Personal or confidential information can end up sent to an external AI service without anyone meaning it to. Security Filter guards that entry point.
Security Filter detects PII before it reaches a model. Detect-and-warn comes standard from Team, and sending it masked with restore-on-response comes standard from Business.
Scan outgoing content for PII.
Mask what's detected.
Send the masked content to the model.
Restore the masked content when the response arrives.
Included on Team, Business, Business+, and Enterprise. Detection precision and scope grow with the plan.
| 項目 | Team | Business | Business+ | Enterprise |
|---|---|---|---|---|
| Detect and warn | Yes | Yes | Yes | Yes |
| Secret-variable masking | — | Yes | Yes | Yes |
| Auto-mask and restore | — | Yes | Yes | Yes |
| Contextual detection + mask-event audit view | — | — | Planned (from Oct 2026) | Planned (from Oct 2026) |
| Custom detection rules, BYO dictionaries & org-wide enforcement | — | — | — | By consultation (from Oct 2026) |
Suppose someone sends "Draft a reply for Mr. Tanaka (tanaka***@example.com / 090-1234-5678)" to an external AI. Here is what happens on each plan.
Right before sending, a warning appears: "This message contains an email address and a phone number." The user decides whether to send. Nothing is rewritten. The detection itself is recorded as an audit event (the actual values are never stored).
The sensitive parts are automatically replaced with placeholders such as «EMAIL_1» before the message leaves. The external AI never receives the real values. If the AI's response references a placeholder, it is restored to the original value only when displayed — so the experience stays seamless.
Detects what fixed patterns cannot catch — names, addresses, and context-dependent secrets — using AI-based contextual detection, and adds an audit view of when, by whom, and what was masked.
Beyond warning and masking: block the send itself, enforce policy across the entire organization, and bring your own detection dictionaries (such as internal project names).
Team gets detect-and-warn, and Business gets automatic mask-and-restore, standard. Business+ will add contextual detection and mask-event audit review on top of that — planned for October 2026 and later. Custom detection rules, bringing your own detection dictionary (BYO), and an org-wide policy that individual users can't turn off are available to discuss through the Enterprise program (rolling out from October 2026 onward).
Security Filter isn't meant to replace perimeter DLP (Data Loss Prevention) — it's designed to work alongside it. Where perimeter tools inspect traffic broadly, Security Filter focuses specifically on content sent to AI models, detecting and masking it before it goes out.
Contextual detection on Business+ is planned for October 2026 and later. A tenant-level extension for custom detection dictionaries and rules tailored to your organization is available to discuss through Enterprise (rolling out from October 2026 onward).
Want to talk about your rollout? Use the contact form.
Try three modes — Chat, Compare, and Debate — free.
Start free