Google analytics are off.

Security, privacy and assurance

A clear boundary for your AI data.

Promptective protects AI workflows across browsers, desktop apps and agents. Content is checked before provider delivery, and routine records exclude prompt and response text.

How data moves

Your AI data follows a controlled path.

Promptective checks supported content before provider delivery and keeps prompt and response text out of routine records.

Enterprise AI tools

AI interactions across browsers, desktop apps and custom agents.

Promptective protection

Check content, apply organisation policy and continue only when the decision allows.

Audit

Approved AI service

Approved content continues to the AI service selected by the organisation.

Routine evidence and dashboard

The dashboard records the decision, policy version, protection status and delivery result. Routine records exclude prompt and response text.

Content-minimised evidence

[2]Managed analysis is used only when selected and remains inside the declared boundary. Content stays out of routine records. Coverage is stated separately for each browser, desktop app and custom agent integration.

Decision outcomes

One clear decision for every checked interaction.

Promptective records the decision, the rule used and whether content was delivered.

  1. Allow

    Permit the supported interaction under the active policy.

  2. Audit

    Record content-minimised decision evidence for review.

  3. Redact

    Remove a detected value before permitted delivery.

  4. Require approval

    Hold the interaction for an authorised decision.

  5. Block

    Stop delivery when the active policy requires it.

Privacy / Data handling

What data goes where

Prompt and response plaintext stays out of routine remote evidence. Your deployment defines where content can be processed and which records can be retained.

Prompt and response content

Where it can exist

Transiently in the declared enforcement boundary, including managed analysis when selected, and in permitted provider transit when policy allows.

Where it is excluded

Routine telemetry, event history, dashboards, product logs, and generic operating-system notifications.

Local explanation excerpts

Where it can exist

Only in trusted endpoint memory and local detail UI, for a limited time when needed to explain a decision.

Where it is excluded

Remote queues, control APIs, dashboards, logs, caches, and generic notifications.

Events and receipts

Where it can exist

Secure endpoint queues and the control plane, database, and dashboard as decision and delivery facts only.

Where it is excluded

Their routine schemas cannot carry prompt or response content, local excerpts, credentials, or arbitrary attributes.

Private endpoint identity keys

Where it can exist

Endpoint or browser-profile storage, where they authenticate the installation or profile.

Where it is excluded

Private key material stays on the endpoint. Shared data is limited to the verification material and signed proofs needed for trust.

Integrity / Trust controls

Policy authority you can verify.

Every security decision is bound to explicit authority, a policy version, and defined failure behaviour. Your team receives evidence it can review.

01

Content-minimised records

Routine evidence records the policy, decision and delivery result without retaining prompt or response text.

02

Versioned organisation policy

Organisation policy defines how supported sensitive content and AI destinations are handled.

03

Explicit failure behaviour

Audit may fail open only by policy. Critical data-loss and destructive actions fail closed or require approval on supported paths.

Assurance / Evidence

Clear evidence for your security review.

Technical controls

We verify each supported surface against its declared protection boundary before publishing a coverage claim.

Independent assurance

Independent reports and certifications are published only when they are complete and verifiable. Our security team will walk you through the evidence relevant to your review.

Verified coverage

We state exactly where protection is active. A control is not described as protecting an AI interaction until we have verified that it can inspect and enforce that interaction.

Security review

Bring your security review forward.

Share your AI tools and security requirements. We will map the data flow, controls, evidence and supported boundaries your team needs to review next steps with confidence.

Start a security review
Trust Centre | Promptective