Zedmos

AI Gateway & DLP

Your data should not leave the company in an AI prompt

Generative AI turned every browser into an export channel. Zedmos inspects the request before it leaves the network, decides on content rather than destination, and records what was sent where.

The Zedmos policy editor inside OPNsense with sections for security, IDS/IPS, antivirus, DNS, application routing, AI security & DLP and TLS.
One policy: IDS/IPS, AI security & DLP, TLS and routing in one editorOPNsense · os-zedmos
AI gateway · decided on content, at the edgeblocked before it leavesEmployee's browsera prompt, a paste, an uploadmay carrycustomer recordssource & secretsnational IDs · payment dataZedmos at the edgethe same firewall that routes itPattern matching69 detectors · 22 national ID formatsLocal language modeljudges meaning, on the applianceOne verdictallowed · blocked · always recordedAI providers · 11 trackedChatGPT · Claude · Gemini · …Shadow-AI inventorywho used what, and whereNothing is sent anywhere to make this decision. The model runs on the appliance.
61
Content detectors
22
National ID formats
7
Detector groups
11
AI providers tracked

What it actually looks for

Payment data, national identifiers across twenty-two countries, cloud provider secrets and access tokens, private keys, personal data and crypto material — plus prompt-injection patterns.

Two layers, one decision

Pattern matching catches the structured things fast. A local language model is asked about the rest, so a paragraph of confidential prose is judged on meaning rather than on whether it matched a regular expression.

Shadow AI, made visible

An inventory of which AI services are actually in use, who is using them and where each one processes data — the report a data protection review asks for.

Questions and answers

What is the Zedmos AI Gateway?

Inline inspection of requests to generative-AI services before they leave the network. The gateway decides on the content of a prompt or upload rather than on its destination, and records what was sent where.

Which AI services does it cover?

ChatGPT, Claude, Gemini, Copilot, Perplexity, DeepSeek, Mistral and on-premises models, with an inventory of which services are actually in use, by whom, and where each one processes data.

What does the data loss prevention detect?

69 content detectors in 8 groups: national identifiers from 22 countries, cloud provider secrets and access tokens, personal data, payment data, AI-prompt patterns including prompt injection, instructions that try to turn an assistant against you, security material and cryptographic material.

Does the AI gateway itself send my data to an AI provider?

No. Pattern matching runs on the box, and unstructured text is judged by a local language model on your own hardware. Nothing is sent to a third-party model to reach a verdict.

Can AI use be allowed for some groups and blocked for others?

Yes. Policy selects by application, category, user, group, device and zone, and the same actions apply as elsewhere in the engine: allow, log, drop, redirect or quarantine, among the sixteen available.