Module 01 · Privalayer

Browser security

The browser is where your people actually meet your data — and where almost nothing is watching. Privalayer sees extensions, paste, upload and every unsanctioned AI tool in use, and it does the seeing on the device rather than in someone else's cloud.

/browser/data/destinations
Unsanctioned LLM · chat tool Source code · 41 events · 14 users Blocked
Personal cloud drive Customer records · 12 uploads Warned
Extension gained host access Silent auto-update · 380 devices Critical
Sanctioned vendor portal Contract PDFs · within policy Allowed
Analysed on device Only the finding record left the laptop
What it covers

Five surfaces, one console

Each area has its own primary action, because a list you cannot act on is a report, not a product.

Extensions

Every extension across the fleet, with a permission score and a behavioural verdict — remote code loading, obfuscation, observed exfiltration paths, publisher reputation change.

  • Inventory with install counts and first-seen dates
  • Version drift and silent auto-updates that changed permissions
  • Store watch for impersonators and ownership transfers

Primary action: set verdict — allow, warn, block, force-remove.

Data movement

Paste, upload, download, form fill and copy — each with its destination, data class and outcome. Grouped by receiving site, this is the view that changes the conversation.

  • Destinations ranked by volume and sensitivity mix
  • Classes: source code, credentials, PII, financial, health
  • Where policy actually intervened, and what the user did next

Primary action: create a policy straight from an event.

Shadow AI and SaaS

Unsanctioned LLM and agent tools discovered from real sessions — not from a static catalogue — with the users, the frequency and the data classes actually submitted.

  • A sanctioning queue, oldest first, so the list never rots
  • Adoption trend per tool, and displacement after a block
  • Non-AI SaaS discovery in the same shape

Primary action: sanction or restrict.

Devices and coverage

Enrolled devices, browser and extension versions, sidecar status — plus the number nobody else shows you: identities active in your IdP with no protected browser at all.

  • Coverage gaps — the honest denominator
  • BYOD, with what is enforced there and what is not
  • Sidecar health: model version, latency, fallback-to-rules rate

Primary action: send an enrolment link.

Policies

Live rules ordered by precedence with hit counts, templates by regulation and use case, and a full change history with diffs.

  • Simulation against the last 30 days before anything goes live
  • Who changed what, when, and exactly what changed
  • Starting points for GDPR, HIPAA, PCI DSS and DORA

Primary action: new policy.

The egress panel

Every screen in this module carries one persistent line: analysis ran on device or in your VPC, and only the finding record crossed the boundary.

  • Local-analysis attestation attached to each event
  • Redacted context — enough to triage, never the raw payload
  • Exportable to an auditor without a second data-flow review

Why it lives here: it is the differentiator, so it belongs in the product, not the deck.

Simulation

Nobody ships a block rule blind.

A rule that stops work is a rule that stops revenue if you get it wrong. Draft it, replay it against thirty days of real events, and read the exact list of what it would have blocked — by team, by destination, by person — before it touches anyone's workday.

  • Real history, not synthetic traffic. The simulation runs on your own captured events.
  • Blast-radius preview. See how many users and which teams a rule would have touched.
  • Warn before block. Ship it in warn mode, read the override reasons, then tighten.

Draft rule · block code paste to unsanctioned AI

30d replay
Would have blocked 41 events
Users affected 14 of 2,410
Teams affected Platform, Data
False-positive review 3 flagged
Safe to enable Warn mode suggested
On-device

Classification happens before the data moves.

The sidecar runs inside the browser. It reads the content of a paste or an upload, classifies it locally, and applies your policy at the moment of the action. The destination never receives what it should not have, and neither do we.

  • No proxy, no TLS interception. Nothing sits in the middle of your traffic to break.
  • Works off the corporate network. A laptop in a café is protected the same as one at a desk.
  • Degrades honestly. If local inference fails, it falls back to rules and reports the fallback rate.
How the sidecar is deployed

Sidecar health

fleet · 2,410 devices
Devices reporting 2,386
Median inference latency 38 ms
Classifier version v4.2.1
Fallback to rules 0.4%

See what your browsers are already doing.

Connect one device group and watch discovery run. Nothing is blocked until you decide it should be.

No credit card. No agent on the endpoint. Nothing leaves your network.