Enterprise AI Governance & Private LLM Guardrails
Secure developer and employee generative AI usage across Microsoft 365 Copilot, Copilot Studio, Azure OpenAI, and local LLMs without leaking sovereign citizen data. Custos Guard intercepts prompts in-flight, tokenizes national IDs, filters RAG context chunks, and neutralizes prompt injections with zero cloud egress.
Custos Guard™ Global LLM Interception Matrix & Healthcare PHI Enclave
Eliminate corporate and patient data leakage across cloud APIs, web portals, developer IDEs, and local open-weights engines. Custos Guard intercepts every prompt in-flight, stripping PII, healthcare PHI, and custom company secrets with < 2ms latency.
Frontier & Enterprise Cloud APIs
Full reverse-proxy protocol inspection supporting standard and streaming completions with deterministic redaction:
- • OpenAI: GPT-4o, GPT-4o-mini, o1, o1-mini, o3-mini
- • Anthropic: Claude 3.7 Sonnet, Claude 3.5 Sonnet, Claude 3.5 Haiku
- • Google Gemini: Gemini 2.0 Flash, Gemini 1.5 Pro, Gemini 1.5 Flash
- • DeepSeek: DeepSeek-V3, DeepSeek-R1 (API & Reasoning)
- • Others: xAI Grok-2/3, Mistral Large 2, Cohere Command R+, AWS Bedrock
Consumer & Web Chat Portals
Network gateway & egress proxy interception terminating unauthorized copy-paste of company confidential data into browser portals:
- • ChatGPT Web: chatgpt.com & chat.openai.com
- • Claude Web: claude.ai consumer & team workspaces
- • Google Gemini: gemini.google.com portal
- • Research Portals: Perplexity AI, Poe.com, HuggingChat, DeepSeek Chat
Developer AI IDEs & CLI Tools
Prevents proprietary codebase embedding poisoning, secret key leaks, and customer database dump exfiltration from developer tools:
- • Cursor AI: Full telemetry and prompt interception
- • GitHub Copilot: VS Code & Visual Studio extension inspection
- • Others: Windsurf (Codeium), Continue.dev, JetBrains AI Assistant, Supermaven
Open-Weights & Local Engines
Enforces prompt sanitation and prompt-shield guardrails even across internal on-premise GPU clusters:
- • Ollama: Port 11434 /api/generate and /api/chat interception
- • vLLM: Port 8000 OpenAI-compatible inference proxy
- • Others: LocalAI, LM Studio, Text-Generation-WebUI, Jan.ai
Enterprise AI Gateways & Routers
Inspects intermediate AI gateway layers to enforce corporate policy before multi-cloud routing:
- • LiteLLM Proxy: Central enterprise gateway enforcement
- • Cloudflare AI Gateway & Portkey AI: Edge routing guardrails
- • Martian Router & OpenRouter: Dynamic model arbitrage security
Browser In-Client & WebAssembly
Intercepts client-side in-browser WebAssembly models before unmanaged offline execution leaks local data:
- • WebLLM: In-browser WebGPU execution interception
- • ONNX Runtime Web: Client-side neural models
- • Transformers.js: In-browser HuggingFace inference inspection
Healthcare & Patient PHI Protection Engine
Hospitals, medical schemes, diagnostic labs, and healthcare providers can safely utilize frontier AI models without violating statutory patient privacy laws. Custos Guard intercepts and redacts:
Deterministic regex masking converting clinical record IDs to
[REDACTED_PATIENT_MRN].
Discovery Health, GEMS, Bonitas, Momentum, Medihelp, and Medicare masked to
[REDACTED_MEDICAL_AID_NO].
HPCSA, BHF, and US NPI clinician registration numbers scrubbed to
[REDACTED_CLINICIAN_PRACTICE_NO].
Clinical diagnostic codes (e.g. I21.9) and prescription dosages scrubbed to prevent medical re-identification.
Company-Defined Custom Sensitive Data Rules Engine
Every organization has proprietary secrets that standard DLP misses. Custos Guard empowers CISO teams to define, manage, and enforce custom classification rules with live testing in the web console:
- • Proprietary Project Codenames: Define secret initiatives (e.g.
PROJECT-VALKYRIE,PROJECT-TITAN) and redact them before external model ingestion. - • Secret Tokens & API Keys: Custom prefix matching (e.g.
custos_sec_...,acme_live_...) neutralizing leaked credentials from developer chats. - • Internal Account & Employee ID Schemes: Define regexes for internal employee numbers (
EMP-xxxxxx) or customer account schemas with custom redaction masks.
Turnkey 30-Day Sovereign Proof of Value (POV)
Tailored specifically for Chief Information Security Officers, Compliance Directors, and Data Architects across African AI Leaders & Enterprise Architecture.
Sovereign Risk & Statutory Compliance Audit
Key Deliverables to the Board of Directors:
- ✓ In-Place Sensitive Data Discovery: Full inventory of unencrypted citizen identifiers, tax numbers, and account records across designated Oracle, SQL Server, Postgres, or S3 stores.
- ✓ Board-Ready Statutory Audit Dossier: Complete readiness scorecards benchmarked against regional data sovereignty acts and central bank cybersecurity directives.
- ✓ ROT Storage Cost Reclaim Matrix: Immediate discovery of duplicate, stale, and orphaned database dumps, identifying 20%–40% reclaimable SAN capacity.
- ✓ 100% Conversion Credit: 100% of the ,000 POV fee is fully credited toward your annual enterprise subscription upon conversion.