Skip to content

AI Data Protection

Mask Personal Data in AI Traffic With No Code Change

Route AI traffic through the Maskflare forward proxy and prompts to eight AI providers, and to ChatGPT on the web, are inspected with your rules. Every other site is tunnelled untouched.
proxy path
  1. 01

    AI traffic from devices

  2. 02

    AI hosts inspected and masked

  3. 03

    Other sites tunnelled unread

500+

Built-in detectors for personal data and secrets

45

Country packs, checksum-validated where the format has one

9

AI providers behind one gateway, plus a no-code proxy

The problem

Not every AI call comes from code you control. Off-the-shelf tools, internal scripts, and employees in the browser all talk to AI providers directly, and none of them will be rewritten to use a gateway.

Blocking AI tools outright moves usage to personal devices, where there's no visibility at all. What's needed is a control at the network layer that lets the traffic through and takes the sensitive parts out.

How Maskflare Forward Proxy works

Clients use the Maskflare proxy as their HTTPS proxy and trust your organization's Maskflare certificate. Traffic to api.openai.com, api.anthropic.com, generativelanguage.googleapis.com, api.mistral.ai, api.x.ai, api.deepseek.com, api.groq.com, and api.together.xyz is decrypted, masked with your rules, and forwarded. With browser data loss prevention turned on, prompts typed into ChatGPT on the web are masked too. Everything else passes through as an encrypted tunnel that Maskflare does not read.

Benefits

No code change

Set the proxy and trust the certificate, typically through device management. Tools and scripts work as before.

ChatGPT on the web

With browser DLP on, prompts to chatgpt.com are masked, and uploads other than plain text, CSV, JSON, and Markdown are blocked.

Narrow by design

Only the eight AI API hosts and ChatGPT are decrypted. Banking, mail, and every other site stay an unread tunnel.

Same rules as the gateway

Proxy and gateway traffic use the same rules for the environment the key belongs to.

Capabilities

Authentication

The Maskflare key travels in the proxy's Proxy-Authorization header, as Basic or Bearer.

Certificate

A shared Maskflare certificate, or your organization's own certificate authority, set up in the console.

Lock-down option

Optionally refuse every destination that isn't an inspected AI host.

Credential blocking

On ChatGPT, prompts containing API keys, cloud keys, tokens, or private keys are blocked outright.

Explore related capabilities

See how Maskflare applies the same masking rules to related AI and data-protection workflows.

Frequently asked questions

Which AI tools does the forward proxy cover?

API traffic to OpenAI, Anthropic, Google Gemini, Mistral, xAI, DeepSeek, Groq, and Together AI from any application, and, with browser data loss prevention on, prompts typed into ChatGPT on the web. Other AI web apps are not inspected today.

Does ChatGPT's reply show the real values again?

No. On ChatGPT in the browser, masking applies to what is sent; the reply shows the tokens rather than the original values.

Is all our web traffic decrypted?

No. Only the AI provider hosts and ChatGPT are decrypted and inspected. Everything else is passed through as an encrypted tunnel.

What do devices need?

The proxy address and trust in your organization's Maskflare certificate. Nothing is installed in the AI tools themselves.

See it on your own data

Book a 30-minute demo.
Bring your hardest prompts.

We'll show detection, masking, and restoration on your providers and data types,
and how it fits your stack.

Book a demo