SentriKat is live, launch pricing and hands-on onboarding for founding customers. Get started
All articles

AI-DLP for SentriKat: stop secrets leaking into ChatGPT, Copilot and Claude

SentriKat now offers an optional AI-DLP endpoint layer, powered by our open-source Contextia engine. Here's what it is, why it matters, and how to turn it on.

Denis Sota · · 4 min read

Your team already pastes code, logs and config into AI assistants every day. Most of the time that’s fine. The problem is the times it isn’t, an API key in a stack trace, a customer’s personal data in a “help me summarise this” prompt, a database URL with the password still in it. Once it’s in the assistant, it’s gone.

Today we’re making that a solved problem inside SentriKat: an optional AI-DLP endpoint layer, powered by our open-source engine Contextia.

First, the honest framing

This isn’t a partnership announcement. Contextia is our own project, MIT-licensed, open-source, built by the same team behind SentriKat. We’re now packaging it as a managed add-on for teams that want it deployed and governed centrally, the same way we offer the Compliance Pack.

So there are two things with two jobs:

  • Contextia, the open, on-device engine that catches secrets and PII before a prompt leaves the machine.
  • SentriKat, the platform that rolls it out across your org, applies one policy everywhere, and gives you the audit trail.

What it actually does

AI-DLP sits at the endpoint, in front of the AI assistants your people already use, ChatGPT, Microsoft Copilot, Claude, and the like. When someone is about to send a prompt, it detects sensitive content in-line and redacts or blocks it before it goes anywhere.

Three properties matter, and they’re deliberate:

  • On-device, zero-network by design. Detection runs locally. Prompt content is never shipped somewhere to be scanned. The whole point is to stop data leaving, so the tool that does it doesn’t get to leak it either.
  • Secret-free telemetry. SentriKat shows you aggregated signals, how many redactions, what kinds, on which teams, but a redaction event never contains the value it redacted. You can prove control without creating a new secret store to protect.
  • Open-source engine. Because the detection engine is Contextia and it’s public, you can audit exactly what runs on your endpoints. No black box on your most sensitive path.

Why this fits SentriKat (and NIS2 / DORA teams)

If you’re already using SentriKat, you’re managing vulnerabilities and producing compliance evidence. “Where does our sensitive data go when staff use AI tools?” is the next question your auditors, and your NIS2/DORA risk-management obligations, are going to ask. AI-DLP gives you a concrete, technical answer plus a searchable log, instead of a policy PDF nobody reads.

And it’s the same operational model you already know:

  • Central rollout, push the extension and proxy to every browser and machine from one console, not device by device.
  • One policy for everyone, set allow / redact / block rules once; they apply org-wide.
  • Audit trail, a searchable record of every secret caught, ready for security reviews.

How to turn it on

AI-DLP is an optional add-on, off by default. There’s no upgrade nag and no lock icons in the product, if you don’t have it, it simply isn’t there.

To enable it, head to your customer portal and use the Activate AI-DLP (Contextia) control, or ask us at [email protected]. We activate it on your license; the platform then starts pushing Contextia’s policy to your endpoints. You can turn it off the same way.

There’s no checkout form and nothing to buy on the marketing site, activation lives in the portal, tied to your account.

Want the engine, not the platform?

Contextia is and stays open-source. If you just want the on-device engine for yourself, grab it at contextia.dev, no SentriKat required. The add-on is for teams that want it deployed, policed and audited across the whole org from one place.

Learn more on the AI-DLP page, or read how the rest of SentriKat fits together in the docs.

Ready to automate your vulnerability management?

Deploy SentriKat on-premises in minutes. Track CISA KEV vulnerabilities, generate NIS2 compliance reports, and protect your infrastructure.

Request a Demo