# Protect data in AI traffic, before and after the model.

> Data protection in AI traffic in ColossalX scans each prompt and answer for sensitive identifiers, including formats only you use, and redacts or blocks them. Canary tripwires raise a critical incident the moment planted data leaks. Beside them, a tool registry, an app catalogue, telemetry and a browser sensor show and limit the AI in use.

Scan prompts and answers for your own identifiers, plant tripwires that fire on a leak, and see the AI tools in use.

Canonical page: https://colossalx.tech/platform/ai-data-protection · Last reviewed: 7 Oct 2026

*Illustration:* One request · your identifier: support-bot to provider A, "Renew policy POL-AB-123456 for this customer". Checks: Built-in identifiers passed, Your policy format flagged, Canary marker passed. Verdict: redacted, Identifier replaced.

## The threat and the control

- **The threat:** A customer's policy number goes into a prompt, and the model provider now holds it.
- **The control:** ColossalX redacts it before it leaves, and plants tripwires that fire if data leaks.

## How it works: From your own identifier to a redacted prompt.

One policy-number format, followed from the identifier you define to a redacted prompt, and a planted marker that catches a leak.

### Workflow: a policy number redacted, a leak caught (illustrative)

1. **Your format added.** A policy-number format is added and tried on sample text.
   Identifier: Policy number; Action: Redact | Tried on sample text
2. **Prompt scanned.** A prompt carries a policy number the model does not need.
   `Renew policy POL-AB-123456 for this customer` | support-bot · to provider A · Scanning
3. **Redacted before sending.** The number is replaced before the prompt leaves.
   Built-in identifiers (done: none); Your policy format (warning: redacted) | `Renew policy [POLICY_NO] for this customer`
4. **Tripwire fires.** A planted marker reaches an answer, and an incident opens.
   Canary: Knowledge-base document; State: Tripped | Critical incident | x, found

## What you see: What is redacted, what is watched, what is in use.

Your identifier is redacted in the prompt and three canaries are watched. A tripped canary opens a critical incident.

1. **Define your identifiers.** Add a format only you use, such as a policy number. Author a pattern for an identifier only your business uses and try it on sample text before it runs. The server refuses patterns that could take exponential time, and built-in matches win any overlap, so a custom pattern cannot unmask a card number.
2. **Scan and redact.** Prompts and answers are scanned; a hit is redacted, blocked or flagged. Scan rules are checked on every request and response, each with an action (block, redact, flag or allow), a category and a severity. Charts show scans, detections by category and recent detections. Rules are set in a guardrail profile or the API, and the 6 presets by law sit beside your own.
3. **Plant a tripwire.** Plant a marker in a prompt, a document or a database row. A canary can sit in an agent's system prompt, a knowledge-base document or a database row. If it ever appears in a model answer, the gateway records the trip, opens a critical incident and can block the answer. Each shows watching or tripped, can be revoked, and comes with copy-ready placement text.
4. **See AI in use.** Registry, catalogue, telemetry and the sensor show what is in use. The tool registry allows, monitors or blocks each tool an agent can call. The app catalogue scores GenAI apps on data handling, compliance, security and terms. Telemetry charts requests, blocks, tokens and spend, with a CSV export. A browser sensor finds AI tools on laptops, and is tested never to read a prompt.

*Illustration:* An illustrative data protection view: a policy-number format only the business uses, redacted in a prompt with the token shown in place of the number, above three canary tripwires in a system prompt, a knowledge base and a database row, one of which has tripped and opened a critical incident. Notes: 1. A format only you use, redacted 2. A planted marker that senses a leak 3. A trip opens a critical incident

## How we know

- Built-in matches win any overlap, so your own pattern cannot unmask a card number.
- A tripped canary opens a critical incident, and the answer can be blocked.
- The browser sensor is tested never to read what a person types.
- Starter app scores are labelled editorial, so you re-assess them rather than rely on them.

## Where the data trail leads.

Scans, tripwires and the sensor feed the records around them.

- **Runtime guardrails.** Presets by law and your own identifiers live in a guardrail profile.
- **Data lineage.** Lineage separates the data sent to a model from what was held back.
- **Shadow AI.** Browser sensor findings feed the Shadow AI inventory like any collector.
- **Incidents.** A tripped canary opens a critical incident in the runtime incident feed.

Where an x ends up: x, held.

## Specs: delivery and data

- **Delivery:** SaaS, from one login.
- **Isolation:** Each customer runs in an isolated workspace with its own database.
- **Certifications:** None held. Frameworks are mapped to and assessed against.

## Frameworks

- Mapped to India DPDP: Redaction preset for personal data.
- Mapped to GDPR: Redaction preset for personal data.
- Mapped to PCI DSS: Redaction preset for card data.

## What it does not do

- A canary plants and senses; it does not trace data beyond the answer it appears in.
- Scan rules are set in a guardrail profile or the API; the screen toggles them.
- The tool registry is a rule list for the ColossalX MCP Firewall, not a discovered inventory of tools.
- App catalogue scores are editorial starting points, and the browser sensor reports only once enrolled.

*Illustration:* Data protection · stated plainly: Scan Prompts and answers; Canary Senses, does not trace; Tool registry Rules, not inventory; App scores Editorial, re-assess. States its own limits.

## Questions

### How do you stop sensitive data going into an AI prompt?

Scan each prompt before it reaches the model and act on what matches. ColossalX checks prompts and answers against 6 presets by law and line of business, plus identifiers you define yourself, and applies the action you set: redact, block or flag. Where a control could not run, the record says so rather than staying silent.

### Can I add my own sensitive identifiers, such as a policy number?

Yes. Author a pattern for an identifier only your business uses, such as a policy number or an account format, and try it on sample text before it runs. A pattern that could take exponential time is refused, and built-in matches win any overlap, so your pattern cannot unmask a card number.

### What is a canary tripwire in AI?

A canary tripwire is a marker planted where only a leak would carry it: an agent's system prompt, a knowledge-base document or a database row. If the marker appears in a model answer, the gateway records the trip, opens a critical incident and can block the answer. It senses a leak; it does not trace where the data went next.

### How do I see which AI tools and apps my people use?

A browser sensor finds AI tools on laptops, including local models that no network log can see, and is tested never to read what a person types. An app catalogue scores GenAI apps on data handling, compliance, security and terms, and telemetry charts requests, blocks, tokens and spend. Catalogue scores are starting points to re-assess.

### What is the AI tool registry?

The AI tool registry is where you allow, monitor or block each tool an agent can call, with parameter checks on the arguments. It is a front for the ColossalX MCP Firewall's rules, not a discovered inventory of tools; the MCP servers view learns those from real requests. Blocking a tool stops agents calling it.

## Related

- [Runtime guardrails](https://colossalx.tech/platform/runtime-guardrails)
- [Data lineage](https://colossalx.tech/platform/data-lineage)
- [Shadow AI](https://colossalx.tech/platform/shadow-ai)

---

ColossalX is an AI security and governance platform from Quantexra Labs LLP, delivered as SaaS. Book a walkthrough: https://colossalx.tech/demo · client.success@quantexra.tech
