Last 24 hours metadata only
AI SECURITY POSTURE
Good morning.
Connect the first application to begin measuring AI traffic.
Universal configuration foundationProviders, policies and metadata-only security events are managed per organization.
View scope ↗Policy decisions no data yet
Sensitive values no data yet
Gateway clients ready to connect
Gateway routing
CyberPassInspect · Decide · RouteBaseline controls
Gateway coreRegistry routing
Text DLPBaseline
LLM GuardIn development
Identity & RBACBaseline
Provider & policy registryBaseline
Coverage reflects implementation stage, not a security score.
Latest decisions
No events recorded yet.
Deployment path
LIVE AI TRAFFIC
Gateway decisions
Metadata-only view of recent AI requests. Prompt and response content is never displayed.
Waiting for Gateway traffic.
INVESTIGATION DESK
Security events
Filter, classify and export metadata evidence for Security Operations.
No matching events.
ENTERPRISE CONNECTIONS
Identity, trust & SIEM
Configure reusable protocol adapters once per organization. Customer URLs, certificates, credentials and role mappings stay in tenant-scoped records.
Identity providers
No enterprise identity provider configured.
Trust bundles
System trust store only.
Secret storage
Checking encryption configuration.
SIEM destinations
No SIEM destination configured.
CONTROLLED TOOL EXECUTION
MCP Firewall
Register Streamable HTTP servers once, expose only approved tools and require analyst approval for sensitive actions.
Server registry
No MCP servers configured.
Policies
No tool policies configured.
Pending approvals
No pending approvals.
Recent tool calls
No MCP traffic recorded.
Arguments and tool outputs are inspected in transit but are not stored. Audit records keep names, decisions and SHA-256 argument fingerprints.
UNIVERSAL LLM CONTROL
Providers, models & routing
Connect compatible inference endpoints once, then expose stable aliases to every approved application.
Inference endpoints
No providers configured.
Stable model aliases
No model aliases configured.
VERSIONED ENFORCEMENT
AI security policies
Create an immutable draft, simulate it with sample text, then activate it for Gateway traffic.
Versions
No policy versions configured.
DATA PROTECTION
DLP detectors
Built-in Kazakhstan and secret detectors plus organization-specific dictionaries and safe regular expressions.
Active inspection rules
Loading detectors.
WORKSTATION PROTECTION
Endpoint devices
Windows-first local Connector for AI agents, IDE tools and the managed Chrome/Edge extension.
Managed connectors
No endpoint devices enrolled.
Connector listens on 127.0.0.1 only. Browser protection inspects text and supported files before submission; direct egress controls remain a customer firewall/MDM responsibility.
Pending installations
No enrollment tokens created.
IDENTITY FOUNDATION
Users & application access
Human access is role-based. Applications authenticate with scoped, revocable keys.
Organization members
Sign in to load members.
Service accounts
Sign in to load service accounts.
EXPLAINABLE AI THREAT SIGNALS
LLM Guard
Detect suspicious instruction patterns, combine them into a risk score and apply the active policy threshold.
Signals for instruction override, hidden context requests and role confusion.
Signals for secret disclosure, system-prompt extraction and credential requests.
Signals that attempt to force commands or unsafe tool behavior through text.
DECISION MODEL
Signal → score → action
Guard does not promise perfect detection. Every matched signal is recorded with the request metadata so an analyst can understand why CyberPass observed or blocked a request.
SAFE VALIDATION
Test lab
Validate text, file and policy behavior with synthetic data. Tests do not call an upstream model.
DLP inspection
Check built-in and organization detectors, see matched rules and preview redaction.
File inspection
Extract and inspect a supported synthetic document with the active file policy. Contents are processed in memory and are not stored.
Policy simulation
Test a specific immutable policy version and model alias before activation.
Use synthetic data only.Do not paste real customer, payment or production secrets into the lab.
ON-PREMISE OPERATIONS
Deployment health
Runtime component state and the minimum readiness gates for a controlled pilot.
Components
Control APIConnecting
—GatewayRuntime available
READYPublic providerNo external route
OFFEvent storeMetadata only
READYPilot readiness
Checking pilot readiness.
ORGANIZATION SETTINGS
Security data
Control the retention period for minimized security-event metadata.
Event retention
Prompt and response content is not stored in the current metadata-only mode.