On the device
Device & Browser ProtectionCover what leaves .
Some sensitive data never crosses a path you can govern. It is copied to a clipboard, dropped into a folder that syncs to a personal cloud, or typed into whatever AI tab is open. A Windows sensor and a Chrome extension cover those.
What that looks like in practice
- A customer record is copied out of your system of record and pasted elsewhere → caught on the device where it happened.
- Files land in a folder that syncs to a staff member’s personal cloud → seen and decided, not discovered months later.
- Staff sign up for AI tools nobody approved → you get an inventory of what is actually running on your machines.
- A device reports that it blocked something → the server confirms it against your rules before it counts.
What you get
- Reach where no server sits in the path. Clipboard, cloud-sync folders, and the AI sites you choose to govern in the browser.
- An inventory before you enforce. See which AI tools are in use across the machines you enrol, then decide how tightly to hold them.
- Verified, not believed. A device claim is checked centrally against the rules your risk owner approved, and refused if it disagrees.
- One rule set. A clipboard event and a blocked prompt are judged the same way, and land on the same record.
Start with one department
Enrol machines through the management tooling you already run, choose the sites you want governed, and let the inventory tell you what staff are really using. Levels for every surface are on Coverage.