Skip to content
MoorAI
// data-loss prevention for AI

On-device AI DLP

Developers paste secrets, customer data, and proprietary source into AI agents all day. MoorAI is data-loss prevention that runs on the endpoint — it reviews every prompt locally and redacts or blocks sensitive data before it reaches Claude Code, Codex, or Copilot CLI. The difference from cloud DLP: nothing has to leave the machine.

// the flow

One local check on the device, before a prompt reaches the AI — then only content-free signals flow to the console.

One check, on the device — before the AI sees anything. // moorai · on-device AI guardrails Employee types a prompt MoorAI 67-threat matrix · content rules · local coach alert block justify prompt content never leaves the machine AI agent Claude · Codex Copilot CLI Model API cloud LLM Central console posture · inventory · compliance — content-free signals only // four pillars On-device DLP Prompts and outputs checkedlocally against policy — nothinghas to leave the endpoint. AI-SPM for endpoints Shadow-AI discovery plusagent, tool & MCP governancewhere the work happens. Human-in-the-loop Coach, alert, block, or requirea signed justification — setper policy, tenant, device. Continuous compliance OWASP LLM · MITRE ATLASNIST AI RMF · ISO 42001EU AI Act-aware.
// how it works

Review before the agent,
redact when possible.

The moment a prompt is sent, MoorAI checks it locally against policy — a 67-threat matrix plus content rules. If it carries an API key, a private key, an email, a national ID, a payment card, or PHI, MoorAI can redact the sensitive span and forward a clean prompt, coach the user, require a logged justification, or block outright — per policy, per tenant, per device. When a prompt is blocked, the user can still send it with the sensitive parts redacted, so work isn't stopped needlessly.

// classification

Classify by data tier.

MoorAI groups detections into four data classes, so you can set one default action per class instead of tuning every rule — and a per-threat setting still overrides it.

Personal data
PII
Emails, phone numbers, national IDs, passports.
Credentials
Secrets
API keys, OAuth tokens, private keys, cloud credentials.
Intellectual property
Source / IP
Roadmaps, architecture, trade secrets, licensed or copyrighted code.
Regulated
PHI / PCI
Health data (HIPAA) and payment-card data — with tighter defaults.
// privacy

Governance without surveillance.

The core invariant: by default, prompts and conversations never leave the device. Security teams receive only redacted, content-free signals — a category, a risk level, and a keyed one-way hash — through a central web console. You get evidence of what class of data was at risk and what action was taken, without ever exposing what anyone typed. The one way content is retained is a capture tier an administrator turns on deliberately, per tenant, and that choice is logged.

// faq

Frequently asked.

Does the prompt content leave my machine?

No. Detection and redaction happen locally; only content-free metadata is reported.

Can it redact instead of just blocking?

Yes — MoorAI redacts the sensitive spans and forwards a clean prompt when possible, so blocked prompts can still be salvaged.

Which agents does it cover?

The AI agents developers run locally — Claude Code, Codex, and GitHub Copilot CLI — as a thin native host in front of them.

More: shadow-AI detection · OWASP LLM Top 10 tooling · MoorAI vs Lakera

Keep the secrets
on the device.

Redact or block before the prompt reaches the agent.