The privacy boundary

One line defines the product.

Everything that involves actual message content stays on the device. Everything that crosses to the organization is metadata describing an event, never the content of that event.

On the device
  • The message the employee wrote
  • The detection verdict
  • The company's policy and seeded terms
  • Any matching confidential documents

never transmitted

crosses
To the organization
  • Category that was flagged
  • Severity of the signal
  • When the event happened
  • Whether the user proceeded

metadata only

The boundary

One line defines the product

On the device: the message, the verdict, your policy, and any matching documents — never transmitted. To the organization: category, severity, timing, and whether the user proceeded — metadata only.

Why on-device

Cloud inspection is its own exposure

Routing employee content through a third party to inspect it is a privacy breach, and a non-starter for security review. Detection on the device removes that trust dependency entirely.

  • Message content never transmitted
  • Detection verdicts stay local
  • Matching documents stay local
  • Only anonymized metadata crosses
Trust

Verifiable, not claimed

The boundary is structural, not a policy promise. Nothing in the architecture transmits content, which is what makes the claim auditable.

Privacy, in detail

The boundary is structural — the architecture has no path that transmits content. That makes it auditable in a way a policy promise alone isn't.

Stop sensitive data walking out through AI tools.

Request access for your security team. We'll set up policy seeding and a deployment plan that respects the privacy boundary.

We'll only use this to reach out — no spam, ever.