Client data is one paste away from an AI chatbot. Catch it at the paste.
Your team already uses ChatGPT, Claude, and whatever launched last week. AstraLink DLP checks every paste into those tools on the device itself, and redacts or blocks sensitive client data before it leaves, under a policy you set.
Deploys through your device management. Employees keep their tools. You keep the data.
What enforcement looks like
- An employee pastes a client email thread into an unapproved AI chatbot
- The SSN and account number are redacted on the device before the paste lands
- The employee sees why, and the event is in your audit log with the sensitive data still safe
Nobody is stealing your data. Your own team is pasting it.
AI tools are genuinely useful, so your staff use them, with or without permission. Every paste is a quiet upload of whatever was on the clipboard: tax returns, case files, patient records, deal terms. Firewalls never see it. Policies on paper never stop it. It is not malice, it is Tuesday.
A preparer pastes a client tax summary into ChatGPT to "clean up the wording" and the SSN goes with it
A paralegal drops a settlement draft into an AI chatbot for a rewrite, privileged and confidential included
Front-office staff paste patient details into a free AI tool because it answers faster than the manual
Blocking AI sites outright just pushes staff to personal devices, where you have no visibility at all
Your acceptable-use policy says "don't paste client data," and nothing on the machine backs it up
Enforcement at the moment it matters
It acts at the paste.
The moment someone pastes into an AI tool, the paste is checked against your policy: allowed, redacted, or blocked, with a clear message telling the employee why.
It knows your client data.
Detection runs on the device itself: Social Security numbers, account numbers, names, emails, and dictionaries built from your own client records, so it catches your data, not just generic patterns.
You set the dial per destination.
Approve your sanctioned AI tools with lighter rules, hold unknown chatbots to strict ones. Policy is set per destination from one console, and every decision lands in the audit log.
Three parts, one decision.
The endpoint agent does the enforcing, the browser extension tells it where a paste is headed, and the console is where you set the rules. Two of the three live on the employee's machine, which is why enforcement does not depend on a network round trip.
The endpoint agent
Installed on every managed computer. It watches for pastes into the browser and applies your policy on the spot: allowed, redacted, or blocked, with a clear message to the employee. Because it works at the operating system's clipboard rather than inside a single web page, switching browsers or windows mid-paste does not get around it. Available for macOS today, with Windows next.
The browser extension
Installed into Chrome and Edge alongside the agent. Its one job is to tell the agent which site is active, so a paste into a tool you have sanctioned is handled differently from a paste into a chatbot nobody has vetted. It communicates only with the agent on the same machine.
The console
Where the rules live: which AI destinations are sanctioned, how strict to be with everything else, the client identifiers worth protecting, and the audit log of every enforcement decision across your fleet.
How a single paste travels
The extension names the destination
It reports the active site to the agent on the same machine, and nothing more.
The agent checks the paste
Content is matched against your policy for that destination, on the device, before the paste completes.
The decision is enforced
Allowed, redacted, or blocked, with the employee told which and why.
The console records it
The event lands in your audit log, so you can show what was stopped without storing what was pasted.
Managed for you now. Yours to run shortly.
Today the console is operated by AstraLink, or by your MSP, on your behalf. You tell us which AI tools are sanctioned and how strict to be, we configure it, and you get the reporting. For most firms without a dedicated IT team, that is the arrangement they want anyway.
A tenant manager role is coming next: a sign-in of your own, scoped to your organization, so your IT lead or office manager can set policy, review the audit log, and manage enrolled devices directly, without going through us.
On the roadmap, not shipped yet. Ask us where it stands when we talk.
Rolled out before the next paste
No workflow changes, no training sessions, no asking employees to install anything. It deploys the way managed software should.
Deploy to your fleet.
The endpoint agent installs on your employer-managed computers through the device management you already use, and the browser extension arrives with it. No one has to install anything by hand.
Set the policy once.
Pick your sanctioned AI tools, set strictness for everything else, and load the client identifiers you care about. Policies update from the console and reach every device.
Enforcement just happens.
Employees work normally. When a paste would leak client data to an AI tool, it is redacted or stopped on the spot, and the event is logged so you can show what happened and what did not.
A DLP tool your employees don't have to fear.
Software that watches pastes has to earn its place on a machine. We designed AstraLink DLP so the honest answer to "what does it send?" is a short one, and we wrote it down where anyone can read it.
Detection happens on the device.
Content is inspected locally, on the computer where the paste happens. Screening a paste does not require sending it to us.
The extension sends nothing anywhere.
The browser extension makes no network requests at all. It only tells the endpoint agent on the same machine which site is active, so policy applies to the right destination.
Employer-managed, and it says so.
AstraLink DLP runs on devices your organization owns or manages, under policy your organization sets. Employees see clear messages when a paste is stopped, not silent surveillance.
The full details, including exactly what the agent and extension collect, are in the AstraLink DLP Privacy Notice.
Questions firms ask us
Does it slow people down?
No. Checks run locally on the device at the moment of paste, so there is no round trip to a server before the paste completes. Pastes that are fine go through as if AstraLink DLP were not there.
What does an employee actually see?
Nothing, until a paste would violate policy. Then they see a clear notice that the paste was redacted or blocked, and why. The goal is to correct the moment, not to ambush anyone after the fact.
Why not just block AI sites at the firewall?
Because your staff are using these tools for a reason, and a hard block sends that work to personal phones and home laptops where you have zero control. AstraLink DLP lets you sanction the tools you trust and make every tool safe to be near client data.
Does pasted content get sent to AstraLink?
No. Detection runs on the device, and the browser extension makes no network requests at all. What leaves the device is policy events for your audit log, not the content your staff work with. The details are in our DLP Privacy Notice.
Do we get our own login to the console?
Soon. Right now AstraLink or your MSP runs the console for you: you set the direction, we configure it, you get the reporting. A tenant manager role is next on the roadmap, giving your IT lead a scoped sign-in to manage policy, devices, and the audit log directly. Ask us where it stands when we talk.
What actually gets installed on a machine?
Two things: the endpoint agent, which does the enforcing at the clipboard, and the browser extension for Chrome and Edge, which tells the agent which site is active. Both arrive through your device management, so employees install nothing themselves.
Which platforms does it support?
The endpoint agent runs on employer-managed Macs today, with Windows next and other platforms after that. The browser extension covers Chrome and Edge. If your fleet is mixed, talk to us and we will be straight with you about timing.
How is this different from AstraLink Connect?
AstraLink Connect protects your office network from the outside world. AstraLink DLP protects your client data from leaving through the browser, one paste at a time. They work independently, and firms that handle sensitive client data typically want both.
Find out what's leaving in the pastes
Book a call and we'll walk you through AstraLink DLP on a real machine: a paste caught, a policy set, and the audit log to prove it. Twenty minutes, no deck.
AstraLink DLP · Built for accounting, legal, and medical practices · Houston, TX