Book an Appointment
Data Loss Prevention for Generative AI

The DLP for ChatGPT, Claude & Copilot.

VamiGuard is the leading data-loss-prevention platform purpose-built for generative AI. Detect, redact, govern and audit every prompt — across browsers, desktop apps, IDEs and APIs, centrally managed, sovereignly hosted on Open Telekom Cloud.

ChatGPTClaudeMicrosoft CopilotGeminiGrokGitHub Copilot& any other LLM

Microsoft Edge · coming soon

chat.openai.com

    The category-defining DLP for generative AI

    BSI C5ISO 27001GDPR Art. 25 / 32EU AI ActNIS-2Open Telekom Cloud
    Coverage at a glance

    Purpose-built for the GenAI tools your employees actually use.

    ChatGPTOpenAI · Web + Desktop
    ClaudeAnthropic · Web + Desktop + CLI
    Microsoft CopilotM365 · Web + Add-In
    GeminiGoogle · Web
    GrokxAI · Web + X app
    GitHub CopilotIDE · LSP plugin
    Cursor · ContinueIDE assistants
    Claude CodeCLI agent
    Self-Hosted LLMsvLLM · Ollama · Mistral
    Direct API CallsServer-to-server proxy
    Future LLMsPolicy-based onboarding
    Custom patternsAdd any domain
    The four pillars of GenAI DLP

    Detect. Redact. Govern. Audit. In every prompt.

    VamiGuard delivers the four DLP capabilities every responsible GenAI deployment requires — from the first keystroke to the audit report.

    01

    Detect

    Sensitive data is detected the moment it is typed — patterns, named entities, semantic context.

    02

    Redact

    Tokens are replaced with placeholders before the prompt leaves the endpoint. The mapping stays local.

    03

    Govern

    Central policies decide whether a finding is monitored, alerted, soft-blocked or hard-blocked — per group and channel.

    04

    Audit

    Every decision is logged in pseudonymised form and is exportable to Splunk, Sentinel, QRadar or Elastic.

    What VamiGuard recognises

    Every category that should never reach an LLM.

    Built-in patterns cover the data types your auditors ask about — custom patterns can be added freely. New patterns roll out without redeployment.

    Personally identifiable information · PII

    Identifying information

    • Email addresses
    • Phone numbers
    • Credit card numbers
    • IBAN
    • Social security numbers
    • Passport numbers
    • IP addresses
    • Names & addresses

    Every pattern is switchable per group. Detected values receive a stable placeholder such as <EMAIL_1>, mapped consistently across the conversation.

    Secrets · Tokens · Keys

    Authentication material

    • AWS Access Keys
    • JWT Tokens
    • Bearer Tokens
    • GitHub Tokens
    • OpenAI API Keys
    • Stripe Keys
    • Passwords & secrets
    • High-entropy strings
    • Custom regex / patterns

    Add plain-text terms (project codenames, internal product names) or full regex. Patterns can be imported and exported as YAML across teams.

    Redact on send · Restore on receive

    A second mapping layer between LLM response and user.

    When Claude or ChatGPT returns a code snippet that references <TOKEN_1>, VamiGuard transparently substitutes the original value back — the user gets working code, the LLM never saw the value.

    1. 1User types: "Help me debug this auth header: Bearer sk-prod-abc…"
    2. 2VamiGuard redacts: "Help me debug this auth header: Bearer <TOKEN_1>"
    3. 3LLM responds with code that references <TOKEN_1>
    4. 4VamiGuard restores: the user sees working code with the original secret — ready to copy-paste
    How detection works

    Three layers. Each stricter than the last.

    Most input is harmless and is cleared in milliseconds. Only truly ambiguous content reaches the deepest layer — low latency, high accuracy.

    L1

    Pattern · Regex · Entropy

    Email, IBAN, credit cards, AWS keys, JWT, GitHub tokens, passwords. Runs entirely on device — the prompt never leaves it.

    < 5 msOn Device
    L2

    Named entities · classifier

    A local NER model recognises people, organisations, addresses, project names — augmented by your own word lists.

    30 – 80 msOn Device
    L3

    LLM guardrail · semantics & intent

    Only ambiguous prompts reach the EU-hosted guard model — already pre-redacted. Categories are configurable per tenant.

    200 – 600 msEU Region
    Policy modes

    Four levels of decision.

    Every detection rule binds to one of four response modes. Different groups, channels and times of day can run different modes simultaneously.

    M1

    Monitor

    Silent observation. Events are logged for reporting. Ideal for the learning phase.

    M2

    Alert

    Visible warning. The user can still submit. Optionally with a notification to manager or SOC.

    M3

    Soft-Block

    Submit is paused. The user enters a written justification — auditable and retrievable.

    M4

    Hard-Block

    The submit path is removed. Three-layer enforcement via MDM, network and Conditional Access.

    Coverage

    Every channel through which your users reach an LLM.

    Browser alone is not enough. VamiGuard covers desktop apps, IDEs, mobile devices and server calls — all governed by a single central policy.

    Browser

    Chrome · Edge · Firefox

    Desktop apps

    Claude · ChatGPT · Copilot

    IDE plugins

    VS Code · JetBrains · Cursor

    Mobile (MAM)

    iOS · Android · Intune · Jamf

    API Gateway

    OpenAI · Anthropic · Server-to-Server
    Sovereignty & compliance

    Your data — in your jurisdiction.

    VamiGuard Cloud runs exclusively in the EU on Open Telekom Cloud — operated by T-Systems under German law. Or fully on your own infrastructure.

    Three availability zones in the region eu-de. KMS-backed encryption with optional BYOK in your own HSM. No US parent company. No CLOUD Act exposure. Full audit-trail ownership in the on-premises tier.

    BSI C5Type-2 attested
    ISO 27001+ 27017 / 27018
    GDPRArt. 32 / 25 / 5
    EU CCoCCode of Conduct L3
    EU AI ActArt. 9 documented
    NIS-2Incident reporting
    TCDP 1.0Level 3
    BYOK / HSMFIPS 140-2 L3
    Plans

    Open source as the foundation. Enterprise on top.

    The browser extension is and remains free, open source and Apache-2.0. Central management is added on top whenever you are ready — data sovereignty stays with you in any case.

    Community

    € 0Self-managed

    Browser extension installed by the user. Local patterns, local mapping, no telemetry, Apache-2.0 licensed.

    • PII redactor
    • Custom regex & patterns
    • Fully client-side
    • Apache-2.0
    Install for free

    Sovereign

    CustomContact Sales

    Helm chart for your own data centre or OTC tenancy. Air-gap-capable. Bring your own LLM and HSM. Audit-trail ownership.

    • Everything in Cloud
    • Helm Chart (CCE / OpenShift)
    • Bring-your-own LLM
    • HSM & BYOK
    • Air-gap update pipeline
    • White-label option
    Contact Sales

    Install it in a minute. Manage it in a quarter.

    Try the free open-source extension on Chrome today. Reach out to us as soon as you want to bring central management to your organisation.

    Protect Your Organization Now!

    Contact us for an individual consultation and security solution tailored to your requirements.

    Valeri Milke, CEO of VamiSec

    "Only when all instruments are well-tuned does your organization become secure and compliant."