AI privacy, on a ledger

See every prompt your team sends to AI.

The NexGuardian gateway logs every prompt before it leaves, redacts your clients' PII, and routes anything sensitive to an approver you name on your side — so nothing slips out unseen, and the decision stays with your people.

Works with the AI you already use. Set up in about a day. No credit card.

LEDGER_ENTRY #4417

"Refund $214.00 to Jordan W at acct •••• 9124 today"

WHOanalyst.f
WHEN14:02
STATUSHold · awaiting approval
Waiting on
[Approver's name]
Human-in-the-loop

Prompt → Redact → Approve

Three lines. That's the whole deal.

Nothing clever or hidden. Every request walks the same three steps, and you can watch it happen in the ledger you own.

01

Prompt

Your team asks an AI to act — a refund, a draft, a lookup. The gateway catches it before it leaves the building.

02

Redact

Names, emails, account IDs, the sneaky fields too — stripped from the request. Your clients stay out of your AI.

03

Approve

If it touches a sensitive action, it holds for an approver you've named on your own team before anything moves. Someone you choose stays on the calls that matter.

What the gateway actually does

The ledger you can open, not a wall against thieves.

We don't pave your floor with encrypted this and zero-trust that. We give you three working things you'll check every day.

Redact

Client data stays out of your AI.

Every prompt is scanned before it leaves. Names, emails, phone numbers, account IDs get stripped before your AI ever sees them — the obvious fields and the sneaky ones.

Redaction · Outbound

Email c.shen@acme.com — policy #A-1192 within 4 hrs

Sensitive spans crossed out in amber-red ink before they reach the model. You see exactly what was held back.

Log & audit

Every prompt, in a ledger you can open.

Each request becomes a dated entry — who sent it, what it said, when, which AI, what came back. An owner can open the whole trail; nothing runs in a black box.

Ledger access · last 4 entries

14:02analyst.f · refund request · hold
13:47marketing.l · draft outreach · sent
13:12legal.k · renewal clause · sent
12:58sales.j · prospect lookup · hold

The whole book is yours. Who, when, model, status — every row openable, nothing in a black box.

Human-in-the-loop

Your named approver says yes first.

Sensitive actions — sending data, spending, sharing — hit a hold row and wait for an approver you name inside your own firm. The amber-red dot marks exactly where one of your people decides.

Approval queue · waiting on your approver

14:02Refund $214.00 · waiting on [Approver]
12:58Prospect lookup · waiting on [Approver]

The amber-red dot means a person is deciding right now. It appears nowhere else — whenever you see it, a human is present.

See your first ledger entry.

It takes about a day to set up, works with the AI you already use, and the first thing you'll see is a clean, readable book where there used to be a black hole.

No credit card. No sales gauntlet. Just the book, proven.

Questions you'd actually ask

Which AI tools does it work with?
Any model your team already uses — the gateway sits in front, logs the request, redacts what needs redacting, and passes it on. You don't change the tool; you change whether it leaks.
Does it slow down the team?
Redaction and logging run in the request path — practically instant. Only actions you've flagged as sensitive go to a human, and only those stop to wait.
Who approves the sensitive stuff?
You name the approvers. It can be you, a compliance lead, a department head — whoever you want in the loop. If no one approves, it doesn't move.
What if a prompt slips past redaction?
The prompt log keeps the original and the redacted version side by side, with who sent it and when. Nothing stays hidden — a slip becomes a dated line in the book you can act on, not a secret.
Do you store my clients' data?
No. The gateway forwards the redacted request and keeps the log of what happened; the raw sensitive value isn't cargo we ship around. Compliance has the exact retention terms if you want them.