Pre-release. RedactWall is available in supervised pilots. See where it stands today.

FAQStraight answers, limits included.

The questions buyers actually ask, answered plainly. Everything about where this product stands today is gathered in one section at the bottom, so you never have to hunt for it.

Using it day to day

Do we have to stop staff using AI?

No. That is the point. Work carries on, and the things that should not leave are stopped. You are not choosing between productivity and control.

How long does it take to get running?

One setting change per application. You point an AI tool or a mail route at RedactWall and it starts deciding on the traffic flowing through it. There is no SDK for your developers to adopt and no application code to change.

Does anything get installed on staff laptops?

Not for the main controls, which run in the cloud. Optional device and browser components cover what leaves from a laptop and never passes a server, and they add to the cloud controls rather than replacing them.

What happens when RedactWall stops something?

The sensitive values are removed and the work carries on, or the request is held for someone to review, whichever your policy says for that kind of data. Your risk owner sets that and signs off before it takes effect.

Who can change the policy?

Whoever you grant that authority, and every change is recorded with their identity and the time. Twenty-one hard stops are fixed in the product and stay on regardless of how it is configured.

Data and privacy

Do you store our data?

No. Nothing we inspect is kept. The record says what kind of sensitive data was found and what was decided about it, never the data itself. Prompts, files, customer records and credentials stay out of our logs, our analytics and our error reports.

How do you match against our own records without holding them?

From a scrambled copy of your records that you provide. Matching works against that copy, and it cannot be turned back into the original data.

What happens if the system fails?

It denies rather than allows. If a decision cannot be recorded the request is refused rather than passed through unrecorded, and if the system cannot establish whose data it is looking at it returns nothing. An outage costs you availability, never a silent gap in the record.

Where does RedactWall run?

As a cloud service we operate. Your sensitive data is inspected in flight and never stored by us.

Evidence, audits and examinations

Will this help with AI compliance and examinations?

It supports preparation of material relevant to an audit or examination: a sealed package covering a period you name, and a way for your own team to confirm the record is intact. Disclosures states what is and is not claimed.

Why can our team check the evidence themselves?

Because evidence only the vendor can check is a claim. The verifier runs on your infrastructure with least privilege and no system of ours involved, so what you hand a reviewer stands on its own. How that works →

Can a package be edited after the fact?

No. Every decision lands on a record where tampering is a detectable event rather than an editable row, and a package names its reporting window at the moment it is made. The examination package →

Are you certified?

Not yet. The full status is in Disclosures below, along with what stands in its place today.

Disclosures

Everything about where this product stands today, gathered here rather than scattered across the site. Your diligence team will ask for it, so it is published rather than supplied on request.

Product status

RedactWall is pre-release software, available in supervised pilots, operated as a cloud service by RedactWall.

Certification, audit and endorsement

Certification and attestation status
ItemStatusWhat that means for your review
SOC 2 reportnot startedThere is no report and no interim letter to point at.
ISO, PCI, HIPAA, NCUAnot claimedNo certification is held or claimed under any of these.
Independent penetration testnot commissionedNo third party has tested this product. Treat the security properties on this site as claims to test yourself.
Regulatory endorsementnoneNo regulator endorses this or any comparable product. We do not say “NCUA-ready” or “examiner-approved”, because no such endorsement exists in this category.
Examination readinessnot claimedReadiness is a property of your organization and the people who review it, not of a vendor’s software.
What stands in their place today: evidence you verify yourself. The chain verifier and the examination-package verifier both run on your infrastructure with least privilege and no system of ours involved. Verify it yourself →

What each surface does, and how far it is proven

Coverage and proof status by surface
SurfaceLevelWhere it stands
AI tools and assistantsdecides before data leavesChecks what your applications send to an AI provider and what comes back, before either one moves, and records both. Fail-closed if evidence cannot be committed.
Outbound emaildecides before data leavesChecks the whole message, including every attachment and nested container, and decides before it is accepted for delivery. Anything it cannot read as text, meaning every PDF, zip file and Office document, is refused rather than scanned, which is a standing operational cost to plan for. Proven against a real cluster. In testing so far both the submitting peer and the next hop have been servers we scripted ourselves, so no production mail server has yet submitted to it.
Microsoft 365 and Google Drivefinds and reports not yet run against the live serviceReads what is already sitting in your drives and reports what it finds, without copying it. It reports what it found rather than preventing anything, because it is not on the path. One run enumerates one folder page and does not recurse; Google is shared drives only, and Google Docs, Sheets and Slides files are not read. Tested against those providers’ published interfaces, not yet against a live tenant.
AI agents and their toolson the deviceApproves or refuses each tool an AI agent tries to use before it runs, and checks the result before the agent sees it. It governs the tools an agent reaches through RedactWall; one it reaches another way is outside it. Blocking inside the assistant itself is in design and not shipped.
Laptops and browserson the deviceSensors on customer-controlled machines; the server re-derives their claimed decisions and refuses any that disagree with the activated policy. Device coverage is Windows and Chrome.

Model providers

Upstream model provider proof status
ProviderStatusWhat that status means
Anthropicrun against the live serviceThe product was run against Anthropic’s live service under a real account, the request succeeded, and both decisions were recorded (2026-08-14).
OpenAI-compatiblenot yet run against the live serviceTested against the provider’s published interface. First contact with the live service is work a pilot does.
Gemininot yet run against the live serviceTested against the provider’s published interface. First contact with the live service is work a pilot does.
Bedrocknot yet run against the live serviceTested against the provider’s published interface. Its request signing is checked against Amazon’s published reference and has not been presented to AWS itself.

Reading the two statuses. run against the live service means the shipped product reached the real provider under a real credential. not yet run against the live service means the connection is built to the provider’s published interface, which cannot show that the live service accepts what this product sends, or that throttling is survivable.

Scope of the product

  • It is data loss prevention for the paths AI uses. Stopped inline in AI tools and outbound email; found and reported after the fact in cloud drives. It does not replace endpoint DLP, and it does not quarantine, encrypt or revoke access to anything.
  • It stops a disclosure; it does not rotate or revoke a credential. When a secret is caught, the disclosure is stopped and the finding goes to your team to act on.
  • Evidence covers the paths you deployed. A workflow that never crossed one produces no entries, and every successful verifier run states plainly what the bundle does and does not prove.
  • Nothing it produces is an audit finding or an opinion about your control environment. It supports preparation of material; it does not make an organization compliant.
  • Coverage follows the path, not the tool. A staff member typing into a consumer AI tab is reached by the device and browser components; an agent’s tool calls by AI Agent Security; API traffic by the gateway.