AI detection
Identifies confirmed AI service access through DNS hostname resolution, with optional SNI correlation.
AIGuard T1 is a passive sensor that detects AI usage on your network through DNS — the one signal that proves a person meant to use it. Built for the governments and non-profits that can't buy their way to visibility.
AI providers run on shared cloud infrastructure. A single Microsoft IP range carries Copilot, Teams, Outlook, and SharePoint at once — so flagging traffic by IP flags everything. The DNS query that precedes the connection is different: it names the service a user actually asked for.
"DNS proves intent. IP only proves a packet reached shared infrastructure."
Keys on destination IP ranges. Because providers share cloud infrastructure with general services, it produces false-positive rates above 96% — noise that can't support a compliance claim.
Keys on the resolved hostname. Each detection is evidence that a user or app intended to reach a specific AI service — an artifact you can defend in an audit.
Identifies confirmed AI service access through DNS hostname resolution, with optional SNI correlation.
Flags potential data-loss events in monitored traffic against patterns you define.
Maps activity to departments or units via VLAN mapping and Active Directory.
Executive, operational, and historical views with filters and CSV export.
Audience-specific DOCX reports for IT, Legal/Compliance, Records, and Executive readers.
Optional syslog integration with severity-based filtering for tools like Arctic Wolf.
Public agencies and non-profits carry real obligations to know what AI they run — under frameworks like the NIST AI RMF and, for public agencies, laws such as Texas's TRAIGA. Most can't afford enterprise tooling to meet them.
AIGuard T1 runs on a single repurposed workstation, carries no licensing cost, and is configurable by an IT generalist without writing code.
AIGuard reports confirmed AI access — not a complete inventory. It says so plainly.
Encrypted DNS, browser-embedded AI, and on-device models can leave no network signature. AIGuard is one tier of a layered approach, and an inventory that acknowledges its own limits is the only kind that corresponds to reality.