LLM-based inspection understands what employees mean, not just what matches a pattern: summaries stripped of identifiers, context that still carries meaning, documents inside uploads, multi-turn conversations.
Products / NativeAI Guard DLP
Let your employees use AI. NativeAI Guard is the safety net.
Real-time DLP for ChatGPT, Claude, Gemini, Copilot, DeepL and every shadow-AI app your employees discover next. Inspected and enforced in Switzerland.
How it works
We cover your main leakage channels.
The employee keeps working while NativeAI Guard filters personally identifiable information out of the data stream. Names, AHV numbers and addresses never leave the premises.
Customer profile for Thomas Brunner, 14.03.1981, AHV 756.1234.5678.97. Update his address to Seestrasse 42, 8002 Zürich. Draft the internal CRM request.
Customer profile for <PERSON>, <DATE>, AHV <CH_AHV>. Update his address to <LOCATION>. Draft the internal CRM request.
Summarize the risks: our clinic group is acquiring a private radiology chain for around forty million, closing before the November board meeting.
NativeAI Guard, WARNING: Policy violation: Confidential Business Information. No patient data matched. Deal value, timing and counterparty identified semantically.
Q3_Kundenliste.xlsx (2,400 rows)
NativeAI Guard, BLOCKED: Blocked attachment: Q3_Kundenliste.xlsx. Blocked by policy: Customer Data Leakage Prevention.
Kundendossier_final.pdf (password-protected)
Label detected: Confidential · Microsoft Purview
NativeAI Guard, PASSWORD REQUIRED: Purview label detected. Enter the file password so it can be scanned, while Microsoft 365 confirms that you may read this file.
Capabilities
Visibility first. Then enforcement.
Sensitive fields become tags ([PERSON], [IBAN], [DIAGNOSIS]) so work continues at full speed while the real data stays inside the company. Blocks are reviewable and overridable in seconds, with audit trail.
Who sent what, when, to which model, and what NativeAI Guard did about it. Your records of processing for all AI usage, DSG Art. 12 and GDPR Art. 30, produced automatically. YAML/API export for auditors.
"Client-identifying data never leaves the company, health data is anonymized", written exactly like that, enforced like code. Your DPO can read every rule. Feed in a compliance document and NativeAI Guard drafts the matching rules. Starter packs per industry included.
When NativeAI Guard intervenes, employees see why (which policy, which data category) right in their workflow. Security awareness training, delivered at exactly the moment it matters.
Every AI tool in use (including the ones IT never approved) with users, frequency and data categories. The management report you cannot produce today.
Every prompt is already classified for DLP; the same data shows which purposes drive the most AI usage across the company. We also compare the model chosen against the task and flag where a lighter, cheaper model would have done the job just as well, with an estimate of what routing to the optimal model would save.
top purpose: contract drafting, 21%
est. savings from model routing: CHF 4,200/mo
Covered channels
Built for the AI assistants. Extended to every channel.
Inspection sits in the browser, not in per-site integrations, so coverage is not a list of supported websites: every web surface your employees can reach, under the same policies.
We tune detection on these four first. The browser extension, Chrome and Edge today, covers every other assistant under the same rules; internal models go through the API proxy.
Seen in the field
The workarounds that other DLP tools do not cover.
A user removes the "confidential" label from a Purview-classified file and uploads the now "public" content to an LLM. Classification-based DLP sees nothing wrong. The policy held; the intent did not.
An analyst summarizes a client dossier in their own words, no name, no IBAN, no account number. Regex-based DLP sees no pattern and lets it through. The full context of the relationship leaves the company anyway.
The corporate ChatGPT quota runs out mid-deadline; the employee switches to a personal account and keeps pasting customer data. Same URL, same interface, but the data processing agreement, audit rights and deletion guarantees are gone.
Legal translates contracts, HR employment contracts, Finance audit reports, through DeepL, daily, in four-language Switzerland. Nobody classifies a translator as an AI risk. Whole documents leave the company, unmonitored.
Fits your stack
Layer 2 on top of Purview. Not a replacement.
NativeAI Guard covers what your existing DLP cannot: the prompt layer, the web surface, the AI apps outside the Microsoft perimeter. Browser extension today, Windows desktop agent in development, drop-in API proxy for internal systems. Swiss SaaS or on-premises; events stream into your SOC's SIEM.
Purview protects structured channels. NativeAI Guard protects the LLM prompt layer that Purview cannot inspect.
Security Architect · Swiss Financial Market Infrastructure
Compliance mapping
Every capability maps to an obligation.
Policy engine
Describe what to protect. In plain language.
Write the rule as you would explain it to a colleague; our own language model turns it into an enforceable policy. No classification trees, no regex, no labeling project.
Anonymize patient names, birth dates and diagnoses before they reach any AI tool.
Draft the discharge letter for Lea Brunner, born 14.05.1962, diagnosis type 2 diabetes (E11.9).
Draft the discharge letter for <PATIENT>, born <DATE>, diagnosis <DIAGNOSIS>.
And most of them are already written, by us.
The regulatory baseline is included in the product
The obligations under the Swiss DSG, GDPR and the EU AI Act that apply to everyone are covered from day one. Written by us, reviewed with security and compliance practitioners, and not left as an exercise for the customer.
A pack for your industry, on top
Banking secrecy, medical secrecy, insurance secrecy, plus public-sector and critical-infrastructure duties. The industry-specific cases are already modeled, so you start from a working set rather than a blank page.
We keep them current, as part of our service.
When a regulation changes, we update the standard policies and you receive them. Keeping up with the law is our job, not another item on your security team's list. It is included in the subscription.
Your own rules come from the documents you have already written.
Hand us your data protection rules, classification policy and AI directive, plus examples of your data structures. We turn them into your policies alongside the standard set, so you start from a working configuration. Edit or extend them in your admin interface at any time.
Deployment
Swiss-hosted or entirely inside your perimeter.
Most customers start on our Swiss infrastructure: it proves the value faster. Environments that cannot send anything outside their network run NativeAI Guard on their own hardware.
Swiss SaaS
Our servers, our datacenter, Lausanne
- Browser extension, rolled out through your existing MDM or Intune. A system-level endpoint agent for desktop applications is in active development.
- Live in days, not quarters. No network re-architecture, no proxy chain to untangle.
- All inspection and logging happens on our own servers in Lausanne, under Swiss law.
Best for: proving the value quickly, and for organizations for whom processing in Switzerland is already sufficient.
On-Premises
Your hardware, your network, your keys
- Runs in your own Kubernetes cluster, on hardware you control, inside your network perimeter.
- No prompt, no log and no policy ever leaves your environment, not even to us.
- Suited to security policies that forbid any external processing.
Best for: classified data, air-gapped networks and policies that prohibit any external processing.
- Same detection engine and policy language
- Full audit log, SIEM export and SOC integration
- No US cloud, no hyperscaler, in either case
- You can start on SaaS and move to on-prem
Common questions
Frequently asked questions
We already run Microsoft Purview. Does this replace Purview, or is NativeAI Guard complementary?
We complement it. Purview protects the structured channels it was built for: mail, endpoints, SharePoint. Its shadow-AI DLP runs only in Edge for Business, billed by usage and driven by static rules, and static rules and classification labels miss content whose sensitivity lies in its meaning, and the AI surface beyond the Microsoft perimeter. A Swiss bank's head of IT security put it plainly: closing that remainder inside Purview costs six figures in consulting; buying the layer is cheaper than building it. NativeAI Guard adds digital sovereignty: no new dependency on a US company.
Which surfaces do you cover today, and which are still coming?
Today: Chrome and Edge through the browser extensions, covering every browser-based AI tool, translation service and webmail, plus mobile devices; a drop-in API proxy protects the AI applications you build yourself. In active development: a system-level endpoint agent for desktop applications and command-line tools such as Claude Code. On the roadmap: macOS, Firefox and Safari, in the order the organizations working with us actually need.
What happens to a prompt while you inspect it? Is it stored?
Transient processing is the standard mode: the prompt is inspected in volatile memory on our own servers in Switzerland and discarded immediately, nothing of its content written to disk. What persists is the audit entry: who sent something, when, to which model, and what NativeAI Guard did about it. Retaining prompt content is an option for customers with record-keeping duties, banks in particular, and is switched on deliberately.
Do you use our data to train or tune your models?
No operational data. Prompts, metadata, decisions and usage logs generated through your use of the platform are never used to train, tune or validate machine-learning models, and that is written into the data processing agreement rather than left as a policy statement. Our classification models are pre-trained on synthetic and public corpora. The one exception is explicit and consent-based: if you choose to provide an anonymized calibration dataset during onboarding to tune detection to your own documents, that use is named in the contract and happens only because you asked for it.
Is the user blocked, or can they keep working?
Both, and the better answer is often a third option: anonymization. NativeAI Guard replaces the sensitive elements (names, client numbers, patient identifiers, contract references) before the prompt reaches the model, so the employee still gets a useful answer and keeps working. Hard blocking stays reserved for categories where no exception is acceptable, and every block is logged with the policy violation in the audit log.
What can an administrator configure?
Every domain can have its own rule, and a default rule applies automatically to all domains until you adjust it for a specific one. Each rule runs in its own mode: anonymization, policy enforcement, allow or block, so the same deployment can be strict in one place and light-touch in another. You write new rules in plain language by typing them in, and you adjust existing rules the same way. You create and manage user groups yourself, so rules can be enforced differently per team or department. The AI governance dashboard shows you at any time which rules are active and how they are being applied.
What about password-protected files, or a document whose classification label was removed before upload?
Password-protected files are intercepted at upload: the user enters the password and the content is scanned in the clear before anything is sent. Documents marked confidential are blocked outright; non-confidential ones are content-inspected, so a file whose label was removed is still caught. Rights-management-encrypted files (Microsoft Purview Information Protection, Azure RMS) are not inspected yet; until that ships, a policy can stop them at upload, so an uninspectable file is a decision, not a gap.
Book a demo
See live how NativeAI Guard stops data leaks.
A 45-minute session with the founders, online. We enter sensitive data into ChatGPT and show how NativeAI Guard anonymizes or blocks it in the same moment, based on different policies.
One month on your own prompts, we run it end to end.
The result: a risk overview of data leaks, shadow AI, AI usage and model costs, the evidence for your management that the topic is urgent.

