Keep company information from leaving.

Personal or confidential information can end up sent to an external AI service without anyone meaning it to. Security Filter guards that entry point.

Security Filter

Detect before it's sent. Mask it. Restore it later.

Security Filter detects PII before it reaches a model. Detect-and-warn comes standard from Team, and sending it masked with restore-on-response comes standard from Business.

How it works

Detect

Scan outgoing content for PII.

Mask

Mask what's detected.

Send

Send the masked content to the model.

Restore

Restore the masked content when the response arrives.

By plan

Included on Team, Business, Business+, and Enterprise. Detection precision and scope grow with the plan.

項目TeamBusinessBusiness+Enterprise
Detect and warnYesYesYesYes
Secret-variable masking—YesYesYes
Auto-mask and restore—YesYesYes
Contextual detection + mask-event audit view——Planned (from Oct 2026)Planned (from Oct 2026)
Custom detection rules, BYO dictionaries & org-wide enforcement———By consultation (from Oct 2026)

The four stages, by example

Suppose someone sends "Draft a reply for Mr. Tanaka (tanaka***@example.com / 090-1234-5678)" to an external AI. Here is what happens on each plan.

Team — detect and warn

Right before sending, a warning appears: "This message contains an email address and a phone number." The user decides whether to send. Nothing is rewritten. The detection itself is recorded as an audit event (the actual values are never stored).

Business — auto-mask on send, restore on response

The sensitive parts are automatically replaced with placeholders such as «EMAIL_1» before the message leaves. The external AI never receives the real values. If the AI's response references a placeholder, it is restored to the original value only when displayed — so the experience stays seamless.

Business+ — contextual detection and mask auditing (planned from October 2026)

Detects what fixed patterns cannot catch — names, addresses, and context-dependent secrets — using AI-based contextual detection, and adds an audit view of when, by whom, and what was masked.

Enterprise — enforce it as company policy (by consultation, rolling out from October 2026)

Beyond warning and masking: block the send itself, enforce policy across the entire organization, and bring your own detection dictionaries (such as internal project names).

An org-wide enforced policy

Team gets detect-and-warn, and Business gets automatic mask-and-restore, standard. Business+ will add contextual detection and mask-event audit review on top of that — planned for October 2026 and later. Custom detection rules, bringing your own detection dictionary (BYO), and an org-wide policy that individual users can't turn off are available to discuss through the Enterprise program (rolling out from October 2026 onward).

Our design approach

Security Filter isn't meant to replace perimeter DLP (Data Loss Prevention) — it's designed to work alongside it. Where perimeter tools inspect traffic broadly, Security Filter focuses specifically on content sent to AI models, detecting and masking it before it goes out.

Contextual detection on Business+ is planned for October 2026 and later. A tenant-level extension for custom detection dictionaries and rules tailored to your organization is available to discuss through Enterprise (rolling out from October 2026 onward).

Related pages

Want to talk about your rollout? Use the contact form.

Try three modes — Chat, Compare, and Debate — free.

Start free
Language日本語English
Security Filter — Prompt Flow Studio