Shadow-AI security

See what your team is about to paste into AI.

Blank finds the AI tools already in use across your company, catches secrets and customer data on the way out, and coaches people in the moment, without blocking the tools they rely on.

Deploys by MDM in minutes · only the finding leaves the browser

You · to an AI assistant

Here's the deploy script. The prod key is key-9f2a-4c81-7de0-prodAWS key so it can push to S3.

Careful, that looks like an AWS access key.

It's masked here. Nothing was sent. Remove it, or continue if it's a placeholder.

How it works

Discover, monitor, coach.

Three steps, in that order. You can't coach what you haven't measured, so every deployment starts by watching, and blocks nothing.

01 · Discover

Find the AI already in use

Blank surfaces the AI tools across your fleet, including ones no catalog has heard of yet. What it sends back is a hostname and a count, never a URL, never a keystroke.

Ships on the Free plan
02 · Monitor

Watch what's on the way out

It notices secrets and customer data heading into an AI tool and records the finding: the rule that fired, the severity, where. The matched text never leaves the browser.

Every deployment starts here
03 · Coach

A nudge, not a wall

When something genuinely sensitive is about to go out, a quiet in-page note. The person can remove it or say it's fine, one tap, and keep working in the tool they chose.

Unlocks after 14 days of monitoring
Privacy

Built to see less.

A tool that watches your team only earns that if it collects almost nothing. Blank is built so you can prove it does.

Only the finding leaves The matched secret stays in the browser. What reaches the dashboard is the rule that fired and where, never the text itself.
Only on AI pages A page that isn't an AI tool emits nothing at all, no event, no record it was even visited.
Scrubbed server-side Identity is stripped on the way out of the API, before it can reach a dashboard or an export. Pseudonymisation is on by default.
Nothing to forge The catalog that steers every device is signed offline. A compromised server can't push a rule to your fleet.
Pricing

Discovery is free. Forever.

Most companies can't name the AI tools running inside them right now. Finding out shouldn't cost anything, so it doesn't. Pay us later, if and when you want to act on what you find.

Free
$0 up to 100 seats

No card, no trial clock, no call with us first.

Discover the shadow AI already in use across your org.

  • Every AI tool in use, including the ones that aren't on anybody's list yet
  • Which browser extensions can read every page your team visits
  • Personal accounts vs. company accounts on the same tool
  • 30 days of history
  • One exportable report you can take to your next security review
Start free

Deploys by browser policy. About 3 minutes of admin work, then devices report in over the next few hours.

Team
$4 / seat / month

$400/month minimum

For when you know what's running and want people to stop pasting secrets into it.

  • Secrets, credentials and customer data caught in the browser
  • Monitor mode first, always. 14 days of real data before anything changes for your team
  • Coaching, not blocking. People get told what they're about to paste, and decide
  • Noisy detectors get switched off automatically, before your helpdesk hears about it
  • 12 months of history, and the evidence pack
Start free, upgrade later
Business
$6 / seat / month

Same price as Chrome Enterprise Premium. On purpose.

For when somebody else audits you, and "we have a policy" isn't the answer they want.

  • Everything in Team, plus enforcement: redaction and blocking
  • Your own detectors, for your own record formats
  • SSO, SCIM, role-based access, SIEM export
  • Pseudonymized mode, so this deploys where a works council has a say
  • Evidence pack mapped to SOC 2, ISO 27001, ISO 42001 and EU AI Act Article 4
Book 20 minutes

When you shouldn't buy Blank

If your whole company runs managed Chrome on Windows and you're happy inside Google's stack, buy Chrome Enterprise Premium instead. It's $6 a seat, it's built into the browser rather than bolted onto it, and for that setup it will serve you better than we will.

If you're already paying for Microsoft E5, you already own Purview. Turn it on before you buy anything else. It's good, and you've bought it.

Blank is for the messier situation. Macs and Windows. Chrome and Edge. Contractors on machines you don't fully control. No E5 license and no appetite for one. And for the part neither of those two does, which is handing you a dated, signed document when somebody asks what your company actually does about AI.

What this costs next to everything else

500 seats · annual · list prices, August 2026

OptionPer year
Blank Free (discovery only, capped at 100 seats)$0
Blank Team (discovery, detection, coaching, evidence pack)$24,000
Blank Business (adds enforcement, SSO, custom detectors)$36,000
Chrome Enterprise Premium (native to Chrome, Chrome only)$36,000
Microsoft Purview (Suite add-on over E3, free if you're on E5)~$72,000 est.
Netskope (full SSE platform, median reported contract)~$97,000 est.

We're not the cheapest and we're not trying to be. Blank Business costs exactly what Google charges, because at that point the question isn't price, it's whether the thing covers your actual fleet and gives you something to hand an auditor.

Early access, and what that's worth to you

Team and Business are live with a small number of design partners. If you join now you get us directly, not a support queue, your priorities go to the front of the roadmap, and your price is locked for a year. When we're wrong about something, you're the reason we find out.

FAQ

Questions teams ask.

What is shadow AI?

Shadow AI is employees using AI tools like ChatGPT, Claude, Gemini, and Copilot for work without IT's approval or visibility. The risk isn't the tools. It's the secrets, customer data, and source code people paste into them.

How do I stop employees from pasting secrets into ChatGPT?

Blank runs in the browser and inspects what's about to be sent to an AI tool. When it spots a credential, secret, or customer record, it coaches the person in the moment, or blocks the send if your policy requires it, without banning the tool.

Is there a DLP tool built for AI tools like ChatGPT?

Yes. Blank is browser-native data-loss prevention designed for AI. It catches sensitive data on the way into catalogued AI tools before it leaves the device, and only the finding is reported, never the content itself.

How does Blank find which AI tools my team is already using?

Blank runs on your managed browsers and matches activity against a catalog of known AI tools, while surfacing uncatalogued ones employees have started using. You get your real shadow-AI footprint, by tool and by device.

Does Blank block AI tools?

Not by default. Every deployment starts in monitor-and-coach mode. Blocking is an optional policy an admin turns on per detector or tool after 14 days of monitoring. It's a nudge, not a wall.

How is Blank deployed?

Blank is force-installed across your fleet through browser management (Chrome and Edge), with no per-user setup. It runs only on AI pages, and only the finding ever leaves the browser.

Get started

See your shadow AI this afternoon.