See every AI app, model, and agent.
Control sensitive data before
it reaches an ChatGPTAI tool

Orthalon correlates observed AI use from browsers, compatible desktop clients, model APIs, MCP, identity systems, and security gateways. Apply identity-aware DLP and keep source-backed governance evidence in one control plane.

Prompt checks run on the endpoint. Gateway traffic is processed in memory. Orthalon stores security metadata, not raw prompts.

Govern supported browser, endpoint, model API, and MCP traffic
ChatGPTClaudeGeminiMicrosoft CopilotCursorPerplexityPoeMistral AIAleph AlphaDeepLBlack Forest LabsSynthesiaHugging FaceDeepSeekQwenKimi ChatDoubaoERNIE BotGLMYi

The control plane for enterprise AI adoption

Orthalon gives security and IT teams one place to find AI use, enforce policy, review incidents, and prepare evidence across browsers, desktop clients, model APIs, identity systems, network controls, and MCP.

One inventory for workforce AI

Orthalon combines observed signals from browsers, desktop agents, the AI gateway, identity systems, network and CASB imports, and MCP clients. Each record shows its discovery source, last-seen time, sanction state, account context, and available risk evidence.

Start a free discovery assessment
Orthalon logo
Applications
Models
Agents
MCP servers
MCP tools
AI extensions

Prompt and file DLP

Orthalon detects credentials, personal and health data, validated national identifiers, payment and banking data, source code, and company-specific patterns in prompts and supported files. Policies can monitor, coach, redact, require approval, or block before submission.

Real-time inspection
Checks prompts and small readable files locally; supported documents use private short-lived analysis
Policy actions
Monitor, coach, redact, require approval, or block matching patterns
Custom detectors
Add company-specific patterns and test results before enforcement
Prompt Preview
Sensitive data detected
Live ScanDLP Triggered
Source: Browser Extension
Target: Anthropic Claude
Status: Intercepted
Redaction Layer
Scanning & stripping secrets
PII (40%)Keys (35%)Safe (25%)
EnforcementRedacted
Prompts were cleaned of all sensitive metadata and safely submitted to the model.
SuccessTransformed
USA
EU
China

Source-backed AI governance intelligence

Review provider training policies, retention windows, hosting regions, certifications, subprocessors, and enterprise controls. Each fact records its source and version so admins can distinguish vendor evidence from AI applications observed inside their organization.

Governance evidence

Orthalon maps observed AI use, policy decisions, approvals, administrative actions, and vendor evidence to EU AI Act, ISO 42001, and NIST AI RMF controls. Reports use security metadata and control records instead of raw prompt bodies.

Framework Mapping

Automated alignment of policy decisions and AI events to EU AI Act and ISO 42001 controls.

Privacy-Safe Logs

Audit records use clean security metadata, system headers, and action logs instead of prompt content.

Evidence Packs

Audit Ready

Export versioned bundles containing observations, logs, and source-backed vendor facts for compliance checks.

Policy Intercept

Browser, gateway, or MCP event

Privacy Sanitization

Clean metadata and timestamp logged

Evidence Pack

Control facts generated & signed

Identity-aware policy and approvals

Target browser, desktop, and gateway rules by application, sanction state, detector, enrolled-member role, and trusted account context. Simulate matching and near-miss selector combinations before activation, then allow, redact, require a bounded approval, or block. Browser flows can show coaching; headless clients receive decision metadata. Wrapped MCP stdio uses separate server and tool rules.

Browser prompt and file protection

Orthalon checks prompts and small readable files on the device before Chrome or Edge submits them. Business and Enterprise can inspect supported PDF, Office, spreadsheet, and ZIP files through a private short-lived analysis path. Teams can test a Firefox pilot; Safari requires conversion, signing, and acceptance testing.

  • On-device inspection before submission
  • Monitor, coach, redact, approve or block
  • Local text checks and bounded document analysis
Laptop displaying AI development tools protected by Orthalon

Desktop and IDE protection

Protect sensitive prompts, source code, and credentials in desktop and developer tools that can use a custom model API endpoint. Inspection runs on the device. Identity and network connectors can still reveal fixed-backend tools whose content cannot be inspected.

  • Managed endpoint packages for macOS, Windows, and Linux
  • Applies policy to supported AI requests and responses
  • Keeps policy active and queues security records during outages

AI gateway for model API calls

Route OpenAI, Anthropic, Gemini, and OpenAI-compatible API calls through an organization-authenticated gateway. Orthalon inspects requests and supported response streams, applies organization policy, and records decision metadata.

  • Gateway routing for leading model APIs
  • Real-time request & response stream inspection
  • Policy enforcement and metadata-only decision records
Model Context Protocol (MCP) connection node diagram illustrating secure client-server model tool calls and stdio discovery mapping

MCP discovery and stdio policy

The endpoint agent inventories MCP servers and tools from supported client configurations. An allowlisted stdio wrapper can allow, deny, redact, or require approval for tool calls. Orthalon inventories HTTP and SSE connections without enforcing their tool calls.

SSO, SCIM, teams, and access control

Admins can configure SSO/SAML, SCIM, teams, and role-based access. Supported browser adapters can apply different policy to personal accounts, managed workspaces, and sessions with unknown account context.

SSO, SCIM, teams, and access control dashboard visualization showing circular layered business data
Identity, SaaS, CASB, and network discovery connector hardware

Identity, SaaS, CASB, and network discovery

Identity and SaaS connectors cover Google Workspace, Microsoft Entra, Okta, Slack, and GitHub. Security telemetry adapters accept Cloudflare, Zscaler, Netskope, Microsoft Defender, Palo Alto, iboss, and Chrome Enterprise data.

Built-in and custom data detectors

Built-in detectors cover credentials, personal and health data, US Social Security numbers, UK National Insurance and NHS numbers, Brazilian CPF, Polish PESEL, payment and banking identifiers, source code, and internal IPv4 ranges. Security teams can add bounded company-specific patterns and test matching and near-miss cases before enforcement.

Security Audit Trail
OpenAI Prompt
Sanitized
AWS Secret Upload
Blocked
Gemini File Transfer
Warned
Showing last 3 incidentsTotal: 1,248

Violation reports and audit records

Security teams can review violations, approvals, sanctions, policy changes, and administrative actions in organization-scoped logs. Business and Enterprise plans add evidence exports and 13-month rollups.

On-Device Privacy Sanitizer
Raw User Prompt
PII Detected
Stored Metadata
{
"action": "redact",
"pii_types": ["key"],
"bytes_saved": 142
}
Zero PII Stored
Content processed in-memory & discarded

Metadata-only security records

Browser and compatible desktop checks run on the device. The AI gateway processes routed content in memory. Orthalon stores detector metadata, decisions, timestamps, and placeholders instead of raw prompt or file content.

AI Discovery Scanner
85%Coverage
Total AI Apps42
Sanctioned12
Unsanctioned30
Scan frequency: Continuous

Guided AI discovery assessment

New organizations can assess AI use before enforcement. Orthalon separates observed assets from global catalog entries, records each discovery source and last-seen time, and lets admins sanction or review each application.

3D metallic electronics cooling tower showing transparent case and internal hardware fan representing secure server deployment
Coming soon

Managed and self-hosted deployment

Use Orthalon's managed service today. An Enterprise self-hosted deployment option is coming soon. Browser extensions, desktop agents, and MCP agents will continue to run on managed endpoints.

Interactive demo · Synthetic data

See a security policy decision before data reaches the AI destination

Pick an enforcement point and a policy action, then inspect a synthetic prompt, file, model call, or tool call. This runs the real detection engine in your browser tab and sends nothing to Orthalon.

Orthalon logo

Orthalon policy lab

1. Where the check runs
2. What policy does when it finds sensitive data

Redact: The message box is rewritten with placeholders before submission.

Scenario

ChatGPT · managed browser session

Live inspection

3 findings
Email addressPhone numberPersonal name

Internal email domains · 1@orthalon.example

No account or setup required
Compare plans

Pricing that scales with your workforce

Start with free monitoring. Turn on enforcement and reporting as you grow.

Save 20%

Monitor

$0
Guided AI discovery assessment & risk catalog
Browser, desktop & model API monitoring
Read-only metadata events and posture views
30-day retention · up to 25 users

Protect

14 days free trial
$15/ user / mo
Everything in Monitor
Prompt and readable-file enforcement
Identity-aware policy templates & tester
Bounded approvals and violations workflow
Chrome, Edge & Firefox pilot rollout · 90-day retention

Business

14 days free trial
$29/ user / mo
Everything in Protect
SSO/SAML and custom detectors
Governance evidence plus event & audit exports
AI response inspection for gateway & desktop
Versioned evidence · 13-month rollups

Enterprise

Custom
Everything in Business
SCIM, teams & advanced RBAC
MCP inventory and stdio runtime policy
Seven security telemetry connectors plus identity/SaaS discovery
Residency options, SLA & named contact
FAQ

Questions, answered.

Get started

Build an evidence-backed AI governance baseline

Create a free organization, connect a browser source, and review the first observed application. Add identity-aware enforcement, connectors, MCP controls, and reporting when your rollout needs them.