Govern AI access and tool use with PromptGuard
Multiple surveys have shown that the vast majority of users across industries have shared work-related information with public AI tools. This doesn’t mean that most people have malicious intent. More often than not, it’s because there isn’t an approved AI tool for company use or that the sanctioned tools aren’t doing a good enough job.
A lot of times the intention is to simply be more efficient. Work faster. Focus on tasks that require more nuance. Avoid bottlenecks. The added risk is a byproduct.
The efficiency gains across teams are undeniable. But so is the increased risk.
Oveka helps make sure teams can keep the benefits while reducing the risk vectors through the PromptGuard feature. PromptGuard checks for unapproved AI use and inspects prompts to make sure sensitive data isn’t being sent to unauthorized AI tools.
What does PromptGuard do?
PromptGuard is a holistic way to inspect traffic to LLMs and stop sensitive data from being sent to these tools.
A simple way to think of PromptGuard is as a protective layer sitting between the LLM interface and the data that is submitted to an LLM. Once a user enters a prompt and hits enter, Oveka inspects the prompt before the data is sent. It will then perform different actions depending on your configuration and what the prompt contains.
How PromptGuard works
PromptGuard can slot in at multiple different layers to catch traffic in different ways from different sources. Some examples include:
- On the browser to check for known LLM urls and inspect traffic and prompts going to any of those sites
- At the network level for entire company networks
- On the device level as an install-and-forget application
- Deployed via endpoint and mobile management tools
Once installed, PromptGuard can monitor for sensitive data being sent to AI. But it does more than just monitor the traffic. It can also surface anomalies. For example, if a device had previously visited ChatGPT every single day and that traffic suddenly stops, there’s a decent chance that the user is still visiting the site. PromptGuard will bring up these kinds of unusual behaviors so you can decide if they’re something worth investigating.
The goal is to both inform you about LLM usage in your environment while also providing pathways to fix them and ensure governed AI use across the organization.
How does PromptGuard ensure governed AI use?
Depending on your configuration, PromptGuard can do a few things when users interact with AI tools: Monitor LLM usage, redact sensitive data, stop prompts from being sent to LLMs, and/or prevent sensitive document uploads.
Monitoring LLM usage
Before you can decide how to handle LLM use in the organization, you have to know how it’s being used. PromptGuard finds how users are interacting with LLMs, which ones they’re using, and how often.
As mentioned above, PromptGuard does this by taking a holistic approach to monitoring LLM traffic. There are multiple places where you can insert PromptGuard depending on your needs and what level of control your organization requires. And the amount and depth of coverage can also be configured to suit your requirements.
For instance, at its maximum capabilities, Oveka can see every prompt sent by anyone in the organization as well as the response the LLM returned. Some organizations though, are uncomfortable with this level of surveillance, and simply want to see which tools are being used, without blocking any use at all. PromptGuard can do either level or somewhere in between.
The goal of Oveka is to help you get a clear picture of how AI is being used across teams so you can decide the best approach to help make sure AI is being used in line with company policies. And if it’s not, it provides some tools to help make that happen.
Redacting sensitive data
One approach to stopping AI from getting ahold of sensitive data while still allowing the tools to be used is by redacting the sensitive parts of the prompt. For instance, a prompt about “joe.bloggs@internet.com is having an issue adding a credit card 5555 5100 6540 4987 to his account. What’s a nice way to tell him his trial has expired?”
In this case, redacting the email address and credit card will still give a valid result, but the AI will never receive data about the specific customer. The user can still get the benefits of using the LLM to help solve the issue, but the identifying markers are removed and never sent to the AI tool,.
Stopping prompts from being sent to AI
By the time the prompt has been sent to the AI tool, it’s too late. Redacting or sanitizing the response to the user doesn’t stop the LLM from having the data.
PromptGuard can be configured to completely stop prompts from getting to AI. There are a few approaches you can take with this:
- Blocking access to tools completely. The user won’t even be able to access certain sites that you block.
- Completely stop prompts from being sent to specific tools. For example, if Microsoft Copilot is the only sanctioned tool, you can deny prompts from going to other providers such as Anthropic and OpenAI.
- Stop only sensitive data from being used in prompts. What counts as “sensitive” will depend on the content types you choose, such as PII and source code.
- Require manual override for certain content signatures. Oveka will pause the prompt for going through and require the user to confirm that they are fine sharing potentially sensitive data with the AI tool.
- Monitor prompts. Prompts will be transmitted freely but also be viewable by Oveka admins.
- See the AI tools only. You can set PromptGuard to surface the tools without viewing the prompts or responses.
Preventing sensitive document uploads
Sensitive information in the prompts themselves is only one way that sensitive data gets to AI tools. Other times the data can part of uploaded documents, and since the data isn’t submitted directly as lines of text, it takes a different approach to identify it.
When enabled, Oveka will check files that are uploaded to LLMs and only allow them through if there is no sensitive data found. Again, this depends on what you define as sensitive in the account so that only the data you don’t want sent is blocked.
Every action is logged
Once Oveka is installed, user actions can be logged at different levels. You can set parameters that range from a user visiting a specific site all the way to receiving a full transcript of LLM conversations, both the prompts and responses. You can also see what files have been uploaded and sent and which LLMs have them.
But Oveka go one step further and send notices based on common use cases. For example, a large CSV file that has 1000 email addresses might not set off any PII alarms. However, that amount of addresses is unusual, so there’s a chance that it’s a customer list. Oveka will log this as something worth investigating, and you can decide whether or not it applies to you and can upgrade or silence specific notification types.
Deploying PromptGuard
Features like PromptGuard work best when they’re accompanied by policy or training. Having users suddenly try to use the AI they’re used to and getting a “prompt blocked” message isn’t clear on its own. Without context, that might seem like just a generic error. And if the prompt doesn’t go through, the sensitive data that’s meant to be contained could just end up in a different AI.
We recommend using PromptGuard alongside a wider governance policy, such as documentation around acceptable and unacceptable AI use in the organization. It works best as part of a holistic approach to governance and security, using Radar to find sensitive data in SaaS platforms and Databridge to govern AI access to company data sets. These features are included in all plans.
For the deployment itself, Oveka is simple and straightforward to set up and configure. It is completely SaaS with no infrastructure and is ready in minutes. Simply choose where you want it deployed, what information you want to check for and associated actions, and add users. For more information or to get a demo, get in touch with us today.