One line defines the product.
Everything that involves actual message content stays on the device. Everything that crosses to the organization is metadata describing an event, never the content of that event.
- The message the employee wrote
- The detection verdict
- The company's policy and seeded terms
- Any matching confidential documents
never transmitted
- Category that was flagged
- Severity of the signal
- When the event happened
- Whether the user proceeded
metadata only
One line defines the product
On the device: the message, the verdict, your policy, and any matching documents — never transmitted. To the organization: category, severity, timing, and whether the user proceeded — metadata only.
Cloud inspection is its own exposure
Routing employee content through a third party to inspect it is a privacy breach, and a non-starter for security review. Detection on the device removes that trust dependency entirely.
- Message content never transmitted
- Detection verdicts stay local
- Matching documents stay local
- Only anonymized metadata crosses
Verifiable, not claimed
The boundary is structural, not a policy promise. Nothing in the architecture transmits content, which is what makes the claim auditable.
Privacy, in detail
The boundary is structural — the architecture has no path that transmits content. That makes it auditable in a way a policy promise alone isn't.
Stop sensitive data walking out through AI tools.
Request access for your security team. We'll set up policy seeding and a deployment plan that respects the privacy boundary.