Shadow AI discovery, observability & governance

Finally see every AI your teams are actually using.

Most of the AI in your business never shows up in a survey or your security stack. Prompt Shields surfaces the shadow tools and the AI your vendors quietly switched on, maps each one to an owner and a risk level, and hands you the evidence auditors ask for. Governance that helps people ship instead of slowing them down.

Connect

Any model — OpenAI, Claude, Gemini, Bedrock.

Observe

Every call, token & dollar in one view.

Govern

Guardrails & EU AI Act-ready evidence.

Built in Norway and the UK. Works with your Microsoft stack. Your data stays in Europe.

  • 40+ years shipping secure software
  • 100+ CIOs & CISOs interviewed
  • Backed by Innovation Norway & Microsoft for Startups
  • Trusted by a leading Nordic insurer

One API · every major model

The gap

The tools you already own can’t find your AI

Your architecture tools, your security stack, and the annual survey each see a slice of it. None of them sees the whole picture, so AI keeps spreading faster than anyone can track it. And you’re the one who has to answer for it.

Your EA tools map AI well. They just can’t find it.

Ardoq, LeanIX and ServiceNow only know about the AI someone tells them about. Today that someone is a quarterly survey, so the map is only ever as current as the last time you asked around.

Security tools stop threats. Keeping an inventory is a different job.

Defender, Purview and DLP are built to block bad behaviour, not to log every legitimate AI use with an owner and a risk score. So that part quietly falls through the cracks.

Surveys go stale the moment you send them

Ask people what AI they use and the list is already missing things. A quarter later it’s mostly fiction, and you’re the one signing off on it.

Your vendors keep switching on AI inside tools you trust

The software you already pay for keeps adding AI features. They touch your data and pull in obligations you’re accountable for, and none of it shows up in a survey or your security stack.

This is the gap we close

Prompt Shields keeps finding the AI those tools miss and gives each one an owner and a risk score, watches it as it runs, and builds the register that takes you all the way to ISO 42001. You go from guessing to a live, honest picture you can actually govern.

See how we get you to ISO 42001

The production stack

Five modules. One control plane.

Everything you need to run AI in production, on one gateway. Observability, guardrails and governance are part of the platform, so you don’t have to bolt them on later.

Model Catalog

Reach every major model (OpenAI, Anthropic, Google, Bedrock, Azure, Mistral) through one API, and switch providers without rewriting your app.

Observability

See every request as it happens, catch anomalies early, and track tokens, latency and cost by app, team and use case.

Guardrails

Block prompt injection, redact PII, and enforce your policies in real time on every model, input and output.

Prompt Management

Get prompts out of your code. Version, test and ship them from one place, with no redeploy and a full audit trail.

AI Governance

Map every use case to its owner, risk and model, and score it against the EU AI Act, NIST AI RMF and ISO 42001.

Free executive briefing

The AI Audit Playbook

How regulated enterprises get an EU AI Act–ready governance programme running in weeks instead of quarters. You get the 7-domain framework, the 6-phase plan, and a clear picture of what board-grade assurance actually takes.

  • Framework mapped to NIST AI RMF, EU AI Act, ISO 42001, OWASP LLM Top 10
  • Engagement tiers with indicative pricing
  • What a board-ready remediation roadmap looks like

We don't share your email. No spam, ever.

Plays well with your stack

Works with the tools you already have

Your EA and GRC tools are good at modelling AI. They just can't find it on their own. Prompt Shields is the layer that finds it and feeds the rest of your stack, so the tools you already bought finally have something to govern.

What Defender & Purview tell you

“Traffic to openai.com”

A domain and an allow-or-block verdict. No owner, no purpose, no idea what data it touched or how risky it is. And nothing at all for the AI your vendors switched on inside tools you already trust.

What Prompt Shields adds

Who, what data, which use case, what risk

The same signal, but tied to a named owner, the use case behind it, the data it touched, and its EU AI Act risk tier. That includes the shadow and vendor AI your security stack never lists. We sit beside Microsoft, not on top of it.

Ardoq

Enterprise Architecture

We fill in the AI register Ardoq has been waiting for. Use cases, owners and dependencies land in your existing capability model, not in yet another tab.

LeanIX

Application Portfolio

Every AI use case we find shows up against the right business capability and app, so your portfolio stays honest about what's actually running.

ServiceNow

GRC + IT Service Mgmt

Risks open as ServiceNow tickets with the owner already attached, so nothing gets lost between the policy, risk and remediation teams.

Microsoft Purview

Data Governance

Sensitivity labels, DLP signals and Purview audit data flow into the register, so the data context arrives with the prompt instead of after the incident.

You don't need another dashboard. You need the tools you already pay for to see the whole AI picture. That's the part we hand them.

European by design

Your data never leaves your tenant

Open source, self-hostable, and built in Europe, so sovereignty is just how it works rather than an upsell.

Data stays in your tenant

Self-host in your own cloud. Nothing leaves your environment.

Open-source core

Read the code, audit it, run it yourself. No black box.

Built in Europe

Norway and the UK, Nordic-backed, European by default.

Regulation-mapped

EU AI Act, DORA, NIS2, GDPR, NIST AI RMF, ISO 42001.

Buy vs build

Your smartest engineers could build this. That's exactly the problem.

A weekend script feels cheaper, right up until it becomes a system someone has to own, maintain and keep compliant while the models, providers and regulations keep changing. The hard part isn't the prototype. It's the discovery, the risk scoring and the framework coverage that have to keep working.

Build it yourself

  • A weekend script that scans one tool, then quietly becomes someone's second job
  • Framework mappings for the EU AI Act, NIST and ISO that you research and re-check by hand
  • Every new model, provider or vendor feature means wiring it up all over again
  • No owners, no risk tiers, no ongoing discovery until you build all of that too
  • The person who built it moves on, and the coverage slowly goes stale

Buy Prompt Shields

  • Running across your whole estate in a four-week pilot that fits a tight budget
  • Four frameworks mapped and kept current for you: EU AI Act, NIST AI RMF, ISO 42001, OWASP
  • Shadow and vendor AI found automatically, no survey required
  • Every use case comes with an owner and a risk tier from day one
  • Looked after by a team that's shipped secure software for 40+ years

Why us

We've done this before. We have the receipts.

We've been shipping secure software for 40+ years. We've talked to over 100 CIOs and CISOs in the last year, and a leading Nordic insurer already runs on us — its CISO now owns AI risk with Atlas AI. It's the tool they kept asking for, ready before the EU's 2026 deadline.

GDPR

Already compliant · Certification in progress

SOC 2 Type II

Certification in progress

ISO 42001

Certification in progress

ISO 27001

Certification in progress

DORA

Aligned for regulated finance

NIS2

Certification in progress

Partners & backers

Partner of Microsoft for Startups and member of Tek Norge. Backed by Antler, Innovation Norway, StartupLab, Microsoft, and Tek Norge.

  • Partner: Microsoft for StartupsMicrosoft for Startups — Partner
  • Member: Tek NorgeTek Norge — Member
  • Backer: AntlerAntler — Backer
  • Backer: Innovation NorwayInnovation Norway — Backer
  • Backer: StartupLabStartupLab — Backer

What you get from a 4-week pilot

All AI use cases discovered — including the shadow AI no other vendor sees

Owners identified per use case, with explicit accountability

Risks classified across nine categories and the EU AI Act risk tier

Concrete remediation actions suggested and initiated, not just flagged

Automated four-framework coverage report (EU AI Act, NIST AI RMF, ISO 42001, OWASP LLM Top 10)

Continuous discovery keeps the view fresh — not a quarterly snapshot

Monthly briefing

AI governance, distilled

One short email a month: what changed in the EU AI Act, the prompt-injection patterns we're seeing in the wild, and one practical control you can ship this week.

No spam. Unsubscribe any time.

On the roadmap

What we're building next

We'd rather be straight about what isn't here yet than over-promise. Here's where the things teams ask us for most actually stand.

In development

Mobile & unmanaged-device coverage

Extend discovery beyond managed desktops to mobile and BYOD, where a lot of shadow AI actually happens.

In development

In-session control & blocking

CASB-style enforcement that can redact, warn or block in real time, not just report after the fact.

Planned

Deeper auto-integration

Pull ownership and metadata straight from Entra ID, Jira and your CMDB, so the register stays current without manual capture.

Planned

Agent red-teaming & runtime monitoring

Test agents for prompt injection and watch their behaviour over time, so autonomous AI stays inside its guardrails.

What brings you here today?

Choose your path to get personalised recommendations

Get the full picture of your AI

Book a 30-minute call. We'll show you the live product, talk through what a four-week pilot looks like for your team, and help you answer the question your board keeps asking: what AI are we actually running?

See every AI in use across your business, shadow tools and vendor features included

Every request, token and dollar in one place, broken down by team and use case

Audit-ready for the EU AI Act, NIST AI RMF, ISO 42001 and OWASP, in weeks