Four pillars. One transparent proxy.
Shield deploys as a client-side agent + a control plane. No model training. No data retention. Patterns live in C-heap memory and are wiped after parse. Detection runs in <100ms across 27+ AI providers.
Data residency options
US, EU, CA, AU residency choices to meet regional regulatory requirements.
Transparent AI proxy
Reverse proxy intercepts traffic across major LLM providers without vendor lock-in.
Retention & deletion controls
Published retention schedules and on-demand deletion to meet legal and privacy requests.
Shield is not another security layer that runs next to your AI tools. It runs between your users and every AI provider, evaluating every prompt and every response before either party sees it.
Frontier and enterprise-grade.
PII Firewall
Inline inspection of every outbound prompt and inbound response. 180+ PII patterns covering all 18 HIPAA identifiers, PCI DSS cardholder data fields, GDPR special categories, and corporate-specific patterns you define. Detection in under 8ms per request. Redaction, block, or allow-with-log — your choice per data class. Client-side processing only: PII never leaves the device to be evaluated.
Agentic Trust
AI agents can request tool calls, execute code, access filesystems, and send network requests — often faster than any human can review. Defog assigns a trust score to every agent action based on the data classes it accesses, the tools it invokes, and the deviation from its stated purpose. Actions above your risk threshold require human confirmation. No confirmation, no execution.
SIEM Telemetry
Every Defog event — detection, block, allow, exception, policy change — streams to your SIEM in OCSF (Open Cybersecurity Schema Framework) format. Pre-built integrations for Splunk, Microsoft Sentinel, Elastic, and any webhook. Event volume: typical enterprise generates 400–800 Defog events per user per week, normalized to roughly 2KB each. Queryable the same day they appear.
Deepfake Defense
Frame-level analysis for video. Spectral analysis for audio. Provenance chain for images (C2PA metadata + hash verification). Defog's deepfake defense is designed specifically for the executive vishing scenario: a fraudulent video call using a CEO's cloned voice and face instructing a wire transfer. Real-time alert to the participant and their security team.
AI Security
Hardening for the AI you run: prompt-injection defense, jailbreak and exfiltration detection, model/endpoint allow-listing, and guardrails for tool-calling agents — so the assistants inside your walls cannot be turned against you.
Seamless DLP + Redaction
Inline detection and automatic redaction of PII, PHI, secrets, source, and contract text across prompts, files, images, and spreadsheets — client-side, before anything reaches a third-party model. Drop-in alongside your existing DLP, not a replacement.
Architecture
- Detection latency
- p50 12ms · p95 84ms · p99 142ms
- Coverage
- 27+ AI providers · 60+ web targets · 12 IDP integrations
- Memory model
- Patterns live in C-heap, wiped after parse · zero retention
- Hardware binding
- TPM/Secure Enclave attestation · per-device key
- Deployment
- Browser ext · OS agent · network proxy · all three at once
- Throughput
- 180k events/sec/tenant sustained · linear horizontal scale
- Update cadence
- Pattern packs weekly · model updates monthly · platform quarterly
- Offline mode
- Patterns cached on-device · resyncs on reconnect (air-gap variant available)
Reference architecture
Three planes. One control surface.
Edge plane (browser extension + OS agent + optional network proxy) inspects prompts and responses inline. Control plane (your cloud or ours) holds policy, identity, audit log. Telemetry plane streams OCSF events to your SIEM in real time. Each plane fails open or closed by policy — your choice, per data class.
Threat coverage
Prompt exfiltration
PII, secrets, source, contracts, IP — leaving your perimeter via LLM. Block, redact, or warn — by data class and user role.
Agent compromise
Prompt injection, tool-chain hijack, scope creep. Trust scoring + policy-as-code stops the agent before the action.
Deepfake & vishing
Frame-level analysis for video. Spectral analysis for audio. Provenance chain for images (C2PA metadata + hash verification). Defog's deepfake defense is designed specifically for the executive vishing scenario: a fraudulent video call using a CEO's cloned voice and face instructing a wire transfer. Real-time alert to the participant and their security team.
Shadow AI sprawl
Discover every AI provider your org touches — including the ones IT didn’t approve. 27+ first-class, long-tail via heuristics.
Model poisoning
Detect adversarial outputs and prompt-injection patterns coming back from the model. Halt the conversation before it acts.
Supply-chain AI
Score third-party AI features your vendors ship inside their products. Govern what you don’t own.
Have any questions?
Talk to the team that built Defog — security and product engineers, not a sales desk.