Your people use AI every day, and most of it is not the tool you pay for. SafeToOpen Browser Security names the platforms your organisation sanctions, warns on or blocks the rest, keeps personal and confidential data out of unsanctioned AI at the moment of the paste, and reports who uses which AI tools. Workspace policy, no proxy, no agent.
Everything below is a setting in the Browser Security console, applied by the extension your fleet already runs.
ChatGPT, Copilot, Gemini, Claude, Perplexity, DeepSeek, Grok and forty more are recognised out of the box; add your own internal portals. Each edition is sanctioned, tolerated or unsanctioned.
Work vs personal editionsTolerated tools show a banner with your wording and the approved alternative. Unsanctioned ones show a notice the person must accept, or are blocked outright.
Warn, block or monitorPasted text, the prompt at the moment it is sent, and file uploads are allowed, checked, warned on or refused per tier. Personal information never reaches an unsanctioned tool.
Paste, prompt, uploadWho uses which AI tools, how long, how many prompts and uploads, sanctioned share, refusals, per workspace and per person. CSV export in one click.
ISO 42001 · EU AI ActThree tiers cover every organisation’s stance, from “we have not decided yet” to “never on a work device”. Typical setup: your contracted tools sanctioned, their personal editions unsanctioned, the long tail tolerated while you read the report.
The contract covers it. Nothing is shown, pastes and uploads are allowed, usage is counted for the report.
A banner with your message on every visit. Paste Guard warns when personal information is found. The right home for the long tail while you decide.
A notice the person must accept, or the page is blocked. Pastes and prompts carrying personal information are refused; uploads are refused outright. Each event can be an incident.
ChatGPT, Gemini and Claude serve work and personal accounts from the same address. SafeToOpen tells them apart from the signed-in account and the vendor’s plan markers, so the contracted edition stays quiet and the personal one is governed.
The moment data leaves the browser is the moment that matters. For each tier you decide what happens to pasted text, to the prompt as it is sent, and to file uploads.
Refuse when personal information is found holds the paste for under a second, checks it against the same engine Paste Guard already uses, and refuses it with a plain notice listing the categories found: name, email, phone, card number, date of birth, credentials. Refuse always closes the door regardless of content. Every refusal is counted per platform and, if you wish, recorded as an incident naming the member, the categories and the platform, so webhooks, SIEM and response rules see it.
AI is where the attention is, but personal Google Drive, Gmail, Dropbox, WeTransfer, WhatsApp Web and paste sites are where the files actually go. The same three tiers, the same Paste Guard matrix and the same report cover them.
Google Drive and Gmail on a personal account are governed; the same sites on your Workspace tenant are not. Personal OneDrive and Outlook.com by address.
Uploads are the usual way data leaves. The recommended unsanctioned row refuses them outright and refuses pastes and messages that carry personal information.
Where screenshots and snippets get shared. Banner, notice or block with your wording, counted and reported like everything else.
Three techniques now lead initial access without a malicious download or a fake login form. Browser Security has a guard for each, and an inventory that shows where your people sign in without single sign-on.
The page copies a PowerShell, mshta or curl-pipe-shell command to the clipboard and tells the person to paste it. The guard replaces the clipboard with a harmless note, shows what the page tried, and records the payload as a critical incident.
CLICKFIX_ATTEMPTMFA passes, the person grants an app mailbox or files access that survives a password reset. The guard reads the consent screen and warns on, or blocks, any app outside your approved list that asks for sensitive permissions.
OAUTH_CONSENT_RISKYA salted fingerprint of the password learned on your identity provider, kept on the device only. Typing it into a proxy phishing kit or a personal site is caught before the submit leaves.
PASSWORD_REUSEEvery site where members sign in with a password of their own, per person and per workspace, with the sites where the work password was reused. Hosts and counts only.
CSV for the auditISO 42001, the EU AI Act and cyber-insurance questionnaires all come down to the same three questions: which AI tools are in use, which are sanctioned, and what control applies to the rest. The report answers them for the period you choose, per workspace and per person, with a CSV for the evidence folder.
Shadow AI is staff using AI tools the organisation has not approved: a personal ChatGPT account beside the corporate Copilot, a free summariser, an AI meeting note-taker. The risk is not the tool but what goes into it: customer records, contracts, source code and credentials pasted into a service with no contract, no retention control and often training rights. Boards, auditors, ISO 42001 and the EU AI Act now ask organisations to show which AI tools are in use and what control is applied.
Microsoft 365 Copilot and consumer Copilot live on different addresses, so the address decides. ChatGPT, Gemini and Claude serve both from one address, so the extension looks at the signed-in account: an address on your work domains marks the work edition, anything else the personal one, backed by the vendor’s own plan markers. Until it has seen either signal the tier you choose for unknown editions applies.
That depends on the Paste Guard matrix you set per tier. On a sanctioned platform the paste is allowed, because your contract covers it. On a tolerated one it lands and the person is warned when personal information is found. On an unsanctioned one the paste is held for a moment, checked, and refused if it carries personal or confidential information; the prompt box and file uploads are covered the same way. Every refusal is counted and can be recorded as an incident naming the person, the categories and the platform.
No. Tiers are decided from the address and the account area of the page. Usage is counted as visits, time spent, prompts sent and files uploaded per platform, never their content. Text that Paste Guard checks goes to the same personal-information engine it already uses, and nothing is stored.
Yes. The extension can enforce Microsoft’s tenant restrictions and Google Workspace’s allowed-domains control on managed browsers, so a personal Microsoft or Google account cannot sign in at all in that browser: Copilot, Outlook and OneDrive, Gmail and Gemini alike. It is a whole-account control, so it is off by default and switched on per workspace.
No. It is workspace policy for the extension your fleet already runs, deployed through Intune, Group Policy, Jamf or Chrome Enterprise. There is nothing to route traffic through and nothing to install on the endpoint.
Yes. Cloud, mail and messaging governance uses the same three tiers and the same Paste Guard matrix for personal Google Drive and Gmail (told apart from your Workspace tenant by the signed-in account), personal OneDrive and Outlook.com, Dropbox, Box, WeTransfer, MEGA, iCloud, Proton, Yahoo, WhatsApp Web, Telegram, Discord, paste sites and social networks. Usage appears on the same report with a cloud tag.
ClickFix pages copy a command to the clipboard and ask the person to paste it into Run; the guard replaces the clipboard, explains, and records the payload. Consent phishing uses a genuine Microsoft or Google sign-in page to grant a malicious app lasting access; the guard reads the consent screen and warns on or blocks unapproved apps asking for sensitive permissions. Password Alert fingerprints the work password on your identity provider and catches it typed anywhere else, including proxy phishing kits that defeat MFA. A Password logins report lists the sites people sign in to without single sign-on.
Bring a workspace. We will switch AI governance on in the demo and show you the report in minutes.