that senses a leak
- A trip opens a critical incident
How it connectsx, held
Where the data trail leads.
Scans, tripwires and the sensor feed the records around them.
Presets by law and your own identifiers live in a guardrail profile.
Lineage separates the data sent to a model from what was held back.
Browser sensor findings feed the Shadow AI inventory like any collector.
A tripped canary opens a critical incident in the runtime incident feed.
Honest by design
What it does, and what it does not.
Data protection · stated plainly: Scan Prompts and answers; Canary Senses, does not trace; Tool registry Rules, not inventory; App scores Editorial, re-assess. States its own limits.
What it does not do
x, not measured
A canary plants and senses; it does not trace data beyond the answer it appears in.
All 4 limits
- Scan rules are set in a guardrail profile or the API; the screen toggles them.
- The tool registry is a rule list for the ColossalX MCP Firewall, not a discovered inventory of tools.
- App catalogue scores are editorial starting points, and the browser sensor reports only once enrolled.
How we know
- Built-in matches win any overlap, so your own pattern cannot unmask a card number.
- A tripped canary opens a critical incident, and the answer can be blocked.
- The browser sensor is tested never to read what a person types.
- Starter app scores are labelled editorial, so you re-assess them rather than rely on them.
Questions
Questions buyers ask
How do you stop sensitive data going into an AI prompt?
Scan each prompt before it reaches the model and act on what matches. ColossalX checks prompts and answers against 6 presets by law and line of business, plus identifiers you define yourself, and applies the action you set: redact, block or flag. Where a control could not run, the record says so rather than staying silent.
Can I add my own sensitive identifiers, such as a policy number?
Yes. Author a pattern for an identifier only your business uses, such as a policy number or an account format, and try it on sample text before it runs. A pattern that could take exponential time is refused, and built-in matches win any overlap, so your pattern cannot unmask a card number.
What is a canary tripwire in AI?
A canary tripwire is a marker planted where only a leak would carry it: an agent's system prompt, a knowledge-base document or a database row. If the marker appears in a model answer, the gateway records the trip, opens a critical incident and can block the answer. It senses a leak; it does not trace where the data went next.
How do I see which AI tools and apps my people use?
A browser sensor finds AI tools on laptops, including local models that no network log can see, and is tested never to read what a person types. An app catalogue scores GenAI apps on data handling, compliance, security and terms, and telemetry charts requests, blocks, tokens and spend. Catalogue scores are starting points to re-assess.
What is the AI tool registry?
The AI tool registry is where you allow, monitor or block each tool an agent can call, with parameter checks on the arguments. It is a front for the ColossalX MCP Firewall's rules, not a discovered inventory of tools; the MCP servers view learns those from real requests. Blocking a tool stops agents calling it.
Related
Where to look next.
-
Runtime guardrails
Injection, data leaks and approval holds
-
Data lineage
Which personal data reached which model
-
Shadow AI
The AI nobody approved, then a standing rule
Next step
Know your x before it leaves.
Try your own identifiers on sample text, then plant a tripwire and watch for a leak.
- 01Tell us what you run
- 02See the four verbs on it
- 03Decide where to start