NEW RESEARCH: Your Sandbox Is Made of Glass

Read

Trinitite

PricingResearchBlogPodcasts

Universal AI Governance

Govern every AI your company uses — set up in an afternoon, nothing to install.

Your people already paste customer records and source code into ChatGPT. Trinitite now governs every AI surface they touch — browser, desktop, and the AI inside your tools, not just your agents — and stops the sensitive prompt before it leaves. No endpoint agent. No browser extension. One policy, every path.

icap · inline · REQMOD

GOVERNING

prompt → api.openai.com

BLOCKED

credentials · pii.ssn · before it left

chatgpt.com · response

correct · rewritten

claude.ai · prompt

mask · pii.email

gemini · response

correct · rewritten

content stored

hash only

You don’t need an agent on every laptop to stop it. You need to govern the traffic.

Governing AI used to mean reading logs after the fact, or wiring a proxy in front of your own agents — which left every employee’s browser ChatGPT a blind spot. By reading AI input and output in real time at the gateway, the same Guardian + DLP brain now covers the surfaces you could never reach, with nothing installed and the cleartext never stored.

Two ways to connect

Bring your own gateway, or use ours.

Enterprise

Bring your own gateway

Already run Zscaler, Cisco, Netskope, Symantec, or Squid? You are minutes away. One line of config on the gateway forwards AI-bound traffic to Trinitite for a verdict — the gateway you already trust does the decryption, we never touch the rest of your web traffic.

Zscaler · Cisco · Netskope · Symantec · Squid (ICAP, RFC 3507)

Mid-market & startups

Use the Trinitite gateway

No enterprise web gateway, and not ready to buy one? Point your AI traffic at the Trinitite-hosted AI gateway instead. It governs AI only — not your whole web estate — so you get inline DLP for ChatGPT, Claude, and Gemini without a six-figure SWG project.

Hosted by Trinitite · AI traffic only · no endpoint install

How it works

Scope it, connect it, govern it.

Connect a gateway

1

Name it

2

Copy the key

3

Go live

Connector name

One connector per gateway. We mint a one-time secret next.

01

Scope it to AI only

Point inspection at the AI destinations — chatgpt.com, *.openai.com, *.anthropic.com, claude.ai, Gemini. Your whole web estate is untouched, so the footprint stays narrow and the liability stays defensible.

02

Connect in one line

Mint a connector, copy the one-time secret, and paste it into your gateway. That is the setup — no agent on a single laptop, no browser extension to break on the next update.

03

Get a verdict in milliseconds

Trinitite reads the actual prompt and reply, runs your policy, and answers pass, correct, mask, or block — inline, before the data leaves your trust boundary.

04

Correct, mask, or block before it leaves

A blocked prompt never reaches the provider. A masked one continues with sensitive values reversibly tokenized. A corrected response is rewritten in place — the Guardian fixes the problem and the work keeps running instead of failing. You allow AI and govern the inputs.

05

Keep a signed trail, no cleartext

Every decision is recorded — vendor, category, severity, verdict, timestamp — while storing only a hash of the content, never the content itself. Your evidence trail does not become your next breach.

Every decision, signed

A pass, correct, mask, or block on every prompt — proven, not promised.

Trinitite recognizes the major providers’ request and response formats, extracts the real prompt and reply, and scans them against your policy. Clean traffic passes untouched. Sensitive values are masked out and the cleaned prompt continues. Policy violations are blocked with a clear message — and never reach the provider.

And for the near-misses that another DLP would just block, the Guardian corrects the response in place — rewriting it so the work keeps running. Every row is recorded with only a hash of the content, so your audit trail proves what happened without becoming a new data-retention liability.

Inline AI Governance · live

no cleartext stored

What you get

Allow AI. Govern the inputs.

Govern any AI, not just agents

Browser ChatGPT, desktop Claude, Gemini, AI baked into the tools your team already uses — all governed by one policy. The same brain that governs your API traffic governs the browser too.

Nothing to install on endpoints

No per-device agent, no extension to disable. If the traffic flows through the gateway, it is governed — browser-agnostic and OS-agnostic by construction.

Stop exposure before it happens

A blocked request is stopped before it reaches the provider — not flagged after the data is already in a third party’s context window. Prevention, not a post-mortem.

Fails open, never an outage

If governance can’t run end-to-end, traffic is allowed and the row is marked "audited, not enforced." A misconfiguration degrades to observation — it never blocks all your AI.

Four verdicts, not two

Most AI DLP can block. We correct.

A generic web DLP sees an opaque HTTPS POST and can only allow or block. Trinitite reads the actual prompt and reply, so it can do what a firewall cannot — rewrite a problematic response in place, mask the sensitive values out of a prompt, or pass the clean call through. One verdict vocabulary across every surface, on every decision.

pass

Clean traffic, or nothing extractable to scan. It flows through untouched, with a signed receipt.

correct

The differentiator. A problematic prompt or response is rewritten in place — the Guardian fixes the issue and the work keeps running instead of failing. Most DLP can only block; we correct.

mask

Sensitive values are reversibly tokenized out of the prompt, and the cleaned version continues to the provider. The same reversible masking that governs your API traffic.

block

A policy violation is stopped with a clear message and never reaches the provider (REQMOD) or the user (RESPMOD). Every block is recorded and replayable.

In your language

One control, every buyer’s problem.

CISO

Coverage for the hardest blind spot — consumer AI in the browser — with no fragile endpoint agent to defend in procurement, and a signed record of every block.

CFO

Allow the productivity of AI while capping the downside. One control across browser, desktop, and API instead of a tool per surface.

General Counsel

Sensitive data is stopped before it crosses the trust boundary, and the audit trail proves it — without retaining the cleartext that becomes its own liability.

Compliance & Privacy

Inline enforcement evidence (EU AI Act, GDPR, SR 11-7, SOC 2) backed by a signed, queryable trail — with optional human-in-the-loop on your highest-stakes categories.

The detection counterpart is Shadow AI Inventory; the content-level controls live in reversible masking; the same brain governs your programmatic traffic in MCP governance; the audit substrate is the audit platform.

FAQ

Universal AI governance, answered

What is universal AI governance?

Universal AI governance means governing every place generative AI shows up in your company — not just your AI agents. By ingesting real-time AI input and output through a Secure Web Gateway (or the Trinitite-hosted gateway), Trinitite inspects the actual prompts and replies flowing to ChatGPT, Claude, and Gemini and returns a pass, correct, mask, or block verdict inline — covering browser, desktop, and API with one policy and nothing installed on endpoints.

Do I need to install anything on employee devices?

No. There is no endpoint agent and no browser extension. Inspection happens at the gateway your traffic already flows through, so it works across every browser and desktop app regardless of operating system. Browser extensions break on every update and are trivial to disable — this approach has neither failure mode.

What if we don’t have a Zscaler or Netskope?

Then use the Trinitite-hosted AI gateway. It is built for mid-market teams and startups that don’t run an enterprise Secure Web Gateway: it governs AI traffic only — not your whole web estate — so you get inline DLP for ChatGPT, Claude, and Gemini without a large gateway project. Enterprises with an existing gateway connect over ICAP instead; both paths use the identical governance brain.

What does “correct” mean — and how is it different from blocking?

Most AI DLP can only allow or block. When a prompt or response trips a policy, Trinitite can instead correct it — the Guardian rewrites the message in place to fix the problem (strip the confidential strategy described in prose, remove an ungrounded claim from a response) and the cleaned version continues, so the work keeps running instead of failing. Masking reversibly tokenizes sensitive values; correction rewrites the content itself. Block is reserved for genuine policy violations. The same four-valued verdict — pass, correct, mask, block — runs on every surface.

Do you store our prompts?

No, by default. The audit record keeps a cryptographic hash of the scanned text plus the finding metadata — never the cleartext. Regulated teams that must retain the full record can opt into an encrypted full-content store with per-record keys, readable only through an access-audited API. The platform default stays no-cleartext.

How is this different from Shadow AI Inventory?

They are the detect and enforce halves of the same problem. Shadow AI Inventory reads the telemetry your gateway already exports to detect unsanctioned AI use, read-only. Universal AI Governance sits inline to enforce — pass, correct, mask, or block before the data leaves. Most teams start with detection and turn on enforcement once they trust the verdicts.

Govern every AI your company uses — starting this week.

Connect the gateway you already run, or use the Trinitite-hosted AI gateway. Start in audit mode, turn on masking and correction, then block your highest-risk categories — each step adds protection independently.