Skip to main content
DSX Digital
DSX Guard

Control every
AI interaction.

Secure, govern and connect AI across your enterprise — from employees using ChatGPT, Claude and Gemini to applications reaching models through APIs.

One control layer for every path to AI: DSX Guard protects sensitive data before it reaches the model, enforces enterprise policy on every request, gives AI governed access to internal systems, and centralises application-to-LLM traffic through a single secure gateway — with central visibility and an auditable record of what happened.

Employees Applications Agents Models Enterprise Data
The control layer

One control layer for every path to AI.

Employees reaching AI applications, enterprise applications calling models through APIs, internal AI applications and AI agents all take different routes to the same models. DSX Guard governs every one of them from one place, across multiple AI and model providers, with one policy set and one audit trail. For the category this sits in, see what enterprise AI governance means in practice.

Protect

Mask or block sensitive values, inspect attached files, and detect threats before anything leaves your perimeter.

Reversible masking File and attachment scanning Prompt-injection detection

Govern

Apply organisational policy to every request, record what happened — including which AI tools employees actually use — and stream the evidence into the tools your security team already uses.

Central policy enforcement Full audit and activity logs SIEM and DLP integration

Connect

Give AI governed access to the systems that hold the answer — through managed agents and connectors, never through pasted credentials.

Enterprise AI agents Managed data connectors Permission-aware access

One security and governance layer across human-to-AI and application-to-AI interactions.

Workforce AI

Protect AI directly in the browser.

Employees keep using the AI tools they already know. DSX Guard inspects every interaction before it reaches the model — no new application to learn, no workflow to change.

No workflow change
Employees work in the same tabs, with the same assistants.
Files inspected too
Attachments are scanned before upload, not audited afterwards.
One extension, every assistant
Coverage for ChatGPT, Claude, Gemini and other browser-based tools.
chat.openai.com DSX Guard
Employee writes a prompt
Prompt & file inspection
Policy decision
ALLOW MASK BLOCK
AI model
Protection happens before sensitive data reaches the AI model.
Managed deployment

Deploy once. Protect every managed device.

Install the DSX Guard agent on the devices your organisation chooses to protect. From then on, the Guard admin console centrally deploys and manages the browser extension across Chrome and Microsoft Edge — without requiring employees to install, configure or maintain anything.

Central deployment

Devices with the DSX Guard agent are automatically brought under protection and managed from the central console.

Policy-protected extension

Employees cannot disable or remove the extension through normal browser controls. Organisational policies keep protection active across managed devices.

Tamper visibility

Administrators are alerted if protection is interrupted, removed outside policy or otherwise falls out of compliance.

Central updates

Extension versions are updated centrally, keeping every protected device on the approved release without employee action.

Centrally deployed. Policy protected. Always on.

Chrome Microsoft Edge Agent-based deployment Policy enforcement Tamper alerts Central version management
Reversible masking

Protect the data. Preserve the workflow.

Sensitive values are replaced before the request leaves the browser and restored when the answer comes back. The employee never sees the difference. Why blocking public AI fails sets out the reasoning behind this model.

1 · Employee types
Summarise the attached agreement for John Smith, record 384827 and reference 879234.
3 sensitive values detected
2 · DSX Guard masks
Summarise the attached agreement for [PERSON_01], record [RECORD_01] and reference [REFERENCE_01].
Mapping held inside your tenant
3 · AI receives
Masked values only. The model reasons over placeholders and returns its answer — DSX Guard restores the real values on the way back to the employee.
Answer delivered in full
Provider never sees the originals

The employee gets the answer. The AI provider never gets the sensitive data.

Computation-aware restoration

Masking that survives arithmetic.

Substitution alone breaks the moment a question operates on the values — a model cannot total two amounts it never saw. Guard handles this by letting the model express the operation over the placeholders. The arithmetic is then evaluated against the real values inside your tenant, and the result is placed into the answer.

Employee asks
What do these two invoices come to together?
Model returns
[AMOUNT_01] + [AMOUNT_02]
Guard resolves, in your tenant
The real figures are added locally and the total is written into the answer.

The employee reads a complete, correct answer. The provider never held a single underlying value.

Your definitions

Your data. Your definitions. Your policies.

Sensitivity does not mean the same thing in a bank, a hospital and a software company. Define it for your organisation, then decide what happens when it appears.

Personal data

Names, national identifiers, email addresses, phone numbers.

Financial data

IBANs, account numbers, card and payment information.

Business-critical data

Customer IDs, contract numbers, pricing, internal codes.

Technical secrets

API keys, credentials, tokens, source-code patterns.

Custom sensitive data

Organisation-specific patterns, dictionaries and rules.

For each category, choose what DSX Guard does: Mask Block Allow Log only
Threat protection

Stop unsafe AI interactions before they happen.

Prompts and files are analysed on every request — not sampled after the fact, and not left to the model provider to police.

Prompt injection Jailbreak attempts Data exfiltration Malicious instructions Suspicious content Policy violations

Detect

Every prompt and attached file is analysed against known attack patterns and your own content rules.

Evaluate policy

Findings are scored against the rules your organisation set — by user, group, application and data category.

Allow · Block · Log

The request proceeds, is stopped, or is recorded for review — and the event reaches your SIEM either way.

Enterprise agents

Bring enterprise data into the AI tools employees already use.

DSX Guard adds governed enterprise agents directly into the assistant the employee already has open. The agent reaches your systems under enterprise permissions — the employee just asks the question.

Employees don't need another AI application. Enterprise capability comes to the AI they already use.

Example · DSX IQ as an agent

Register DSX IQ in Guard and your document archive becomes one of those agents. An employee asks a question in ChatGPT; Guard masks what policy requires, routes the question to IQ, and returns an answer drawn from your corpus with the document, page and passage attached. Every exchange is inspected and logged like any other.

Claude · DSX Guard Agent: Customer Risk
Show ABC Corp's current exposure, payment history and last six months' transaction volume.
Connecting securely
CRM Oracle Data Warehouse
DSX Guard agent response
Exposure
$2.4M
Payments
On time
6-mo volume
+18%
Access resolved against enterprise permissions — the agent returns only what this user may see.
Connectors

Connect AI securely to enterprise data.

Agents reach real systems through managed connectors — never through credentials pasted into a prompt.

Oracle SQL Server PostgreSQL Salesforce SharePoint Google Drive REST APIs Internal systems

Give agents the data they need — under enterprise-defined permissions and policy, with every access recorded.

Application AI

Secure application-to-AI traffic.

DSX Guard is also the central gateway for every application in your estate that calls an LLM — one endpoint instead of a provider SDK in each service.

Applications
Customer portal
CRM
Internal copilot
Business application
DSX GUARD
AI Gateway
Data protection Threat inspection Model routing Audit & usage
Models
OpenAI
Anthropic
Google Gemini
Private LLM
One endpoint. Multiple models. Central control.
Provider management API key management Model routing Data protection Threat inspection Audit Usage tracking Central policies

One integration

Applications target a single endpoint instead of a different provider SDK in every service.

Swap models without redeploying

Routing is configuration, not code — move traffic between providers centrally.

Keys never leave the platform

Provider credentials stay in DSX Guard instead of being copied into each application.

One policy layer

Both paths. One rule set.

Everything above converges here: whether a person or a service is talking to the model, it meets the same evaluation and leaves the same trail.

Workforce AI
Employee
Browser
AI
Same control layer
DSX Guard
Every request, from either side, evaluated against the same policy set.
Application AI
Application
API
AI
Shared foundation
Data policies Threat protection Access control Masking Audit Logging SIEM / DLP

Human-to-AI and app-to-AI. Governed together.

Administration

One console for the whole control layer.

Policy, infrastructure, agents and evidence in one place — not spread across six separate tools.

guard.dsxdigital.com/admin
Protection
Browser extensionManaged devicesDeployment statusPolicy complianceTamper alertsVersion management
Data protection
Data maskingSensitive data typesThreat protection
Infrastructure
ProvidersAI gatewayAPI keysPlayground
AI agents
AgentsConnectorsData sources
Monitoring
ActivitySecurity eventsAudit logsAnalytics
Integrations
SIEMDLPAPI & webhooks
Administration
UsersGroupsBillingSettings
Industries

For organisations where data matters.

Financial services

Protect customer, account and transaction information.

Insurance

Protect policyholder and claims data.

Legal

Protect confidential and privileged information.

Healthcare

Protect sensitive health and operational information.

Technology

Protect source code, credentials and intellectual property.

FAQ

Questions about AI security and governance.

Does this block employees from using AI?

Only where your policy says so. Blocking, warning, masking and allowing are all outcomes, evaluated per user, per assistant and per data class. Masking is the default posture because it is the one employees do not route around.

Does the AI provider still see the prompt?

It sees the structure of the task with placeholders where sensitive values were, which is what makes the answer useful. The values themselves never leave, and they are restored only inside your tenant.

Does masking break answers that need the real numbers?

No. Where a question operates on masked values — totalling two amounts, comparing two dates — the model returns the operation over the placeholders and Guard evaluates it against the real values inside your tenant, then writes the result into the answer.

Is this the same as our DLP?

It is the AI-path extension of it. Traditional DLP was built for email, endpoints and file transfer; browser AI prompts and application-to-model API calls are channels it does not see. Guard covers those and streams its events into the DLP and SIEM tooling you already operate.

What about applications and agents, not just people?

Applications call models through a gateway that holds the provider keys centrally instead of each service carrying its own, under the same policy set and one audit trail. Agents connecting to enterprise systems run under the same controls, with human review where policy requires it.

Which assistants and providers are covered?

Browser protection covers the major AI assistants employees already use, and the gateway routes application traffic across providers with central key management, so provider choice stays a configuration decision rather than a rebuild.

What does an auditor actually get?

Who asked what, which assistant or application it went to, which data classes were masked, which policy applied and what the outcome was — recorded in a form that can be read without an engineer and streamed to your SIEM.

How is it priced?

A shared platform base plus a per-protected-user rate that steps down with volume. Applications calling models through the gateway are priced per application by traffic volume, quoted with your numbers. Every capability is included — there are no feature tiers.

AI is everywhere. Control it from one place.

Protect employees. Secure applications. Connect enterprise data. Govern every AI interaction from a single control layer.