Shadow AI Sentinel is a free browser extension that discovers every AI tool your employees touch, enforces policy at the browser, and turns it all into auditor-ready evidence — no agents, no deployment, installed in 30 seconds.
Free forever for discovery & monitoring · No credit card · No PII collected · Opt-in telemetry only
Employees paste source code into chatbots, route customer data through unvetted copilots, and connect AI agents to production systems — invisible to your SSO logs and your CASB. Regulators stopped accepting "we didn't know." So did insurers.
A curated allowlist of 142+ AI services (ChatGPT, Copilot, Gemini, Claude, Midjourney, agent platforms and more), observed at the browser with zero PII in free mode — anonymous device IDs only.
Block, warn, or allow per domain with policy-as-code: versioned, audit-trailed, signed down to the browser. A fleet-wide kill switch satisfies the insurer's first question before it's asked.
Deterministic, reproducible reports mapped to EU AI Act, ISO 42001, NIST AI RMF, DPDP×EU, and insurer six-controls — generated on demand with locked legal wording and a 90-day coverage window.
No agents, no network taps, no MDM project. The Chrome extension observes only curated AI domains via a published, versioned allowlist. Least privilege by design — never <all_urls>.
The console shows every tool in use, its vendor posture (enterprise vs consumer), risk tier, and what policy did about it — live violations feed included.
Policy-as-code with version diffs and an admin-identity audit trail. Modes: enforce, monitor-only, or full off (kill switch). The extension enforces at the browser via declarative net request rules.
One click produces EU AI Act transparency evidence, an insurance readiness pack naming the EPC's six controls, or a DPDP×EU joint map — JSON, print-ready HTML, or branded PDF.
"You can't govern what you can't see — and you can't buy insurance for what you can't prove. Discovery is table stakes; evidence is the product."
These are generated by the same deterministic engine that runs in the product, from an anonymized demo organization (90-day window, enforcement mode ON, policy v7). Every score is reproducible by an auditor.
Score 0–100, tier, named findings with remediation, coverage window. The one-page answer to "how bad is our shadow AI?"
Art. 50 transparency mapping, GPAI context, Annex III boundary statement — locked legal wording, ready to hand to counsel.
The EPC six controls by name — kill switch, human-in-the-loop inventory, provenance, accountable exec, deepfake-resistant auth, MS-stack enforcement — each mapped to NIST AI RMF · ISO 42001 · AIUC-1.
Cross-border obligations shared between India's DPDP Rules and the EU AI Act — one table your GC can act on.
No PII in free mode. Anonymous device IDs; org linkage happens server-side against hashed install keys. Index data opt-in and k-anonymized at source. Published methodology, not vibes.
Signed config (HMAC-SHA256, dual-key rotation), zero remote code, strict CSP, SBOM per release, threat model + ADRs in-repo, OpenAPI contract, wire-level tests. The repo survives diligence tomorrow.
Reports state plainly: informational evidence — not certification, not insurance advice. Findings-not-bugs: "you cannot audit X" appears as a finding with remediation, never hidden.
Add the extension, browse as usual, watch your inventory build itself — then generate your first EU AI Act evidence pack before lunch.
Security teams: ask us for the broker/insurer evidence pack · security@shadowaisentinel.app