Your people already use AI — approved or not. Coding agents on laptops, chat in browser tabs, and AI built into the tools you already pay for. Most of it never looks like "AI traffic" on your network, so most of it is invisible.
You carry the legal risk for all of it.
Shows you what's actually in use. Which AI tools, on how many devices, and which third-party apps hold standing access to your Drive, Mail and SharePoint.
Keeps sensitive values from leaving. Names, IBANs, credentials and client references are replaced with tokens on the device, before the prompt goes anywhere — and restored in the answer. In development.
Hands your DPO the paperwork. Coverage reports, retention mapping, and AI Act Article 4 training records with certificates.
Four independent signals, each reported for exactly what it proves — never more:
| Signal | Answers |
|---|---|
| Installed software | Do they have it at all? |
| Running processes | Is someone working in it right now? |
| Live connections | What is this machine talking to? |
| Browser extension | What happened in a tab? |
No TLS interception. No keylogging. No screen capture. Not as a policy — as a design decision we can't quietly reverse.
Your raw data never reaches us. Not "we promise not to look" — there is no field in our event schema that can hold what anyone typed. Our CI fails the build if someone adds one.
We can't identify your employees. Identifiers are hashed with a salt you generate and keep. We never receive it. Re-identification is a join you perform, on your side.
We publish our own gaps. Every report shows what we can see versus what we can actually protect. Where we can't reach a tool, we say so and move on — rather than implying coverage we don't have.
Your people keep their tools. One setting, set once by IT. No new chat box to learn, no workflow to change.
In active development, running private pilots with EU companies. Discovery is live; on-device masking is in build behind a compatibility gate we won't sell ahead of.
Repositories here are private during the pilot phase. Public documentation will follow.
Colchix B.V. · Netherlands · EU-hosted infrastructure colchix.com