redSec
The redbtn security suite

Every prompt is an exit.
redSec watches the door.

Your team runs on AI now. redSec is the layer that catches sensitive data the moment it heads for a chatbot — and blocks it, redacts it, or logs it, on your terms.

The suite

Catch it. Clean it. Watch it.

Two of the three ship today. redDLP guards the endpoint, redAct makes redaction something you can call, and redEye is coming to keep watch over both.

01  /  endpoint

redDLP

Data loss prevention for the AI era.

An endpoint agent and a console. It inspects what your people paste into ChatGPT, Claude, Copilot and the rest — on the device, before it is sent — and stops the records, secrets and keys, while ordinary work goes straight through.

  • On-device detection
  • Block, redact, observe
  • Fail-closed by design
  • Metadata-only audit
  • Per-organization policy
  • Fleet in one console
02  /  api

redAct

Redaction, as an API.

Point any text or document at redAct and get it back clean. Names, emails, SSNs, medical record numbers — found by a detection engine you tune with your own patterns and profiles, and it never keeps what it reads.

  • Text & document redaction
  • Custom patterns & profiles
  • Org-scoped API keys
  • Types-and-counts logging
  • Presidio-grade detectors
  • Self-host or hosted
Coming soon
03  /  agentic

redEye

Agents that watch what your AI is doing.

redEye puts autonomous agents on your security surface. They watch the egress, the redactions, the sign-ins and the alerts across redSec, chase down what looks wrong, and bring you the story instead of the raw feed.

  • Autonomous investigation
  • Cross-product signal
  • Anomaly detection
  • Plain-language findings
  • Always-on watch
  • Built for the suite
In development, part of redSec
The posture

Built so the safe thing is the default thing.

Four decisions shape everything redSec does. They are the reason security teams can hand AI to their people without holding their breath.

on-device

Detection runs where you type

Prompt text is inspected on the endpoint before it is sent. It is never shipped to a cloud service to be scanned.

fail-closed

Off means stopped, not open

If protection cannot run, data does not move. The failure mode is a closed door, not a quiet bypass.

metadata-only

The log keeps counts, not contents

An audit record says what kind of data was found and how much — never the sensitive values themselves.

org-scoped

Everything belongs to one org

Every device, key and event is bound to a single organization and isolated from every other tenant.

Let your team use AI.
Keep what matters off it.

Start with the console, or wire redaction straight into your own stack. Two products today, a third on the way.