ZEROSHIELD / AI DATA SECURITY POSTURE

See every path from AI to sensitive data.

Discover agents, models and MCP tools. Trace their access to enterprise data, then investigate scoped remediation with evidence in view.

Demo workspace · synthetic data · no live connections

ZEROSHIELD / PRODUCT WALKTHROUGH00:54 · SAMPLE DATA
Nine views · synthetic demo workspace

EXPLORE THE WORKSPACE

A closer look, one chapter at a time.

Five interactive chapters · sample data

INTERACTIVE TOUR · SAMPLE DATA

CHAPTER 01 / 05

Discover AI estate

01

Support assistant

Agentic application

observed activeapproved
02

Bedrock model route

Managed AI service

configuredapproved
03

Coding assistant on dev laptop

Coding assistant

installedpending review
04

export_cases MCP server

MCP server & tool

configuredpending review
05

Direct SDK call in repository

Direct model call

candidateunknown
06

Workspace AI feature

AI-enabled SaaS

unknownunknown

Find the AI assets and sources behind each signal.

Open this view

THE CONNECTED ESTATE

One map. From source to sensitive data.

Bring signals from where AI is built, deployed and used into an evidence-aware view of identities, access and data. The diagram shows product scope, not active connections.

01 / SIGNAL SOURCES

Code & build

GitHubAzure Repos

Cloud & data

AWSGoogle CloudSnowflake

Identity & usage

Entra IDGoogle WorkspaceOpenAI

ZeroShield

Evidence-aware security posture

01Discovery & classification
02Identity & effective access
03Relationship graph
04Evidence freshness & policy
05Scoped decisions & audit

02 / INVESTIGATION SURFACES

AI apps & agents

Ownership · activity

MCP tools & models

Bindings · routes

Sensitive datasets

Classification · reach

Findings & decisions

Evidence · status

Illustrative relationships · sample connectors, not a live customer estate.

Explore integration previews

THE INVESTIGATION, END TO END

Each question leads to evidence.

01 / Shadow AI discovery

Find what the inventory missed.

Compare repository, device, SaaS and cloud signals without mistaking installation for use.

Learn more about shadow ai discovery
Shadow AI discoverySAMPLE VIEW

Direct SDK

Candidate

Workspace AI

Unknown use

Model route

Configured

Demo workspace · open a detailed view to investigate

02 / Access intelligence

See the path behind the permission.

Follow identities through agents and tools to the sensitive data they may reach.

Learn more about access intelligence
Access intelligenceSAMPLE VIEW

Identity

svc-support-prod

Agent

Support Copilot

Tool

Shared RAG

Data

Payroll · restricted

Indexed grant exceeds source ACL · review path

Demo workspace · open a detailed view to investigate

03 / Code to cloud

Know what actually reached production.

Connect a repository to builds, artifacts and running workloads with confidence at each hop.

Learn more about code to cloud
Code to cloudSAMPLE VIEW
Repositorysupport-assistant · commit 8f3a7c01
BuildCI #218 · provenance declared02
Artifactsha256:demo21803
Workloadsupport-api · snapshot observed04

Demo workspace · open a detailed view to investigate

04 / Data lifecycle

Protect the data behind the answer.

Connect classification, retrieval indexes and model inputs to the original source and its controls.

Learn more about data lifecycle
Data lifecycleSAMPLE VIEW

Restricted HR source

Source ACL · revision 12

Derived RAG chunks

ACL mapping · unknown

Demo workspace · open a detailed view to investigate

05 / MCP & agent security

Bound every tool an agent can call.

Review offered tools, service identities and downstream grants before approving a connection.

Learn more about mcp & agent security
MCP & agent securitySAMPLE VIEW
TOOLPERMISSIONREVIEW
export_casesRead exportUnknown
ticket-searchRead ticketsPurpose-bound
postgres-queryRead / writeReview scope

Demo workspace · open a detailed view to investigate

06 / AI lifecycle

Carry evidence through every stage.

Keep acquisition, development, evaluation, release, runtime and retirement decisions together.

Learn more about ai lifecycle
AI lifecycleSAMPLE VIEW
01

Acquire

Evidence tracked

02

Develop

Evidence tracked

03

Evaluate

Evidence tracked

04

Release

Blocked · review

05

Runtime

Evidence tracked

06

Retire

Receipt pending

Demo workspace · open a detailed view to investigate

07 / Controlled remediation

Preview the change before the change.

Scope an action, review authority and verify the result before calling a finding closed.

Learn more about controlled remediation
Controlled remediationSAMPLE VIEW
BEFORE

3 shards serving · stale chunk ACL

AFTER / PARTIAL

2 resynced · shard 3 unchanged

Receipt rcpt-a724 · precondition failed · retest pending

Demo workspace · open a detailed view to investigate

INTEGRATION ECOSYSTEM

Start with the systems that matter.

Explore sample sources and preview additional connections across the AI stack.

Browse setup previews

GitHub

Sample data

AWS

Sample data

Bedrock

Sample data

OpenAI

Sample data

PostgreSQL

Preview

Snowflake

Preview

Zendesk

Sample data

Google Cloud

Preview

Entra ID

Preview

Splunk

Preview

Sample records and guided previews are separate from connected services.

RUNTIME EXAMPLE / OBSERVABILITY

See where a request spends its time.

A trace explains request behavior. Collection freshness explains how recently posture evidence was updated. They are not the same metric.

Agent trace waterfall

SYNTHETIC · 1.28 s
SPAN
0 ms4008001,200 ms
Prompt received
38 ms
Retrieve context
412 ms
MCP tool check
240 ms
Model response
563 ms
Output policy
168 ms

Example trace, not collected telemetry. Segment positions are illustrative.

REQUEST LATENCY

p50

420 ms

p95

1.28 s

Synthetic runtime example · not a service-level claim

USAGE / ESTIMATE

12 requests · 8.4K input / 3.1K output tokens

Estimated cost: $0.07 · sample rates only

GPU: N/A for hosted model · self-hosted example: 62% utilization

EVIDENCE FRESHNESS

14 min sample collection lag

A stale collector does not imply a slow request or a clean source.

EXPORT TARGETS / PLANNED

OpenTelemetryGrafanaDatadogPrometheus

Format/export configuration is planned; no telemetry stream is connected.

Learn more about observability

GOVERNANCE / EXPLAINABLE DECISIONS

Keep a record worth reviewing.

Connect decisions to their actor, scope and evidence. Framework mapping helps organize review; it does not establish certification or legal compliance.

SAMPLE AUDIT TIMELINE

02:05Scan receiptcollector-eu-03 · sample resourceRecorded
03:12Index quarantineremediation-service · sample resourcePartial
08:05Release manifestrelease-service · sample resourceRecorded

Append-only audit storage, durable signatures and retention are target architecture, not implemented by this preview.

TEAM / ROLE / SCOPE

TEAMROLESCOPE
Platform IAMReviewerRead evidence
SupportOwnerSupport assets
SecurityApproverScoped action

CONTROL MAPPING / REFERENCE

SOC 2 topicsHIPAA safeguardsGDPR principles

Mapping is an organizational aid, not a claim of certification or compliance.

Learn more about governance

REFERENCE DEPLOYMENT TOPOLOGY

A boundary you can define.

A planned design for private cloud, VPC, on-premises and isolated environments. The hosted preview is not air-gapped and does not promise no egress.

CUSTOMER-CONTROLLED BOUNDARY / PLANNEDPrivate cloud · VPC · on-prem · isolated
01

Local collectors

Read-only scoped signals

02

Policy engine

Classification & access

03

Approval gate

Human-scoped actions

04

Audit component

Retention & export design

Explicit egress policy and offline bundle exchange belong to deployment design and validation—not to this frontend.
Learn more about deployment options

EXPLORE THE WORKSPACE

Follow a path. Question the evidence.

Start with an illustrative AI asset and trace it through access, findings and reviewable actions.

Open sample console