— Integrations

Plug into the stack you already paid for.

timeline

Delta policy simulation

See what a policy change would have caught before deployment to reduce false positives.

integration_instructions

Marketplace & partner channels

CrowdStrike, SentinelOne, and SIEM marketplaces speed procurement and deployment.

auto_awesome

Provenance analytics at scale

Postgres hot cache + BigQuery overflow for historical sighting and trend analysis.

The Ecosystem You Already Secure.

Shield was built to disappear into the stack you already run. Detection that lives in a silo is detection nobody acts on, so every verdict Shield produces is structured, CIM-compliant JSON that lands in your SIEM, your data lake, and your ticketing system without a line of glue code. If your analysts live in Splunk, the events arrive as Splunk events; if your platform team standardized on Elastic or Datadog, the same telemetry shows up there, normalized and ready to correlate.

Out of the box, Shield speaks the languages your operations already trust. Splunk HEC and the Microsoft Sentinel ingestion API receive alerts the instant a prompt is flagged or a response is blocked. Elastic and Datadog get the same stream for long-horizon hunting and dashboards. A generic webhook and exportable connectors cover everything else — from a homegrown SOAR runbook to a Slack channel that pages the on-call the moment a high-severity manipulation attempt crosses the wire.

Access follows the rules you have already written. Shield federates with your identity provider over SAML and OIDC, so Okta, Microsoft Entra ID, Google Workspace, and Ping map cleanly onto Shield’s tenant and role model. Analysts inherit the groups they already belong to, offboarding takes effect the instant HR disables an account, and every administrative action is written to an immutable audit trail your compliance team can export on demand.

On the other side of the wire, Shield sits between your users and every major model — OpenAI, Anthropic, Google, Azure OpenAI, AWS Bedrock, and the open-weight models you host yourself — evaluating each prompt and each response before either party sees it. PII is caught and redacted against dozens of built-in patterns plus the custom ones you define; prompt-injection and data-exfiltration attempts are scored and stopped; and the verdict, the reason, and the policy that fired are all logged for review.

None of this requires a forklift. Shield deploys as a reverse proxy, an SDK, or a gateway sidecar, and runs in your cloud, your VPC, or fully air-gapped on your own metal. You keep your keys, your data never leaves your boundary, and the integration you stand up on day one is the same one that scales to every team in the company.

— Identity
OktaEntra IDAuth0PingOneLoginJumpCloud
— Endpoint / EDR
CrowdStrikeSentinelOneDefenderJamfIntuneKandjiTaniumMosyle
— SIEM / Observability
SplunkSentinelElasticDatadogSumoChronicle
— Network / Gateway
ZscalerNetskopePalo AltoCiscoForcepointCloudflare

Don’t see yours?

Shield speaks OCSF, CEF, LEEF and raw JSON over HTTPS or syslog. If your tool ingests events, we ship them. Custom adapters are 1–2 weeks; we don't charge for them.

Have any questions?

Talk to the team that built Defog — security and product engineers, not a sales desk.

Email us