NewSnippets: tell the AI about you and your company once.See how New modelClaude Sonnet 5.5 is now available.Read more
GOVERN

One set of controls for everything AI in your company.

Admins decide which providers each team may use, where the workspace's data is stored, and what happens when someone pastes a card number or an API key into a prompt. The rules live in one place, in Workspace settings, and every time a guardrail fires it is written to the Privacy Log.

Sensitive info detection: choose surfaces and warn, redact or block per detector 1 Choose what is scanned 2 Warn, redact or block
The controls

What an admin actually gets to decide.

Nine settings that answer the questions Security, Legal and Finance ask before they say yes. All of them are in the app today, under Workspace.

Sensitive info detection
Built-in detectors for payment data, credentials, email addresses, phone numbers, IP addresses and government IDs. Each one set to Warn, Redact or Block.
Your own patterns
Add custom patterns as regular expressions, such as Northwind's order or employee numbers, and check them with Preview before they go live.
Scan surfaces
Choose what gets scanned: what people type, what tools return, and what the model writes back. Each surface switches on and off separately.
Model & provider access
Allow a provider, block it, or open it to specific teams only. Workspace admins can always use every model.
Data residency
Workspace data is stored in the EU by default. US hosting is available on request for Enterprise workspaces.
Inference constraints
Require EU-served inference endpoints, or allow only providers with zero data retention. The impact on your model catalog shows before you save.
Privacy Log (AI Act)
Every guardrail trigger and policy change, recorded as Warned, Redacted or Blocked. Filter by area and action, then export.
Roles and team owners
Owners and admins manage the workspace. Teams can have owners who approve prompts and control budgets; the rest are managed by admins.
Scoped connections
Databases connect read only, read and write, or with full access. CRM connections are read only until someone allows write access.

Guardrails, sensitive info detection, EU-only endpoints and the Privacy Log are included from the Business plan. Compare plans

GUARDRAILS

Warn, redact or block, per detector.

Sensitive info detection scans what people type, what tools return and what the model writes back. Card numbers and IBANs, credentials, email addresses, phone numbers, IP addresses and government IDs each get their own action, and your own patterns can be added as regular expressions. Watch it catch them as you type.

  • Choose which surfaces are scanned
  • Warn, redact or block for each detector
  • Every trigger recorded in the Privacy Log
WHAT THE MODEL SEES

The model gets placeholders.

With redaction on, the numbers never reach the provider. The model works with [payment_data] and [phone] in their place, and still writes a usable reply. A Northwind support agent can paste a customer's refund details and draft the email without the card number leaving the workspace.

  • Redaction happens before the request leaves
  • Replies stay useful without the raw values
  • Prompt injection detection is coming soon
A chat where card numbers and a phone number were redacted before the model saw them 1 What the user typed 2 What the model saw
MODEL & PROVIDER ACCESS

Decide who may use which provider.

Each provider gets one setting: Allow, Block, or Specific teams. Northwind can open every provider to Marketing for image work and keep Finance on a shorter list. Models blocked by your data residency settings are greyed out and cannot be used by anyone.

  • Allow, Block or Specific teams, per provider
  • Workspace admins can always use every model
  • Residency rules apply to the model list automatically
Model & provider access: allow, block or limit providers to specific teams 1 Every provider, one setting 2 Allow, block or teams
DATA RESIDENCY

Your data in the EU, by default.

New workspaces store chats, files and records in the European Union. From there you can tighten inference as well: require EU-served endpoints, or allow only providers that contractually keep no data. The impact on your model catalog updates live before you save, so nobody is surprised on Monday.

  • EU storage by default, US on request for Enterprise
  • Require EU-served inference endpoints
  • Zero data retention providers only, if you choose
EU AI Act resources
Data residency: EU storage by default, EU-served inference and zero-retention constraints 1 EU by default 2 EU endpoints only
PRIVACY LOG

A record you can hand over.

Every guardrail trigger and every change to your policies lands in the Privacy Log: what happened, which detector, which surface, when. When your DPO or an auditor asks how personal data is handled, you answer with the record and the settings behind it, not a promise.

  • Warned, Redacted and Blocked events
  • Policy changes recorded alongside triggers
  • Filter by area and action, then export
The privacy log (AI Act): every redaction and policy change, exportable 1 What happened, and when 2 Export the record
Why one workspace governs better than nine tools
  • A guardrail set once covers chats, prompts, agents and workflows in the workspace, not one tool at a time
  • One Privacy Log to filter and export, instead of an export per tool
  • IT decides on a provider or a region once, for every team
  • New capabilities arrive inside the controls you already set

ISO 9001: certified · ISO 27001: in progress · SOC 2: in progress. Certifications are held by LogiNet, the company behind StickyPrompts.

Trial
A $5 balance to start. No card needed.
Give IT the controls first

Set the guardrails first, then invite the team.

Choose your providers, your guardrails and where your data lives before anyone sends a prompt, then roll out team by team. Book a demo and we will walk your security team through Workspace settings.