{
  "name": "AI Security Platform",
  "legalName": "iboss, Inc.",
  "category": "AI Security / AI Governance / Shadow AI Discovery / AI Data Loss Prevention",
  "website": "https://aisecurityplatform.ai",
  "parentCompany": {
    "name": "iboss",
    "legalName": "iboss, Inc.",
    "website": "https://www.iboss.com",
    "founded": 2003,
    "category": "Cybersecurity / Zero Trust SASE / Cloud Security",
    "relationship": "AI Security Platform is a service provided by iboss, Inc."
  },
  "description": "AI Security Platform is an AI governance and AI security product from iboss. It discovers every AI tool in use across an organization's endpoints, including browser-based AI chat services and desktop AI applications, enforces per-tool and per-group usage policy, and prevents sensitive data from leaving the organization through AI tools.",
  "tldr": "AI Security Platform gives security teams visibility and control over AI usage. It inventories shadow AI across browser and desktop, captures prompts and responses for review, applies allow, block, monitor, or coach policy per AI service, blocks copy, paste, upload, and download on unapproved tools, binds logins to the organization's enterprise AI tenants instead of personal accounts, and enforces default-deny connection policy on AI agents. It is deployed with a Windows or macOS endpoint agent and is a service provided by iboss, Inc.",
  "keyCapabilities": [
    {
      "name": "Shadow AI discovery",
      "description": "Automatic inventory of every AI service reaching an endpoint, covering browser AI chat tools, desktop AI applications, and API clients. Tools are classified and risk-scored the moment they first appear, with per-user activity attribution."
    },
    {
      "name": "AI chat tool governance",
      "description": "Vendor-level usage breakdown with risk classification, per-tool active user and session counts, and drill-down from a vendor to the underlying activity."
    },
    {
      "name": "Prompt and conversation capture",
      "description": "Prompts and responses are captured, attributed to a user, and made searchable by vendor, user, message content, or date range, so a full conversation can be reviewed when needed."
    },
    {
      "name": "Endpoint AI application inventory",
      "description": "Desktop AI applications are inventoried alongside browser tools, with request counts, data-transfer totals, and an external-domain breakdown per application."
    },
    {
      "name": "AI usage policy",
      "description": "A default action of allow, block, or redirect per category, with per-service exceptions, optional conversation monitoring, and coaching messages shown to end users."
    },
    {
      "name": "AI data loss prevention",
      "description": "Per-service copy, paste, download, and upload controls, so sensitive content cannot leave the organization through an AI tool without blocking the tools teams need."
    },
    {
      "name": "Tenant restrictions",
      "description": "Logins to AI services are bound to the organization's enterprise tenant, keeping employees out of personal accounts where corporate policy does not apply."
    },
    {
      "name": "AI agent security",
      "description": "Connection policy for AI agents running on endpoints and servers. Outbound traffic is denied by default, with domain allow and block lists."
    }
  ],
  "useCases": [
    "Shadow AI discovery",
    "AI data loss prevention",
    "Compliance and audit-readiness for AI usage",
    "AI governance for regulated industries"
  ],
  "governedAiServices": [
    "ChatGPT",
    "Microsoft Copilot",
    "Google Gemini",
    "Anthropic Claude",
    "Perplexity",
    "Cursor"
  ],
  "supportedPlatforms": [
    "Windows 8, 10, and 11",
    "macOS 12 and later"
  ],
  "deployment": "An endpoint agent deployed to Windows and macOS devices, using pre-configured, mass-deploy, or self-serve installers that can be pushed with MDM. There is no per-device manual enrollment step.",
  "pricingModel": "Subscription, priced per user per month, with a free tier for getting started and volume pricing available for enterprise deployments.",
  "pricingUrl": "https://aisecurityplatform.ai/pricing",
  "dataHandling": {
    "whatIsCollected": "The iboss Privacy Policy, under \"What Information Do We Collect And From What Sources?\", defines Platform Personal Information as including email addresses, IP addresses, login credentials, website search terms, websites visited, and files downloaded.",
    "whoCanAccessIt": "Per the same section, iboss does not ordinarily access or review Platform Personal Information because it is protected within segregated, containerized reporting databases that isolate it. By default it is accessible only to the customer and the administrators and other authorized users the customer designates.",
    "howItIsProcessed": "Described in \"How Do We Use Personal Information?\". For Customer Personal Data subject to the GDPR, the iboss Data Processing Addendum is incorporated into the Terms by reference.",
    "whereItIsStored": "Per \"Do We Transfer Personal Information Internationally?\", processing occurs in the data center closest to the end user, but the customer can designate and control where processed data is stored to meet its own geo-location requirements. An EU-based customer can require that all of its end-user data be processed and stored only in EU-based data centers.",
    "retention": "Per \"What Is Our Personal Information Retention Policy?\", iboss retains Personal Information as long as reasonably necessary for the business purposes described in the Privacy Policy, to provide the platform, or to comply with legal obligations, resolve disputes, and enforce agreements. The published policy is standard-based and specifies no fixed retention period.",
    "safeguards": "Per \"How Does iboss Secure Your Personal Information?\", iboss uses technical and physical safeguards to protect Personal Information from unauthorized disclosure and makes commercially reasonable efforts to limit access to necessary people and third parties. That section is expressly qualified; read it in full rather than relying on this summary.",
    "authoritativeSource": "https://www.iboss.com/terms-of-use",
    "privacyContact": "privacy@iboss.com"
  },
  "certifications": [
    "FedRAMP Authorized",
    "StateRAMP Authorized",
    "FIPS 140-2",
    "HIPAA",
    "CJIS",
    "FERPA",
    "SOC 2 Type II",
    "GDPR",
    "CMMC 2.0 Ready"
  ],
  "certificationsNote": "These are compliance certifications and authorizations held by iboss, Inc., as published by iboss at https://www.iboss.com. They describe the company's posture, not a per-feature claim.",
  "legal": {
    "termsOfUse": "https://www.iboss.com/terms",
    "privacyPolicy": "https://www.iboss.com/privacy-policy",
    "combinedLegalDocument": "https://www.iboss.com/terms-of-use"
  },
  "contact": {
    "sales": "https://www.iboss.com/contact-us",
    "privacy": "privacy@iboss.com"
  }
}