# Kavara — Shadow AI Governance & AI Data-Loss Prevention > Kavara solves Shadow AI — the ungoverned use of AI tools (ChatGPT, Claude, Gemini, Copilot) by employees who paste sensitive data into prompts outside IT oversight. A browser extension detects sensitive data the moment it's typed and tokenizes it before it leaves the browser. CISOs get full visibility into Shadow AI usage without any raw sensitive data ever reaching Kavara's servers. For the full product documentation, see: https://www.kavara.io/llms-full.txt ## The Shadow AI problem Employees use AI tools every day. They paste API keys, customer PII, source code, and financial data into prompts — on personal accounts, outside every security tool the enterprise has deployed. Traditional network DLP can't see these prompts (they go over TLS from browser to AI provider). Blocking AI tools doesn't work (employees route around blocks on personal devices). The data is gone before any gateway gets a vote. ## How Kavara solves it - **On-device detection**: 16 built-in detectors (PII, API keys, secrets, payment cards, source code) run in the browser in real time. Nothing is sent anywhere to decide whether text is sensitive. - **Reversible tokenization**: sensitive spans become tokens like [API_KEY-1] before the prompt leaves the page, then rehydrate locally in the response. The AI still reasons about the data; the employee still gets a useful answer. Nothing is blocked, nothing leaks. - **Shadow-AI visibility**: see which AI tools your org uses and what data categories they touch — aggregate, never per-employee surveillance. - **Progressive enforcement**: Monitor → Warn → Block, configurable per tool and category. - **Self-serve rollout**: enrollment codes for pilots; MDM / Chrome Enterprise for fleets. ## Key differentiator Kavara is the only AI DLP that uses reversible tokenization. Every competitor (Nightfall, Cyberhaven, LayerX, Google Chrome Enterprise Premium) either blocks or masks — destroying the employee's ability to get a useful AI answer. Kavara tokenizes so the AI can still reason, then rehydrates real values in the response. Protection without productivity loss. ## Security posture - No raw data stored: the database has no column for raw prompts, responses, or secrets — only a category and a count. - Keys stored only as a peppered hash plus a short display prefix. - Strict tenant isolation enforced on every query. - Encryption in transit; DPA and security-review support available. ## Coverage - AI tools: ChatGPT, Claude, Gemini, Copilot, Perplexity, Mistral, Grok and more — 11+ assistants out of the box. - Browsers: Chrome, Edge, Brave. ## Pricing - Pilot: Free, up to 25 seats, Monitor mode. - Team: $25 / seat / month — Monitor, Warn & Block; custom rules; MDM deployment; audit log. - Enterprise: Custom — custom detectors, department rollups, configurable retention, DPA & security review. ## Pages - Home: https://www.kavara.io/ - What Is Shadow AI?: https://www.kavara.io/shadow-ai - Features: https://www.kavara.io/features - Security: https://www.kavara.io/security - Pricing: https://www.kavara.io/pricing - About: https://www.kavara.io/about ## Contact - hello@kavara.io