— Shield / Platform

Four pillars. One transparent proxy.

Shield deploys as a client-side agent + a control plane. No model training. No data retention. Patterns live in C-heap memory and are wiped after parse. Detection runs in <100ms across 27+ AI providers.

public_off

Data residency options

US, EU, CA, AU residency choices to meet regional regulatory requirements.

auto_awesome

Transparent AI proxy

Reverse proxy intercepts traffic across major LLM providers without vendor lock-in.

backup

Retention & deletion controls

Published retention schedules and on-demand deletion to meet legal and privacy requests.

Shield is not another security layer that runs next to your AI tools. It runs between your users and every AI provider, evaluating every prompt and every response before either party sees it.
— Defog platform overview

Frontier and enterprise-grade.

gpp_good

PII Firewall

Inline inspection of every outbound prompt and inbound response. 180+ PII patterns covering all 18 HIPAA identifiers, PCI DSS cardholder data fields, GDPR special categories, and corporate-specific patterns you define. Detection in under 8ms per request. Redaction, block, or allow-with-log — your choice per data class. Client-side processing only: PII never leaves the device to be evaluated.

smart_toy

Agentic Trust

AI agents can request tool calls, execute code, access filesystems, and send network requests — often faster than any human can review. Defog assigns a trust score to every agent action based on the data classes it accesses, the tools it invokes, and the deviation from its stated purpose. Actions above your risk threshold require human confirmation. No confirmation, no execution.

stream

SIEM Telemetry

Every Defog event — detection, block, allow, exception, policy change — streams to your SIEM in OCSF (Open Cybersecurity Schema Framework) format. Pre-built integrations for Splunk, Microsoft Sentinel, Elastic, and any webhook. Event volume: typical enterprise generates 400–800 Defog events per user per week, normalized to roughly 2KB each. Queryable the same day they appear.

security

Deepfake Defense

Frame-level analysis for video. Spectral analysis for audio. Provenance chain for images (C2PA metadata + hash verification). Defog's deepfake defense is designed specifically for the executive vishing scenario: a fraudulent video call using a CEO's cloned voice and face instructing a wire transfer. Real-time alert to the participant and their security team.

gpp_good

AI Security

Hardening for the AI you run: prompt-injection defense, jailbreak and exfiltration detection, model/endpoint allow-listing, and guardrails for tool-calling agents — so the assistants inside your walls cannot be turned against you.

gpp_good

Seamless DLP + Redaction

Inline detection and automatic redaction of PII, PHI, secrets, source, and contract text across prompts, files, images, and spreadsheets — client-side, before anything reaches a third-party model. Drop-in alongside your existing DLP, not a replacement.

Architecture

Detection latency
p50 12ms · p95 84ms · p99 142ms
Coverage
27+ AI providers · 60+ web targets · 12 IDP integrations
Memory model
Patterns live in C-heap, wiped after parse · zero retention
Hardware binding
TPM/Secure Enclave attestation · per-device key
Deployment
Browser ext · OS agent · network proxy · all three at once
Throughput
180k events/sec/tenant sustained · linear horizontal scale
Update cadence
Pattern packs weekly · model updates monthly · platform quarterly
Offline mode
Patterns cached on-device · resyncs on reconnect (air-gap variant available)
Defog Shield architecture diagram

Reference architecture

Three planes. One control surface.

Edge plane (browser extension + OS agent + optional network proxy) inspects prompts and responses inline. Control plane (your cloud or ours) holds policy, identity, audit log. Telemetry plane streams OCSF events to your SIEM in real time. Each plane fails open or closed by policy — your choice, per data class.

Threat coverage

gpp_good

Prompt exfiltration

PII, secrets, source, contracts, IP — leaving your perimeter via LLM. Block, redact, or warn — by data class and user role.

smart_toy

Agent compromise

Prompt injection, tool-chain hijack, scope creep. Trust scoring + policy-as-code stops the agent before the action.

security

Deepfake & vishing

Frame-level analysis for video. Spectral analysis for audio. Provenance chain for images (C2PA metadata + hash verification). Defog's deepfake defense is designed specifically for the executive vishing scenario: a fraudulent video call using a CEO's cloned voice and face instructing a wire transfer. Real-time alert to the participant and their security team.

stream

Shadow AI sprawl

Discover every AI provider your org touches — including the ones IT didn’t approve. 27+ first-class, long-tail via heuristics.

lock

Model poisoning

Detect adversarial outputs and prompt-injection patterns coming back from the model. Halt the conversation before it acts.

link

Supply-chain AI

Score third-party AI features your vendors ship inside their products. Govern what you don’t own.

Drop in. Change nothing. Seeeverything.·every prompt.·every agent.·every signal.·Drop in. Change nothing. Seeeverything.·every prompt.·every agent.·every signal.·Drop in. Change nothing. Seeeverything.·every prompt.·every agent.·every signal.·Drop in. Change nothing. Seeeverything.·every prompt.·every agent.·every signal.·Drop in. Change nothing. Seeeverything.·every prompt.·every agent.·every signal.·Drop in. Change nothing. Seeeverything.·every prompt.·every agent.·every signal.·Drop in. Change nothing. Seeeverything.·every prompt.·every agent.·every signal.·Drop in. Change nothing. Seeeverything.·every prompt.·every agent.·every signal.·

Have any questions?

Talk to the team that built Defog — security and product engineers, not a sales desk.

Email us