AI Data Protection
Mask Personal Data in AI Traffic With No Code Change
- 01
AI traffic from devices
- 02
AI hosts inspected and masked
- 03
Other sites tunnelled unread
500+
Built-in detectors for personal data and secrets
45
Country packs, checksum-validated where the format has one
9
AI providers behind one gateway, plus a no-code proxy
The problem
Not every AI call comes from code you control. Off-the-shelf tools, internal scripts, and employees in the browser all talk to AI providers directly, and none of them will be rewritten to use a gateway.
Blocking AI tools outright moves usage to personal devices, where there's no visibility at all. What's needed is a control at the network layer that lets the traffic through and takes the sensitive parts out.
How Maskflare Forward Proxy works
Clients use the Maskflare proxy as their HTTPS proxy and trust your organization's Maskflare certificate. Traffic to api.openai.com, api.anthropic.com, generativelanguage.googleapis.com, api.mistral.ai, api.x.ai, api.deepseek.com, api.groq.com, and api.together.xyz is decrypted, masked with your rules, and forwarded. With browser data loss prevention turned on, prompts typed into ChatGPT on the web are masked too. Everything else passes through as an encrypted tunnel that Maskflare does not read.
Benefits
No code change
Set the proxy and trust the certificate, typically through device management. Tools and scripts work as before.
ChatGPT on the web
With browser DLP on, prompts to chatgpt.com are masked, and uploads other than plain text, CSV, JSON, and Markdown are blocked.
Narrow by design
Only the eight AI API hosts and ChatGPT are decrypted. Banking, mail, and every other site stay an unread tunnel.
Same rules as the gateway
Proxy and gateway traffic use the same rules for the environment the key belongs to.
Capabilities
Authentication
The Maskflare key travels in the proxy's Proxy-Authorization header, as Basic or Bearer.
Certificate
A shared Maskflare certificate, or your organization's own certificate authority, set up in the console.
Lock-down option
Optionally refuse every destination that isn't an inspected AI host.
Credential blocking
On ChatGPT, prompts containing API keys, cloud keys, tokens, or private keys are blocked outright.
Explore related capabilities
See how Maskflare applies the same masking rules to related AI and data-protection workflows.
Frequently asked questions
Which AI tools does the forward proxy cover?
API traffic to OpenAI, Anthropic, Google Gemini, Mistral, xAI, DeepSeek, Groq, and Together AI from any application, and, with browser data loss prevention on, prompts typed into ChatGPT on the web. Other AI web apps are not inspected today.
Does ChatGPT's reply show the real values again?
No. On ChatGPT in the browser, masking applies to what is sent; the reply shows the tokens rather than the original values.
Is all our web traffic decrypted?
No. Only the AI provider hosts and ChatGPT are decrypted and inspected. Everything else is passed through as an encrypted tunnel.
What do devices need?
The proxy address and trust in your organization's Maskflare certificate. Nothing is installed in the AI tools themselves.
See it on your own data
Book a 30-minute demo.
Bring your hardest prompts.
We'll show detection, masking, and restoration on your providers and data types,
and how it fits your stack.