One system, from the console to the device.

Alesia is a cloud console for policy and visibility, a lightweight daemon on every device that enforces it, and a detection layer that never sends your content anywhere. Here's how the five pieces fit together.

Cloud console
Alesia Core
Extensions
Cloud console

Define policy once. See everything it applies to. Define policies across organization.

Admins define policy, deploy detection models, and see shadow AI usage and analytics across the organization from one console. It can run in our cloud or self-hosted inside yours.

  • Define policies for teams, employees, or entire organization
  • Deploy and update detection models without touching devices
  • See every AI tool in use, and how, across the organization
  • Self-hostable for organizations that need it in their own environment
Alesia Core

A lightweight daemon that watches the network layer, not each app.

Alesia Core runs on every employee's device. Because it works at the network layer instead of integrating app by app, it covers over 100 AI tools out of the box, on any surface an employee actually uses: browser, IDE, native apps, or CLI. It collects the telemetry that powers shadow AI visibility, and it's what enforces policy in real time, on the device, before anything is sent.

Browser AI chat

The surface where careless pasting overwhelmingly happens. ChatGPT, Claude and Gemini in the browser, checked before every send.

IDEs

Coding assistants that auto-attach large amounts of company code as context, without the employee actively choosing to share it.

// attached silently as context
src/billing/stripe.go
src/internal/customer_db.go

Command Line

Piped output and agent prompts in terminal workflows.

Native Apps

Desktop AI clients, covered the same way, at the network layer.

Runs on macOS Windows
Extensions

Optional extensions for a better warning, right where the work happens.

Alesia Core alone is enough to detect and enforce. Extensions, like a browser extension, are optional add-ons that surface a warning directly on the page instead of a separate popup, so the employee sees it exactly where they were about to paste.

How on-device content protection works.

Four checks run on every message, on the device, before it is sent. Together they catch what a simple keyword match would miss.

Layer 01

Known-shape secrets

Credentials, API keys, card numbers and anything with a recognizable, near-certain form. These are the cases that warrant a hard block rather than a warning.

ak_live_9f3d...ce21
Layer 02

Company-specific terms

Project codenames, customer names, unreleased product names. The organization seeds these in advance, and Alesia matches them on the device.

Project Northwind
Layer 03

Resemblance to confidential docs

Catches paraphrased or reworded versions of material the company marked confidential. A plain keyword match would miss this entirely.

Q3 forecast, rephrased
Layer 04

A judgment layer for the rest

Genuinely ambiguous cases get a contextual pass. Several small hints together can matter more than any single signal alone.

looks like internal data
Reporting

Only the event crosses the boundary. Never the message.

Once a message is checked, only metadata about that event, its category, severity, and the employee's decision, is sent to the console. What the employee actually asked never leaves the device.

On the deviceNever Transmitted
  • The message the employee wrote
  • The detection verdict
  • The company's policy and seeded terms
  • Any matching confidential documents
To the organizationMetadata Only
  • Category that was flagged
  • Severity of the signal
  • When the event happened
  • Whether the user proceeded

For organizations in the EU, especially Germany, this on-device boundary is what clears data protection and works council review, without a separate fight over employee monitoring.

See the privacy use case

FAQs

Alesia works on the network layer, so all surfaces are covered, like browser, IDEs, CLI, and native apps. Mobile apps are coming soon.

Yes. Alesia inspects context attached for you, not just what you paste, which is where much of the real leakage now happens.

Detection runs on the device, so it works without sending content to the cloud. Online access is only needed for metadata reporting and policy sync.

The boundary is structural: the architecture has no path that transmits content. That makes it auditable in a way a policy promise alone isn't.

Only metadata: the category flagged, its severity, when it happened, and whether the employee proceeded. Never the message or the document.

No. Content is never transmitted to Alesia either. There is nothing to train on because nothing arrives.

Bring every AI tool your company uses under one policy.

Talk to our team. We'll scope a rollout for your organization, without compromising the privacy boundary.

We'll only use this to reach out. No spam, ever.