PROTECT AI PROMPTS

Keep sensitive data out of AI prompts

Your people need AI to work faster. Identra helps keep sensitive data within policy across browser prompts, file uploads, coding agents and desktop AI apps.

Sensitive data in promptsCOVERED
  1. Act before browser prompts leave
  2. Put boundaries on file uploads
  3. Keep work in company AI accounts
  4. Protect prompts to coding agents
  5. Extend protection to desktop composers
ONE IDENTITY · ONE TIMELINEBrowserEndpoint
01What goes wrong today

The risk is already in use.

What security teams run into with sensitive data in prompts today, before a control is in place.

  • 01

    A useful prompt exposes data

    An employee pastes a customer conversation into an AI chat. Names, account details and credentials can travel with the question.

  • 02

    Files carry more than context

    A document uploaded for a quick summary can contain confidential material beyond the section the employee meant to share.

  • 03

    The right app, wrong account

    Employees can use the same AI service for work and personal tasks. An approved app name alone does not tell you which account receives company data.

  • 04

    Code leaves through another window

    Developers bring source code and troubleshooting details into coding agents and desktop AI apps. Browser rules alone leave that workflow unaddressed.

02What Identra does

What changes with Identra.

Covered where the risk happens, tied to one identity and one timeline.

Identra Guard in the browserSee Identra in the browser
  • 01

    Act before browser prompts leave

    Identra Guard checks prompts before send for sensitive data such as card numbers, API keys and credentials. Policy can allow, alert, mask sensitive content with replace and send, or block the prompt.

  • 02

    Put boundaries on file uploads

    Inspect AI uploads, including sensitivity labels, and block uploads by policy. Clipboard controls and secret detection also address sensitive pastes.

  • 03

    Keep work in company AI accounts

    Allow, redirect to the company AI workspace, or block access by signed-in account for ChatGPT, Gemini, Claude, Perplexity and Grok. Apply account-aware AI access where people work.

Identra on macOS and WindowsSee Identra on the endpoint
  • 04

    Protect prompts to coding agents

    Prompts to Codex and Claude Code are checked on the device before they are sent. Active policy can block those prompts.

  • 05

    Extend protection to desktop composers

    Apply desktop composer data loss prevention with on-device checks through the Identra agent for macOS and Windows.

  • 06

    Give investigations a person and timeline

    Connect browser, endpoint and provider activity to one person and timeline, where the person is known. AI agent runs record the user, device, AI client and allowed or blocked outcome.

03Before and after

A support reply should not expose a customer's credentials

The same moment, played twice. Once without Identra, once with it.

WITHOUT IDENTRA

EXPOSED
  1. A support engineer opens ChatGPT while signed into a personal account.

  2. They paste a customer conversation containing an API key to draft a reply.

  3. They attach a document labeled confidential for extra context.

  4. They send the material without applying the company's data rules.

WITH IDENTRA

CONTAINED
  1. Identra Guard redirects the engineer to the company AI workspace under the account policy.

  2. The browser prompt is checked before send, and policy masks the API key with replace and send.

  3. Upload inspection checks the document's sensitivity label, and policy blocks the upload.

  4. The engineer continues with the masked prompt in the company workspace.

04How it works

Four steps. One timeline.

  1. 01

    See

    Discover the AI apps and accounts people use in the browser, alongside coding agents and desktop AI apps on their devices.

  2. 02

    Decide

    Set browser policy for signed-in accounts, sensitive prompts and file uploads, and activate prompt blocking for Codex and Claude Code.

  3. 03

    Protect

    Apply browser prompt and upload controls, with on-device prompt checks for coding agents and desktop composer DLP.

  4. 04

    Connect

    Bring browser and endpoint activity into one identity timeline, where the person is known, with recorded outcomes for AI agent runs.

QUESTIONS

What buyers ask us about sensitive data in prompts.

Does Identra send employee prompts away for inspection?

Prompt content stays on the device by default. Browser prompts are checked on the device before they are sent, and prompt checks for Codex and Claude Code also run on the device.

What do we deploy?

Identra Guard is a browser extension for Chrome, Edge, Firefox and Safari. The Identra endpoint agent supports macOS and Windows for coding-agent prompt checks and desktop composer DLP.

Does every sensitive browser prompt have to be blocked?

No. Browser policy can allow, alert, mask with replace and send, or block. You can choose the response that fits your data rules.

Can we control attachments as well as pasted text?

Yes. Identra Guard inspects file uploads to AI, including sensitivity labels, and can block uploads by policy. It also provides clipboard controls and secret detection in pastes.

How should we scope coverage across AI tools?

Evaluate coverage by workflow: browser prompt and upload protection, account controls for ChatGPT, Gemini, Claude, Perplexity and Grok, prompt checks for Codex and Claude Code, and desktop composer DLP. These are distinct controls, each with its own scope.

SEE IT IN YOUR ENVIRONMENT

See Identra handle sensitive data in prompts.

A walkthrough with a security engineer.