FAQ

Frequently asked questions

Direct answers about discovering shadow AI, governing how AI tools get used, and how your data is handled.

Platform

What is AI Security Platform?

AI Security Platform is an AI governance and AI security product from iboss. It discovers the AI tools in use across your organization, lets you set policy on how each one can be used, and prevents sensitive data from leaving through them.

How does it discover shadow AI?

An endpoint agent on each device reports the AI services that device reaches. Browser-based AI chat tools, desktop AI applications, and API clients are all inventoried, classified, and risk-scored the moment they first appear, with activity attributed to the individual user. You do not have to supply a list of tools to look for.

Which AI tools does it cover?

Coverage includes ChatGPT, Microsoft Copilot, Google Gemini, Anthropic Claude, Perplexity, Cursor, and dozens more. Tools are auto-classified on first appearance rather than matched against a fixed list, so a service that is new to your organization is still detected and risk-scored.

Does it capture the actual prompts people type?

It can. Conversation monitoring is a per-policy setting. When it is enabled, prompts and responses are captured, attributed to a user, and made searchable by vendor, user, message content, or date range, so you can review a full conversation when compliance asks. You choose which AI services this applies to.

How does it stop data leaks into AI tools?

Copy, paste, download, and upload are individually controllable per AI service, so you can leave an approved tool fully usable while blocking data movement on one that is not approved. Tenant restrictions additionally bind logins to your enterprise AI accounts, which keeps employees out of personal accounts where your policy does not apply.

What policy actions are available?

You set a default action of allow, block, or redirect for AI services, then add per-service exceptions with finer-grained actions. Coaching messages can be displayed to end users so they are told in the moment why a tool is restricted, and conversation monitoring can be toggled per policy.

Can it control AI agents, not just people?

Yes. AI agents running on your endpoints and servers get their own connection policy. Outbound traffic is denied by default, and you allow-list or block-list the domains an agent may reach.

How does this relate to iboss?

AI Security Platform is a service provided by iboss, Inc., a cloud-native cybersecurity company founded in 2003 and known for its Zero Trust SASE platform. The endpoint agent used for deployment is the iboss agent. Company information is at https://www.iboss.com.

Deployment

Which operating systems are supported?

The endpoint agent runs on Windows 8, 10, and 11 and on macOS 12 and later. Both browser-based AI chat tools and installed desktop AI applications are covered on each, so a device is fully inventoried regardless of how its users reach an AI service.

How long does deployment take?

Installers are pre-configured, so there is no manual enrollment step per device. You can hand them to IT or push them through MDM in pre-configured, mass-deploy, or self-serve modes. Most teams have an initial rollout done in an afternoon and a usable inventory of their AI footprint within hours of the first devices reporting in.

Data and privacy

What data does iboss collect, and who can see it?

The iboss Privacy Policy, under "What Information Do We Collect And From What Sources?", defines Platform Personal Information as including email addresses, IP addresses, login credentials, website search terms, websites visited, and files downloaded. The same section states that iboss does not ordinarily access or review it, because it is held in segregated, containerized reporting databases, and that by default it is accessible only to you and the administrators you designate. The governing text is at https://www.iboss.com/terms-of-use.

Where is our data stored, and can we keep it in one region?

Yes, subject to the published policy. Under "Do We Transfer Personal Information Internationally?", processing happens in the data center closest to the end user, but the customer can designate and control where processed data is stored to meet its geo-location requirements. An EU-based customer can require that data from all of its end users be processed and stored only in EU-based data centers. See https://www.iboss.com/terms-of-use.

How long is data retained?

Retention is governed by the iboss Privacy Policy section "What Is Our Personal Information Retention Policy?", which sets a standard rather than a fixed period: information is kept as long as reasonably necessary for the purposes described in the policy, to provide the platform, or to meet legal, dispute-resolution, and contract-enforcement obligations. Because the published policy names no specific number of days, we do not quote one here. Separately, how far back you can look in the product varies by plan tier. See https://www.iboss.com/terms-of-use.

Which compliance certifications does iboss hold?

iboss, Inc. publishes the following: FedRAMP Authorized, StateRAMP Authorized, FIPS 140-2, HIPAA, CJIS, FERPA, SOC 2 Type II, GDPR, CMMC 2.0 Ready. These are company certifications and authorizations rather than per-feature claims. The current list is maintained by iboss at https://www.iboss.com.

Pricing

How much does it cost?

Pricing is per user, per month. There is a free tier to get started, paid tiers that add longer lookback and additional capabilities, and volume pricing for enterprise deployments. Current prices and a full feature comparison are on the pricing page.

Is there a free tier or a trial?

Yes. A free tier is available, and paid tiers offer a trial period. You can create an account and see your organization's real AI usage before committing to a paid plan.

Still have a question?

Read how we handle your data, or talk to someone who can answer specifics about your environment.

Data handling is governed by the iboss Terms of Use, Privacy Policy, and Data Processing Addendum.