Your teams use ChatGPT, Claude, Gemini, Copilot, DeepSeek and browser extensions far beyond what your SSPM, LLM gateway or DLP/CASB can see. SentinelleIA operates the missing enforcement point: runtime supervision in the browser, at the endpoint and on the server, before exfiltration.
Four tool families dominate enterprise AI security today. Each addresses a legitimate segment, with a distinct operating mode (passive read or active enforcement). None, taken in isolation, covers the zone where data actually leaves the perimeter.
| Approach | Mode | Operation layer | Shadow AI blind spot |
|---|---|---|---|
| SSPM OAuth mapping, SaaS inventories |
Passive read | SaaS control plane via admin API | A posture tool, blocks nothing. Blind to prompt content. Blind to public models accessed via direct browsing. Blind to browser extensions and local MCP servers. |
| CASB API-mode Out-of-band, reads sanctioned SaaS |
Passive read | SaaS control plane via API | Same blind spot as SSPM. Sees the configuration of known SaaS, does not cover off-catalog usage. |
| LLM Firewall API Enterprise outbound gateway |
Active enforcement | Declared enterprise API | Blind to any model not going through the gateway, i.e. the dominant Shadow AI perimeter by definition. Handles neither multi-turn exfiltration nor token-by-token streaming. |
| CASB in-line / DLP / SWG HTTPS proxy, endpoint DLP, network DLP |
Active enforcement | Network (HTTPS proxy with TLS MITM) or OS (clipboard, syscalls) | A reading grid calibrated for structured data (IBAN, SSN, regex), with no LLM conversational semantics (injection, jailbreak, progressive leakage). Bypassed by desktop apps with certificate pinning. Massively bypassed outside the network perimeter (mobile, BYOD, remote work without SASE/ZTNA). Invisible to browser extensions and local MCP servers that orchestrate the flow in the DOM before emission. |
| SentinelleIA In-line control plane, multi-surface |
Active enforcement + observation | Browser (DOM via Manifest V3 extensions) + Endpoint (processes via Windows agents) + Server (orchestration) | The missing enforcement point, complementary to the four above. Active authorization policy per user, per department, per domain, applied at the point of creation. Capture of the content actually exchanged with an LLM-native reading grid (OWASP LLM Top 10). |
SSPM and API-mode CASB are posture tools (read-only). In-line CASB, DLP and SWG enforce policies but with a grid calibrated for structured data, not for natural language and the conversational patterns specific to LLMs. SentinelleIA operates an application-layer enforcement at the point of creation, with an LLM-native reading grid: complementary to, not a replacement for, the other tools.
Not a mockup. Not a PowerPoint. This is the SentinelleIA CISO console running in production.
Unified view of the supervised AI models, the open alerts and the active technical agents. Performance graphs, data flows and live incident timeline.
LIVE · production
Every prompt sent to ChatGPT, Claude, Gemini or DeepSeek is analysed in real time, with the machine, the user and the model that received it.
5 CRITICAL 5 BLOCKED
Unauthorised filesystem call blocked by agent-guard, Q4 financial data caught in a ChatGPT prompt, OpenAI API key detected before sending. Every alert is traceable by machine, user and source.
129 UNREAD
Rules created per target AI domain: block chat.openai.com, warn on *.deepseek.*, whitelist the rest. Three levels: BLOCK (access cut), WARN (warning), ALLOW (no log).
GRANULAR
5 supervised machines, 3 agents online. Each workstation runs endpoint + prompt-guard agents. Visibility by department, OS, IP and status.
3 AGENTS ONLINESentinelleIA covers the entire OWASP LLM Top 10 matrix (2025 edition). Each item is handled by one or more of the platform server-side agents.
| OWASP LLM item | Agents in charge |
|---|---|
| LLM01 — Prompt Injection | AI Firewall Prompt Guard |
| LLM02 — Sensitive Information Disclosure | Prompt Guard (input) LLM Security (output) |
| LLM03 — Supply Chain | Supply Chain Visibility |
| LLM04 — Data & Model Poisoning | Supply Chain Visibility |
| LLM05 — Improper Output Handling | LLM Security (classify_output) |
| LLM06 — Excessive Agency | Tool Protection Governance (politiques tools) |
| LLM07 — System Prompt Leakage | Prompt Guard LLM Security (analyze_response) |
| LLM08 — Vector & Embedding Weaknesses | Resilience (vector_integrity_check) |
| LLM09 — Misinformation | Resilience (check_hallucination embeddings) |
| LLM10 — Unbounded Consumption | Visibility Governance AI Firewall Gateway |
SentinelleIA is designed to address the technical requirements applicable to high-risk AI systems defined by Regulation (EU) 2024/1689, in particular the articles that structure a controlled enterprise deployment.
| Article | Requirement | Technical coverage |
|---|---|---|
| Art. 9 | Risk management system | Governance Visibility Resilience |
| Art. 10 | Data governance | Supply Chain Visibility |
| Art. 12 | Record-keeping, automatic logging | Supervisor (audit chain SHA-256) |
| Art. 13 | Transparency and user information | Governance Visibility (SBOM IA) |
| Art. 14 | Human oversight | Tool Protection (tool actuation policies) |
| Art. 15 | Accuracy, robustness, cybersecurity | Resilience AI Firewall LLM Security |
The coverage shown here is a technical and operational capability. Certified legal conformity in the sense of Annex IV / Art. 17 is a matter for an independent assessment (CSPN, ANSSI, notified body) and for the analysis of the using organization and its DPO.
Every prompt sent to ChatGPT potentially contains source code, customer data, trade secrets. This data is stored on foreign servers beyond your control.
39.7% of data movements into AI tools involve sensitive data (Cyberhaven Labs, 2026)Sending personal data to public LLMs breaches the GDPR. The EU AI Act requires a full inventory of every AI system in use, including the ones you are not aware of.
Fines up to 3% of global revenue (EU AI Act, art. 99)Your employees make business decisions based on unverified LLM answers. Buggy code shipped to production, contracts drafted by AI with invented clauses.
20% of AI answers contain major accuracy issues (EBU/BBC, 2025)You do not know who uses what, with which data, for what purpose. Employees bypass VPNs, use personal accounts and unapproved AI browser extensions.
Only 34% of organisations with an AI governance policy audit for unsanctioned AI (IBM, 2025)Every unlisted AI tool is an entry point for attackers: malicious plugins, compromised APIs, exfiltration via indirect prompt injection.
97% of organisations breached through an AI model or application had no AI access controls (IBM, 2025)Personal ChatGPT Plus subscriptions, APIs paid on corporate credit cards without approval... Shadow AI generates invisible, unbudgeted costs.
A sales rep copy-pastes a commercial proposal with pricing, client names and special terms into ChatGPT to "rephrase the email".
A dev installs an AI extension on their IDE. Their code (with hard-coded API keys) is sent to a third-party server for autocompletion.
HR uses a free AI tool to analyze resumes. Candidates personal data (name, address, degrees) is sent to a foreign server.
A lawyer uses DeepL Pro to translate a confidential M&A agreement. The full document transits through external servers.
Without an observation layer at the point of creation, the CISO has neither the logs, nor the alerts, nor the policies applicable to these usages. The data is already gone. And it starts again on Monday.
Five front-line protection functions, operated by nine server-side agents (detailed architecture on the agents page). Each function targets a facet of Shadow AI; together they deliver full visibility and control.
Blocks outbound flows to unauthorized LLMs. No data leaves your perimeter without your consent.
Learn more →Scans your network and detects all hidden AI usage: APIs, extensions, plugins, personal accounts.
Learn more →Zero-Trust gateway: every AI request is authenticated, logged and rate-limited. Full control of flows.
Learn more →Detects and masks sensitive data (PII, secrets, code) before it is sent to LLMs.
Learn more →Automatically generates the AI systems inventory, DPIAs and EU AI Act documentation.
Learn more →No. SentinelleIA is a complementary in-line AI control plane. It sits alongside an existing EDR and adds visibility those tools do not provide by design: analysis of LLM flows in browser and process memory, multi-turn exfiltration detection, real-time injection scoring.
Components deployed on the workstation: Chrome / Firefox browser extension (Manifest V3) and Windows endpoint agent. Memory and CPU footprint shared under NDA during the pilot phase.
Local analysis on the workstation for detection functions. Metadata and security events sent to the SentinelleIA supervisor hosted at your site (on-premises deployment or sovereign French cloud). No data sent to a non-European third-party service.
Standard GPO / MDM deployment with browser-extension lockdown via Chrome / Edge / Firefox enterprise policies. The endpoint agent registers as a protected Windows service. Emergency bypass procedure documented for CISO operations.
Dedicated deployment recommended for OIV / OES environments and any regulated sector. Multi-tenant mode available for mid-market companies under a logically isolated architecture.
Browser interception latency is designed to stay transparent to the user in supervision mode, independent of the remote model network latency. Precise measurements shared under NDA during the pilot phase.
Scope limited to 5-20 workstations for 48 hours. Deliverables: inventory of detected AI tools, qualification of outbound data flows, technical coverage of EU AI Act requirements on the scope, prioritized recommendations.
The agent processes personal data (user identifiers, prompt content that may contain PII) for security purposes. Legal basis: legitimate interest of the employing organization, documented in the PIA provided with the deployment. Employee information required via the internal rules or an amendment.
You submit your environment, we return a Shadow AI exposure report: detected AI tools, exposed data, measured attack rate and EU AI Act coverage.
Fill in the form below. An expert will get back to you within 24h to schedule your free diagnostic.
A SentinelleIA expert will get back to you within 24h to schedule your Shadow AI diagnostic.