Operations / Overview
ON-PREMISE?

YOUR AI SECURITY AT A GLANCE

Protection overview

Understand what CyberPass protected, what needs attention and whether every control is working.

Review incidents

CURRENT STATUS

Checking protection…

CyberPass is confirming the active policy, routes and system components.

Setup
Checking
Last 24 hours
Data stored
Metadata only
AI ACTIVITY
0

Requests inspected in 24 hours

PROTECTION ACTIONS×
0

Blocked or redacted 0%

NEEDS ATTENTION!
0

Security events awaiting review

CONNECTED APPS
0

Approved identities using Gateway

24-HOUR PROTECTION ACTIVITY

What CyberPass did

Explore activity
AllowedRedactedBlocked
PRIORITY QUEUE

What needs attention

Open queue

Checking open security work.

RECENT ACTIVITY

Latest protection decisions

No events recorded yet.

SETUP PROGRESS

Finish protection setup

0 / 4
  1. Connect a providerAdd one approved OpenAI-compatible endpoint.
  2. Create a model aliasGive applications a stable model identifier.
  3. Activate a policySimulate before enabling enforcement.
    Open
  4. Issue application accessCreate a service account and scoped key.
    Open
Gateway endpoint copied

ON-PREMISE CONTROL PLANE

Sign in to CyberPass

Credentials stay inside this deployment. The first administrator can initialize a new installation.

HUMAN ACCESS

Add member

APPLICATION ACCESS

Create service account

SCOPED CREDENTIAL

Create API key

Scopes

STREAMABLE HTTP

Add MCP server

Current baseline supports MCP Streamable HTTP tools/list and tools/call. HTTPS verification is mandatory.

TOOL CONTROL

Add MCP tool policy

ONE-TIME DEVICE ENROLLMENT

Add Windows endpoint

Download the CI-built artifact, unzip it, then run the generated command in PowerShell as Administrator.

PROVIDER ADAPTER

Add inference provider

Public routes require HTTPS and certificate verification. Credentials are AES-GCM encrypted before storage.

MODEL CATALOG

Add model alias

Applications use the stable alias. The upstream model can be changed later without changing application code.

IMMUTABLE VERSION

Create policy draft

Allowed file formats

Creating a draft does not change live traffic. Activation is a separate audited action.

NO PROVIDER CALL

Policy simulation

CUSTOM DATA RULE

Add DLP detector

Use synthetic examples only. Dictionary matching is case-insensitive.

LOCAL EVALUATION

DLP test lab

IN-MEMORY EXTRACTION

File test lab

Maximum 10 MB hard limit; the active policy may set a smaller limit. Encrypted and embedded documents fail closed.

SECURITY REVIEW

Review security event

UNIVERSAL IDENTITY ADAPTER

Add identity provider

Provisioning

Federated mapping cannot grant the owner role. Credentials are encrypted and never returned by the API.

CUSTOMER PKI

Add CA trust bundle

The bundle is parsed locally. Only its fingerprint, count and expiration are shown after upload.

CEF / SYSLOG

Add SIEM destination

No prompt or response content is sent. TCP/TLS validates the server certificate; private keys are encrypted before storage.