Solutions / Shadow AI

Shadow AI

Find the AI tools your employees already use, stop sensitive data from leaving by accident, and govern the tools you approve. Endpoint Guard runs on Windows and macOS devices.

Discover AI appsLocal data protectionApp and device policy
Why Cortega

The problem

Employees adopt AI tools faster than IT can approve or configure them. Some of that use sends company data to a provider nobody vetted, and without a way to see it, there is no way to tell which. Endpoint Guard brings that use into view and under policy.

Today

Employees use AI tools nobody approved

  1. Employee deviceDesktop app · browser assistant · local MCP tool
  2. Customer recordsSource codeCredentials
  3. AI provider nobody vettedOutside every control
  4. IT cannot see which AI tools are in use
  5. Company data reaches providers no one reviewed
  6. No policy, budget, or record applies
  7. Gateway controls never see this traffic
With Cortega

Policy runs on the device itself

  1. Employee deviceEndpoint Guard native agent · Windows and macOS
  2. App policy and local guardrailsObserve · Police · Block
  3. Original destinationAllowed traffic, unmodified
    Cortega consoleFindings and device records
  4. Every AI app in use is discovered
  5. Sensitive data is masked or rejected locally
  6. Unapproved apps are blocked
  7. Assistants route through your gateway with budgets
Why Cortega

What you get

ChatGPT in the browserObserved
Desktop AI appObserved
Local MCP toolObserved

Discover AI apps

ProblemA desktop app, a browser assistant, or a local MCP tool never touches a gateway.

CortegaObserve catalog AI apps on the device and report what was used, with no change to the user’s workflow.

Endpoint Guard →
Approved assistantPolice
Trial AI toolObserve
Unapproved AI appBlock

Allow, watch, or block

ProblemNot every AI app deserves the same treatment.

CortegaSet observe, police, or block rules per app. Police adds local guardrails.

A. Rivera · MacBook ProEnrolled
J. Chen · Windows laptopEnrolled
Unknown deviceNot enrolled

Know every device

ProblemYou cannot govern what you cannot enumerate.

CortegaSee each enrolled device by user, hostname, and hardware serial. Remove a device to free its slot.

SSN 123-45-6789 · key sk-live-8f2a…SSN ●●●-●●-●●●● · key ●●●●●●●●

Stop accidental leaks

ProblemAn employee pastes a customer record or a credential into an assistant.

CortegaLocal guardrails detect sensitive data and log, mask, or reject it before it leaves the device.

AI Data Protection →
Device offlineGuardrails run
Default postureFails open
Strict postureBlock on failure

Works without the cloud

ProblemA device that cannot reach the control plane should not stop work or skip protection.

CortegaGuardrails run on the device with no cloud call. If the device cannot reach Cortega, AI traffic keeps working, with a stricter block-on-failure option.

GeneralHealthcareFinanceGovernment
Plus custom patterns for your own terms

Tune to your industry

ProblemA bank and a hospital worry about different data.

CortegaStart from a General, Healthcare, Finance, or Government pack. Switch detectors on or off and add custom patterns.

Claude CodeCursorAiderAI Border Gateway
Control models, budgets, and observability

Route assistants through your gateway

ProblemCoding assistants send model calls straight to a provider.

CortegaConfigure Claude Code, Cursor, Aider, and other supported tools to use AI Border Gateway with one Cortega key per device.

Coding tools →
1Selected traffic opted inOn
2Topics and sentimentLabeled
3Citation checkFlagged

Add signals and verification

ProblemSeeing that AI was used does not show whether it went well.

CortegaOpt in Cortega Agents on selected endpoint traffic for AI Signals and response verification.

AI Signals →
FleetMDM + certificates
PilotSelf-service
Internal testShared key

Roll out your way

ProblemA fleet, a pilot, and a lab test need different enrollment.

CortegaUse MDM with per-device certificates for a fleet, self-service for admin-managed pilots, or a shared key for internal testing.

App inspection covers supported, configured domains on Windows and macOS. Domains outside the configured scope stay encrypted and are not captured or checked.

In the console

Manage applications, guardrails, and enrolled devices.

App policy
Endpoint Guard application policy settings
Endpoint Guard local data protection guardrails
Endpoint Guard enrolled device inventory
Endpoint Guard observed traffic in the Cortega console

From the Cortega console.

Shadow AI

See the AI use you cannot see today

Start with the devices, the AI apps in use, and the data you need to protect.