Solutions · Security

Find AI use. Understand the risk. Choose the response.

Review AI activity from managed browsers and connected enterprise sources. Identify the owner, check the data boundary, and apply the supported access or gateway controls for that workload.

TallinShadow AI discoveryExample workspace

From a browser signal to a useful next step

An AI visit starts a question.

  1. Observe
  2. Compare
  3. Review
Observed on managed browsers

Claude · claude.ai

A managed browser reported a visit to a supported AI hostname. A visit does not establish account type or reveal the prompt.

Approved access
A Claude Enterprise workspace is connected
Still unknown
Which Claude account was used during this visit
Needs review

Ask the responsible team to confirm the business use and account. Keep the finding open until the evidence supports a decision.

Browser discovery is not inline blocking. Controls apply only to requests routed through Tallin.

The response workflow

Turn an unknown service into an owned review.

Discover
Review supported service visits from managed Chrome and Edge profiles, plus configured identity, CASB, SSE, SIEM, expense, and provider evidence.
Establish context
Compare approved access and available ownership records. A browser observation does not prove which provider account was active or what content was entered.
Choose the response
Assign review, update sanctioned-use status, use a supported provider access action, or route a selected workload through Gateway controls.
Retain the decision
Keep the source, owner, disposition, and follow-up with the finding. Bring material gaps into the next project or policy review.

Review versus blocking

Be specific about the control.

Seeing a record, reviewing content, and blocking a request are different actions. Tallin shows the relevant source, permission, and request path.

Discover
Browser discovery records a supported hostname and managed profile context, without prompts, responses, page content, or unrelated browsing.
Supervise
Review retained content from supported enterprise compliance APIs with authorized, reason-gated reviewer access. This is not in-flight content filtering.
Gateway
Enforce approved models, spend limits, rate limits, and actor access on routed traffic. Content-level PII blocking is on the roadmap.
Outside the path
Connected provider APIs can observe direct calls, but Gateway cannot block those calls or tool and MCP execution side effects outside Tallin.

Data handling

Choose the deployment and capture mode.

Hosted gateway
Metadata-only capture stores no prompt or response content, but Tallin still processes routed content in memory. Full-content storage is an explicit capture option.
Customer VPC
The gateway processes traffic in your environment and sends requests to your configured AI provider. Tallin receives agreed content-free metadata, not prompts or responses.
Access and archive
Supervision archive placement and reviewer permissions are configured separately from gateway capture. Confirm the requirements for each service during setup.

Start with one source and one clear response.

Find a signal, confirm its owner and scope, then choose the review or control that matches the risk.

AI Discovery & Controls for Security Teams | Tallin