# Sanitized Ai > Shadow AI detection and PII leak prevention for enterprise LLM usage. Sanitized Ai detects and redacts sensitive data in AI prompts — across ChatGPT, Claude, Gemini, Copilot, Perplexity, and a growing list of tools — before it leaves the organization. Sanitized Ai is an enterprise security product from Sanitized AI Inc. (Canada). It deploys as a browser extension (Chrome, Microsoft Edge, and Firefox — available on the Chrome Web Store, Edge Add-ons, and Firefox Add-ons). Prompts and file uploads (DOCX, XLSX, PPTX, PDF) are inspected and PII is redacted — names, emails, credit cards, SSNs, health records, and proprietary data — before the prompt reaches the AI provider. Admins see only flagged event metadata, not full prompt content. Risk dashboards and audit-ready reporting support AI acceptable-use policy and compliance. ## Core pages - [Home](https://sanitized.ai/): product overview and live sanitization demo - [Mission](https://sanitized.ai/mission/): why Sanitized Ai exists — safe AI adoption, not AI bans - [Trust Center](https://sanitized.ai/trust/): commitments, framework mapping (PIPEDA, Quebec Law 25, GDPR, PHIPA), data-handling FAQ, responsible disclosure - [Shadow AI Readiness Check](https://sanitized.ai/readiness/): five-question self-assessment with scored results - [For law firms](https://sanitized.ai/solutions/law-firms/): privilege, confidentiality, and supervision — AI adoption a partner can defend - [For accounting firms](https://sanitized.ai/solutions/accounting/): CPA confidentiality duty, client SINs and returns caught before submission - [For healthtech & clinics](https://sanitized.ai/solutions/healthtech/): PHIPA-fluent PHI protection in prompts and file uploads - [For software & engineering teams](https://sanitized.ai/solutions/engineering/): source code, API keys, and trade secrets stay home - [For financial services](https://sanitized.ai/solutions/finance/): client holdings, account numbers, and MNPI caught before a prompt leaves the firm - [For insurance](https://sanitized.ai/solutions/insurance/): policyholder identities, medical details, and claim numbers stay inside the claims workflow - [For security awareness programs](https://sanitized.ai/solutions/security-awareness/): a prompt-level checkpoint that turns AI training into a measurable control - [For game studios](https://sanitized.ai/solutions/gaming/): source code, unannounced titles, platform NDA material, and player data stay in the studio - [AI Acceptable-Use Policy Generator](https://sanitized.ai/tools/aup-generator/): answer six questions, download a working policy draft — free, no email - [AI Tool Risk Directory](https://sanitized.ai/ai-tools/): data-handling and compliance profiles of the AI tools professionals actually use — training on inputs, retention, residency, SOC 2, HIPAA/BAA, FERPA — verified against vendor policies. Each tool has its own profile at https://sanitized.ai/ai-tools// (e.g. /ai-tools/chatgpt/, /ai-tools/microsoft-copilot/, /ai-tools/otter-ai/) answering "is this tool safe for confidential data?" per plan tier, with a dated policy changelog and a "verified" date on every profile - [AI Compliance Standards](https://sanitized.ai/standards/): plain-language guides (English and French) to NIST AI RMF, ISO/IEC 42001, the EU AI Act, PIPEDA, Quebec Law 25, AIDA/Bill C-27, FERPA, COPPA, the Colorado AI Act, CCPA/CPRA, NYC Local Law 144, SOC 2, and ISO 27001 as they apply to AI and data privacy — verified against primary sources, each at https://sanitized.ai/standards// with a "verified" date - [AI Security Glossary](https://sanitized.ai/glossary/): plain-language definitions of AI security, privacy, and governance terms — shadow AI, prompt injection, PII redaction, training on inputs, DPA, BAA, zero data retention, and more — each at https://sanitized.ai/glossary// with links to the related tool profiles and compliance guides - [Programs & Partners](https://sanitized.ai/partners/): the acceleration and innovation programs Sanitized AI is part of — Rogers Cybersecure Catalyst (/partners/rogers-cybersecure-catalyst/), Innovation Factory (/partners/innovation-factory/), and the Clay Startup Program (/partners/clay-startup-program/) - [Get started / request access](https://sanitized.ai/intake/): request early access or book a demo - [Pricing](https://sanitized.ai/pricing.md): enterprise, custom-quoted - [Blog](https://sanitized.ai/blog/): research and guidance on shadow AI and data leakage - [Privacy Policy](https://sanitized.ai/privacy/) - [Terms of Service](https://sanitized.ai/terms/) ## Capabilities - Shadow AI Detection — discover AI tools in use across the organization (ChatGPT, Claude, Gemini, Copilot, Perplexity, and a growing list) - PII Leak Prevention — real-time scanning of prompts and file uploads (DOCX, XLSX, PPTX, PDF) for SSNs, credit cards, health records, and proprietary data - Prompt Privacy — admins see only flagged content, not full prompts - Risk Dashboards — risk scores, trend analysis, and audit-ready reports - Policy Enforcement — block, warn, or allow AI usage with full audit trails - Team Insights — AI adoption patterns by department ## Selected writing - [Shadow AI, explained](https://sanitized.ai/blog/shadow-ai-explained/) - [Shadow AI in 2026: the insider threat draining your enterprise data](https://sanitized.ai/blog/shadow-ai-in-2026-the-insider-threat-draining-your-enterprise-data/) - [Canada's OpenAI privacy violation](https://sanitized.ai/blog/canada-openai-privacy-violation/) - [The opt-out illusion](https://sanitized.ai/blog/the-opt-out-illusion/) - [US cyber-defense chief leaks info](https://sanitized.ai/blog/us-cyber-defense-chief-leaks-info/) - [Why your AI acceptable-use policy probably isn't working](https://sanitized.ai/blog/why-your-ai-acceptable-use-policy-probably-isnt-working/) - [We're live on Chrome and Edge](https://sanitized.ai/blog/we-are-live-on-chrome-and-edge/) ## Contact - Sales: sales@sanitized.ai - App: https://app.sanitized.ai