
See every AI app, model, and agent.
Control sensitive data before
it reaches an
AI tool
Orthalon correlates observed AI use from browsers, compatible desktop clients, model APIs, MCP, identity systems, and security gateways. Apply identity-aware DLP and keep source-backed governance evidence in one control plane.
Prompt checks run on the endpoint. Gateway traffic is processed in memory. Orthalon stores security metadata, not raw prompts.
The control plane for enterprise AI adoption
Orthalon gives security and IT teams one place to find AI use, enforce policy, review incidents, and prepare evidence across browsers, desktop clients, model APIs, identity systems, network controls, and MCP.
One inventory for workforce AI
Orthalon combines observed signals from browsers, desktop agents, the AI gateway, identity systems, network and CASB imports, and MCP clients. Each record shows its discovery source, last-seen time, sanction state, account context, and available risk evidence.
Start a free discovery assessmentPrompt and file DLP
Orthalon detects credentials, personal and health data, validated national identifiers, payment and banking data, source code, and company-specific patterns in prompts and supported files. Policies can monitor, coach, redact, require approval, or block before submission.
Source-backed AI governance intelligence
Review provider training policies, retention windows, hosting regions, certifications, subprocessors, and enterprise controls. Each fact records its source and version so admins can distinguish vendor evidence from AI applications observed inside their organization.
Governance evidence
Orthalon maps observed AI use, policy decisions, approvals, administrative actions, and vendor evidence to EU AI Act, ISO 42001, and NIST AI RMF controls. Reports use security metadata and control records instead of raw prompt bodies.
Framework Mapping
Automated alignment of policy decisions and AI events to EU AI Act and ISO 42001 controls.
Privacy-Safe Logs
Audit records use clean security metadata, system headers, and action logs instead of prompt content.
Evidence Packs
Audit ReadyExport versioned bundles containing observations, logs, and source-backed vendor facts for compliance checks.
Policy Intercept
Browser, gateway, or MCP event
Privacy Sanitization
Clean metadata and timestamp logged
Evidence Pack
Control facts generated & signed
Identity-aware policy and approvals
Target browser, desktop, and gateway rules by application, sanction state, detector, enrolled-member role, and trusted account context. Simulate matching and near-miss selector combinations before activation, then allow, redact, require a bounded approval, or block. Browser flows can show coaching; headless clients receive decision metadata. Wrapped MCP stdio uses separate server and tool rules.
Browser prompt and file protection
Orthalon checks prompts and small readable files on the device before Chrome or Edge submits them. Business and Enterprise can inspect supported PDF, Office, spreadsheet, and ZIP files through a private short-lived analysis path. Teams can test a Firefox pilot; Safari requires conversion, signing, and acceptance testing.
- On-device inspection before submission
- Monitor, coach, redact, approve or block
- Local text checks and bounded document analysis

Desktop and IDE protection
Protect sensitive prompts, source code, and credentials in desktop and developer tools that can use a custom model API endpoint. Inspection runs on the device. Identity and network connectors can still reveal fixed-backend tools whose content cannot be inspected.
- Managed endpoint packages for macOS, Windows, and Linux
- Applies policy to supported AI requests and responses
- Keeps policy active and queues security records during outages
AI gateway for model API calls
Route OpenAI, Anthropic, Gemini, and OpenAI-compatible API calls through an organization-authenticated gateway. Orthalon inspects requests and supported response streams, applies organization policy, and records decision metadata.
- Gateway routing for leading model APIs
- Real-time request & response stream inspection
- Policy enforcement and metadata-only decision records

MCP discovery and stdio policy
The endpoint agent inventories MCP servers and tools from supported client configurations. An allowlisted stdio wrapper can allow, deny, redact, or require approval for tool calls. Orthalon inventories HTTP and SSE connections without enforcing their tool calls.
SSO, SCIM, teams, and access control
Admins can configure SSO/SAML, SCIM, teams, and role-based access. Supported browser adapters can apply different policy to personal accounts, managed workspaces, and sessions with unknown account context.


Identity, SaaS, CASB, and network discovery
Identity and SaaS connectors cover Google Workspace, Microsoft Entra, Okta, Slack, and GitHub. Security telemetry adapters accept Cloudflare, Zscaler, Netskope, Microsoft Defender, Palo Alto, iboss, and Chrome Enterprise data.
Built-in and custom data detectors
Built-in detectors cover credentials, personal and health data, US Social Security numbers, UK National Insurance and NHS numbers, Brazilian CPF, Polish PESEL, payment and banking identifiers, source code, and internal IPv4 ranges. Security teams can add bounded company-specific patterns and test matching and near-miss cases before enforcement.
Violation reports and audit records
Security teams can review violations, approvals, sanctions, policy changes, and administrative actions in organization-scoped logs. Business and Enterprise plans add evidence exports and 13-month rollups.
Metadata-only security records
Browser and compatible desktop checks run on the device. The AI gateway processes routed content in memory. Orthalon stores detector metadata, decisions, timestamps, and placeholders instead of raw prompt or file content.
Guided AI discovery assessment
New organizations can assess AI use before enforcement. Orthalon separates observed assets from global catalog entries, records each discovery source and last-seen time, and lets admins sanction or review each application.

Managed and self-hosted deployment
Use Orthalon's managed service today. An Enterprise self-hosted deployment option is coming soon. Browser extensions, desktop agents, and MCP agents will continue to run on managed endpoints.
See a security policy decision before data reaches the AI destination
Pick an enforcement point and a policy action, then inspect a synthetic prompt, file, model call, or tool call. This runs the real detection engine in your browser tab and sends nothing to Orthalon.
Orthalon policy lab
· Local product simulationScenario
Live inspection
3 findingsInternal email domains · 1@orthalon.example
Pricing that scales with your workforce
Start with free monitoring. Turn on enforcement and reporting as you grow.
Monitor
Protect
Business
Enterprise
Questions, answered.
Get started
Build an evidence-backed AI governance baseline
Create a free organization, connect a browser source, and review the first observed application. Add identity-aware enforcement, connectors, MCP controls, and reporting when your rollout needs them.


