Every figure comes from the organisation's own gateways, which inspect AI traffic on each user's machine. Gateways send only counts — never prompts, files or the values they protected.
Activity and exposure
Bars: AI requests per day across the organisation. Line: sensitive items that would otherwise have reached a provider.
Protected, by data class
tokennever sent
Obligations touched
Top categories
| category | token | never sent | frameworks |
|---|
Usage
Licence -
Never restricted by any licence state: .
Evidence for auditors
Who proposed and approved every rule, every signed rule set published, fleet coverage and audit anchoring, the licence. Counts and metadata only.
Each gateway also produces its own pack, with its hash-chained audit log and latest proof run: vguard evidence export, vguard prove.
Plans
| plan | list price | seats | includes |
|---|
Gateways
One row per enrolled installation. A gateway keeps protecting when it cannot reach this console or when a licence lapses.
| user | host | version | policy | last seen | AI clients | audit seq | requests | protected |
|---|
Rules the organisation defines centrally. A rule is proposed, then approved by a different person (four eyes), then published as a feed signed with the organisation key on an administrator's machine (vguard org publish). Gateways verify that signature, so this console cannot alter rules on its own.
Propose a rule
Catalogue
| rule | kind | sensitivity | status | proposed |
|---|
A gateway joins this organisation with a one-time enrolment token, the organisation salt and the organisation public key. Create the bundle on an administrator's machine so the salt never touches this console: vguard org bundle --control URL --admin-token ... --salt-file org.salt --public-key org.pub. Then on each machine: vguard org join BUNDLE --user alice@example.com.
Create an enrolment token
The token is shown once. Anyone holding it can enrol a gateway until it expires or is used up.
Who did what
| time | actor | action | detail |
|---|