01 AI Security Workspace

The device boundary for enterprise AI work.

Secure AI Work.Without Slowing It Down.

Neurlect controls sensitive information movement through today’s human AI workflows—at the device boundary.

Local browser isolation. Safer document handling. Explainable controls.

Agent workflow controls are an architecture and expansion direction.

Request a Private Demo
  1. 01Workspace
  2. 02Policy
  3. 03Action
  4. 04Evidence
See the boundary in action
An employee working at a laptop with Dodam and the three-bar BI character beside her.
AI work, with room to move.Concept illustration
Device-boundary control Privacy-minimized evidence Today’s human AI workflows Agent controls · architecture direction

02 The operating reality

AI work should move fast. Sensitive information should not move without control.

AI work brings external websites and documents into everyday workflows. The same workflows send prompts, files, and sensitive details back out.

Keep risky content in a protected environment. Evaluate sensitive information against the customer’s policy before it moves to the next step.

Preserve the workflow.Govern the movement.

03 The Neurlect boundary

Control the boundary.
Preserve the workflow.

Neurlect places policy at the device boundary of the Neurlect-managed workspace. The workflow stays familiar while the boundary evaluates sensitive movement and applies an allowed, protected, or blocked action before the next step.

Dodam and BI examining a document inside a protective glass case.
Concept illustration · isolated inspection

Keep external content at a distance.

Local Browser Isolation (LBI) keeps managed web work inside a local isolation boundary. A safe viewer is designed to let people inspect supported documents within that protected workflow.

BI removing gear-shaped hazardous elements from a document while Dodam observes.
Concept illustration · document reconstruction

Preserve the useful work.

For supported document paths, content disarm and reconstruction (CDR) is designed to remove potentially hazardous elements and reconstruct a usable document. Inspection, reconstruction, viewing, and export remain distinct steps; supported formats and release scope are checked during the demo.

Architecture illustration · product control flow

  1. 01
    InputDocument or prompt

    Synthetic work enters a managed context.

  2. 02
    WorkspaceNeurlect-managed workspace

    The user keeps a familiar AI workflow.

  3. 03
    BoundaryDevice boundary policy

    The local host evaluates movement before the next step.

  4. 04
    ActionAllowed / Protected / Blocked

    The decision stays explicit and explainable.

  5. 05
    EvidenceLocal evidence relationship

    The ledger records only what the device can support.

One decision. An explainable next step.

See how a synthetic work item moves through the workspace, a device policy, an illustrative action, and a local evidence relationship.

This architecture illustration describes the control flow. It does not establish that every protection or transformation path is available.

Architecture illustration Synthetic workspace event
  1. Workspace
  2. Policy
  3. Action
  4. Evidence
Work context Strategy-notes.docx Synthetic fixture · 28 KB
Managed workspace Local host

Prompt draft

Summarize the launch assumptions in this internal strategy note.

Strategy-notes.docx
Device boundary Policy decision
Action Protected Sensitive detail minimized before the next step
AllowedProtectedBlocked
Local evidence relationship Confirmed relationship
Exact content

Synthetic document entered the managed workspace.

04 Connected controls

One workspace.
Protection with a defined scope.

01

Local browser isolation

A local boundary for Neurlect-managed web work, designed to separate external content from the everyday work environment.

Protected context
02

Safer document handling

Safe viewing and CDR address supported document paths. Inspection, reconstruction, viewing, and export remain distinct steps.

Inbound protection
03

Customer-defined classification

Customer-defined grades are intended to connect sensitive information to each customer’s controls. Customer-specific Block connections have been checked in synthetic workflows; end-to-end customer classification remains under validation.

Under validation
04

Masking & pseudonymization

Masking hides sensitive details. Pseudonymization replaces identifiers while preserving useful relationships within its defined scope. End-to-end customer pseudonymized transmission remains under validation: a policy permission to send does not establish that transformation or delivery occurred.

Under validation
05

Prompt Lineage

When an exact-content relationship is confirmed on the device, the local ledger records that connection. Otherwise, it reports relationship not established. Broader incident explanations remain under validation.

Exact-content foundation
An employee explaining personal, business, and confidential information with Dodam and BI.
Concept illustration · information categories

Your information.
Your classification context.

Personal details, business information, and confidential work need context. Customer-defined grades remain under validation; the illustrated symbols are not universal security levels.

05 Explainable by design

Connect the evidence
to the action.

Neurlect separates what the device confirmed from what it could not establish, and separates relationship status from evidence acquisition and ledger integrity.

The interface does not turn missing evidence into a clean bill of health.

  1. Observed information
  2. Inspection policy
  3. Decision & actual treatment
  4. Input delivery outcome
  5. Relationship & evidence state

The wider record linking inspection policy, actual treatment, and input delivery remains under validation.

An input-delivery result is not proof that an AI service received it. For supported output, a recovered watermark can provide an investigation candidate; it is not proof of attribution.

Axis A

Relationship status

Confirmed relationship

An exact-content relationship was confirmed on the device.

Relationship not established

The product did not establish the relationship. This does not mean no relationship exists.

Axis B

Acquisition & ledger integrity

Evidence unavailable

Required comparison material was not acquired.

Ledger gap detected

A recording loss, damage, or completeness issue was detected and disclosed.

These are separate axes, not four levels of certainty.

06 People now. Agents next.

Built for today’s AI users.
Architected for tomorrow’s AI agents.

Product foundation

  • Secure AI workspace
  • Device-boundary policy enforcement
  • Local evidence foundation
  • Exact-content Prompt Lineage foundation

Architecture direction

  • Agent identity
  • Tool-use lineage
  • Approval binding
  • Agent egress controls

Agent controls are an architecture and expansion direction, not a representation of complete Agent Security functionality.

07 Privacy-minimized evidence

Evidence without building another sensitive-data repository.

Neurlect’s architecture is designed to keep detailed content references and verification material in the customer environment while exposing privacy-minimized states and event relationships to management surfaces.

Architecture principle · management-plane coverage under validation
Customer environment Detailed verification
  • Content references
  • Local ledger
  • Verification material
Minimized projection Closed states · event relationships
Management surfaces Operational evidence
  • Relationship state
  • Integrity state
  • Policy action

Management-plane coverage is being validated across requests, storage, responses, and logs. This principle is scoped to evidence architecture and is not a universal statement about all device data flows.

08 Controlled environments

Designed for enterprises where evidence has to be as disciplined as enforcement.

Neurlect is designed for regulated and sensitive environments across financial services, public sector, research, and enterprise operations.

Product foundation
Local isolation, device-boundary checks, document protection, and exact-content evidence within the Neurlect-managed workspace. Verify the supported paths in a private demo.
Under validation
Customer-specific Block connections have been checked in synthetic workflows. Pseudonymized allowed transmission, full IdP coverage, industry-specific integrations, and broader incident explanations remain under validation.
Architecture direction
Agent identity, tool-use lineage, approval binding, and agent egress controls are expansion directions.
01Device-hosted enforcement

Policy stays anchored to the customer’s device boundary.

02Customer-controlled detail

Detailed evidence remains under the customer’s control.

03Explicit uncertainty

Relationship and ledger health never collapse into one claim.

04Architecture direction

Today’s human AI workflows establish a possible foundation for future governed agent actions.

09 Private demo

See Neurlect on your AI workflow.

Request a private walkthrough of the workspace, device-boundary policy, and evidence model. We will use a synthetic workflow, not your sensitive data.

Request a Private Demo