SeeData protection in AI trafficx, held

Protect data in AI traffic, before and after the model.

Scan prompts and answers for your own identifiers, plant tripwires that fire on a leak, and see the AI tools in use.

How it works

Specs

Data protection in AI traffic, in detail

Delivery and data

Delivery
SaaS, from one login.
Isolation
Each customer runs in an isolated workspace with its own database.
Certifications
None held. Frameworks are mapped to and assessed against.

Frameworks

India DPDP
Mapped to: Redaction preset for personal data.
GDPR
Mapped to: Redaction preset for personal data.
PCI DSS
Mapped to: Redaction preset for card data.
See the frameworks

Last reviewed 7 Oct 2026

One request · your identifierIllustrative

One request · your identifier: support-bot to provider A, "Renew policy POL-AB-123456 for this customer". Checks: Built-in identifiers passed, Your policy format flagged, Canary marker passed. Verdict: redacted, Identifier replaced.

In short

Data protection in AI traffic in ColossalX scans each prompt and answer for sensitive identifiers, including formats only you use, and redacts or blocks them. Canary tripwires raise a critical incident the moment planted data leaks. Beside them, a tool registry, an app catalogue, telemetry and a browser sensor show and limit the AI in use.

A customer's policy number goes into a prompt, and the model provider now holds it.

ColossalX redacts it before it leaves, and plants tripwires that fire if data leaks.

How it works

From your own identifier to a redacted prompt.

One policy-number format, followed from the identifier you define to a redacted prompt, and a planted marker that catches a leak.

Workflow · a policy number redacted, a leak caughtIllustrative

01 Your format added

A policy-number format is added and tried on sample text.

02 Prompt scanned

A prompt carries a policy number the model does not need.

03 Redacted before sending

The number is replaced before the prompt leaves.

04 Tripwire fires

A planted marker reaches an answer, and an incident opens.

What you see

What is redacted, what is watched, what is in use.

Your identifier is redacted in the prompt and three canaries are watched. A tripped canary opens a critical incident.

  1. Define your identifiers
  2. Scan and redact
  3. Plant a tripwire
  4. See AI in use
Read the detail, step by step4
  1. Define your identifiers. Add a format only you use, such as a policy number. Author a pattern for an identifier only your business uses and try it on sample text before it runs. The server refuses patterns that could take exponential time, and built-in matches win any overlap, so a custom pattern cannot unmask a card number.
  2. Scan and redact. Prompts and answers are scanned; a hit is redacted, blocked or flagged. Scan rules are checked on every request and response, each with an action (block, redact, flag or allow), a category and a severity. Charts show scans, detections by category and recent detections. Rules are set in a guardrail profile or the API, and the 6 presets by law sit beside your own.
  3. Plant a tripwire. Plant a marker in a prompt, a document or a database row. A canary can sit in an agent's system prompt, a knowledge-base document or a database row. If it ever appears in a model answer, the gateway records the trip, opens a critical incident and can block the answer. Each shows watching or tripped, can be revoked, and comes with copy-ready placement text.
  4. See AI in use. Registry, catalogue, telemetry and the sensor show what is in use. The tool registry allows, monitors or blocks each tool an agent can call. The app catalogue scores GenAI apps on data handling, compliance, security and terms. Telemetry charts requests, blocks, tokens and spend, with a CSV export. A browser sensor finds AI tools on laptops, and is tested never to read a prompt.
Data protectionIllustrative

An illustrative data protection view: a policy-number format only the business uses, redacted in a prompt with the token shown in place of the number, above three canary tripwires in a system prompt, a knowledge base and a database row, one of which has tripped and opened a critical incident.

3notes
  1. A format only you use, redacted
  2. A planted marker that senses a leak
  3. A trip opens a critical incident

How it connectsx, held

Where the data trail leads.

Scans, tripwires and the sensor feed the records around them.

  1. Presets by law and your own identifiers live in a guardrail profile.

  2. Lineage separates the data sent to a model from what was held back.

  3. Browser sensor findings feed the Shadow AI inventory like any collector.

  4. A tripped canary opens a critical incident in the runtime incident feed.

Honest by design

What it does, and what it does not.

Data protection · stated plainlyIllustrative

Data protection · stated plainly: Scan Prompts and answers; Canary Senses, does not trace; Tool registry Rules, not inventory; App scores Editorial, re-assess. States its own limits.

What it does not do

x, not measured

A canary plants and senses; it does not trace data beyond the answer it appears in.

All 4 limits
  • Scan rules are set in a guardrail profile or the API; the screen toggles them.
  • The tool registry is a rule list for the ColossalX MCP Firewall, not a discovered inventory of tools.
  • App catalogue scores are editorial starting points, and the browser sensor reports only once enrolled.

How we know

  • Built-in matches win any overlap, so your own pattern cannot unmask a card number.
  • A tripped canary opens a critical incident, and the answer can be blocked.
  • The browser sensor is tested never to read what a person types.
  • Starter app scores are labelled editorial, so you re-assess them rather than rely on them.

Questions

Questions buyers ask

How do you stop sensitive data going into an AI prompt?

Scan each prompt before it reaches the model and act on what matches. ColossalX checks prompts and answers against 6 presets by law and line of business, plus identifiers you define yourself, and applies the action you set: redact, block or flag. Where a control could not run, the record says so rather than staying silent.

Can I add my own sensitive identifiers, such as a policy number?

Yes. Author a pattern for an identifier only your business uses, such as a policy number or an account format, and try it on sample text before it runs. A pattern that could take exponential time is refused, and built-in matches win any overlap, so your pattern cannot unmask a card number.

What is a canary tripwire in AI?

A canary tripwire is a marker planted where only a leak would carry it: an agent's system prompt, a knowledge-base document or a database row. If the marker appears in a model answer, the gateway records the trip, opens a critical incident and can block the answer. It senses a leak; it does not trace where the data went next.

How do I see which AI tools and apps my people use?

A browser sensor finds AI tools on laptops, including local models that no network log can see, and is tested never to read what a person types. An app catalogue scores GenAI apps on data handling, compliance, security and terms, and telemetry charts requests, blocks, tokens and spend. Catalogue scores are starting points to re-assess.

What is the AI tool registry?

The AI tool registry is where you allow, monitor or block each tool an agent can call, with parameter checks on the arguments. It is a front for the ColossalX MCP Firewall's rules, not a discovered inventory of tools; the MCP servers view learns those from real requests. Blocking a tool stops agents calling it.

Related

Next step

Know your x before it leaves.

Try your own identifiers on sample text, then plant a tripwire and watch for a leak.

  1. 01Tell us what you run
  2. 02See the four verbs on it
  3. 03Decide where to start