Your gateway sees AI tools only as domains. You should see the tools, the people and the prompts — iboss AI Security Platform finds the AI apps your staff use, who uses them and what they ask, from an agent that sits beside your current SASE — visibility free, enforcement paid.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers iboss AI Security Platform — the standalone AI-usage product with a free visibility tier. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
Seeing which AI apps staff use and what they share, then setting rules per tool, person and data type.
What consolidation actually replaces, dimension by dimension.
| Dimension | Domain blocks and guesswork | iboss AI Security Platform |
|---|---|---|
| Which AI tools are in use | A guess from gateway domain logs | An inventory, each tool given a risk class |
| Who is using them | An IP address, if anything | Per-user attribution |
| What was typed | Invisible once the session opens | Prompt and response history |
| An unapproved assistant | Block the domain and hope | Redirect to the approved tool (paid) |
| Getting started | Swap the SASE to gain AI control | An agent beside the stack you have |
| What it is NOT | — | A web gateway, CASB or ZTNA on its own |
The cheapest test costs nothing: a week of the free tier on one team shows which AI tools are in use and what is being typed into them.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Installed on Windows and Mac endpoints, per the launch release, it sees AI app sessions without editing or relying on system proxy settings, so the gateway you run keeps working.
Every AI tool found is listed with a risk classification and tied to the person using it, giving a named register of sanctioned and shadow AI rather than a list of domains.
Paid tiers add allow, block and redirect actions, tenant restrictions, connection rules for AI agents, and DLP set by user, group, tool or risk, according to iboss.
The same deployment upgrades in place to the full iboss platform, which adds a cloud web gateway, CASB, ZTNA and broader DLP for teams that later want one vendor for both jobs.
An endpoint agent beside your gateway — AI tools found and risk-ranked free, then allowed, blocked or redirected on paid tiers.
The iboss AI Security Platform shows and governs staff use of AI apps without replacing the gateway you already run.
The free tier discovers the AI apps staff actually open, from chatbots to coding assistants such as Cursor, per iboss’s launch release.
Each discovered tool lands in an AI inventory with a risk classification, so approval decisions start from a ranked list, not a hunch.
Activity is attributed per user, which lets a review name the team behind heavy use of an unapproved tool rather than an IP address.
Paid tiers can allow a tool, block it, or send people on to the approved one, and apply tenant restrictions to sanctioned AI services.
Data-leak prevention rules are set by user, group, tool or risk level, so a rule written for source code need not hit the marketing team.
Connection policies limit what AI agents may reach, a paid control iboss lists beside prompt-level data rules in its launch material.
Prompt and response history is part of the free tier per the release, so a reviewer can see what was asked and what the tool returned.
Paid tiers add full prompt and response capture with an audit trail, the record a compliance team asks for after an incident.
iboss’s AI security page extends coverage to Copilot and the AI assistants built into Excel and Word, not only chatbots in a browser.
AI Chat Security, the capability behind the AI Security Platform: a module overview and a full monitoring demo, both from iboss’s official channel in January 2026, before the standalone launch.
AI Chat Security, the capability behind the AI Security Platform, shown as a module of the iboss SASE platform before the July 2026 standalone launch.
A full walk-through of AI Chat Security monitoring, the capability behind the AI Security Platform, recorded before it was sold on its own.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Most AI-control products arrive inside a SASE or a browser you must adopt first. iboss built this one to sit beside any SASE, SSE or web security product: its agent neither changes nor depends on system proxy settings, and iboss says it deploys in an afternoon. Your traffic path stays as it is.
According to iboss’s launch release, the free tier covers shadow-AI discovery, an AI inventory with risk classes, per-user attribution and prompt and response history. A security team can measure its real AI exposure, and build the case for enforcement, before any money changes hands.
Paid tiers turn the inventory into policy: allow, block or redirect per tool, tenant restrictions, connection rules for AI agents, and DLP set by user, group, tool or risk. Copilot and the assistants inside Excel and Word are covered as well, per iboss’s AI security page, not just browser chatbots.
It only launched in July 2026. The paid tiers carry no public price, no customer or analyst assessment is published, and the launch release names only Windows and macOS for the agent. iboss documents neither a storage location nor a retention period for prompt history, Indian or otherwise.
Deploy the agent to one department’s Windows and Mac machines, leaving the current SASE and proxy settings untouched.
Rank the AI tools found by risk class and user count, then agree with legal which are sanctioned and where others redirect.
Get the paid-tier quote, switch on redirects and DLP for a pilot group, and log every false positive for a fortnight.
Turn on full prompt capture for regulated teams, walk the audit trail with compliance, and settle where that data is stored.
Extend the agent across the fleet, or decide whether an in-place move to iboss Zero Trust SASE is worth a quote.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“We left our SSE alone and put the agent on finance laptops. The free inventory showed Cursor and Perplexity in daily use.”
“Prompt history showed a sales team pasting customer lists into a chatbot. That one report paid for the enforcement tier.”
“Blocking felt blunt, so we redirect people from an unapproved assistant to our own Copilot tenant instead. Complaints stopped.”
“Copilot inside Excel was our blind spot. The agent picked those sessions up alongside the browser chatbots we expected.”
“There is no public price for the paid tier, and the quote for 400 users took longer than the free pilot itself.”
“Our developers run Linux, and the launch material names only Windows and macOS, so we had to ask iboss what covers them.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the AI usage security market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Free visibility tier; paid tiers quoted.
The grid nobody publishes — how freely it sits beside the network and browser you already run vs how deeply it governs AI prompts and data.
Beside any SASE; enforcement on paid tiers.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Akamai Workforce Protector, Netskope Data Protection, Palo Alto Prisma Access Browser, Sophos Workspace Protection and Chrome Enterprise Premium — on deployment, AI coverage, prompt visibility, enforcement, price, India and exit.
| Dimension | iboss AI Security Platform | Akamai Workforce Protector | Netskope Data Protection | Palo Alto Prisma Access Browser | Sophos Workspace Protection | Chrome Enterprise Premium |
|---|---|---|---|---|---|---|
| What it is | Standalone AI control | Browser extension for AI | Module of Netskope One | Enterprise work browser | Browser-led bundle | Paid tier of Chrome |
| Deployment | Endpoint agent | Extension + console | Client into NewEdge | Browser, extension, app | Browser plus agents | Chrome policy |
| Beside an existing SASE | Designed to coexist | Network-neutral | Needs Netskope One | Alone or with SASE | Bundle, no proxy | Any network stack |
| AI apps covered | Six named, dozens more | Web, browser, desktop | GenAI via SkopeAI | GenAI in its browser | Approved vs the rest | AI sites in Chrome |
| Shadow-AI discovery | Free, risk-classed | Found and risk-scored | Tenant-aware | Assessment on offer | Shadow IT and AI | Shadow AI view |
| Prompt visibility | History free; audit paid | Live prompts and replies | Guardrails on prompts | Prompt redaction | Not described | Evidence locker |
| Enforcement and DLP | Paid tiers only | Typing, paste, files | One DLP engine | 1,000+ classifiers | Upload and clipboard | Paste, upload, print |
| Pricing model | Free tier, then quote | Quote; unit unstated | Per user, in platform | Per user, quoted | One per-user count | Per user per month |
| Published entry price | Free visibility tier | Not published | Not published | Not published | Not published | $6/user/month |
| Included vs add-on | Only visibility is free | Browser layer only | Inside Netskope One | Shared Palo Alto engines | Four controls in one | Core free, Premium paid |
| Integrations | Not itemised | IdP, SIEM, MDM, tickets | One Zero Trust Engine | SAML, OIDC, Prisma | Sophos Central | Open Connector Framework |
| India data location | AI data region unstated | Not documented | Eight Indian DCs | PoP; console unstated | India Central for DNS | Not published |
| Lock-in and exit | Uninstall the agent | Remove the extension | Moves with Netskope One | Browser to switch back | ZTNA leaves with it | Chrome keeps running |
| Best fit | Free AI baseline | AI control, any browser | Netskope One customers | Prisma SASE estates | Sophos-first firms | Chrome-only estates |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
TechBag has no AI usage security guide yet, so iboss AI Security Platform sits outside the category guides. Browse all products to compare it with the rest of the catalogue. →
Drag the sliders (staff who use AI tools; compliance-team hour cost). Estimates model the review time spent working out which AI tools are in use, what data went into them and answering auditors about it, at an assumed 1.5 hours per staff member a year, with 70% of it saved by an automatic inventory and prompt history. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Free to start: iboss’s 1 July 2026 launch release makes shadow-AI discovery, the risk-classed AI inventory, per-user attribution and prompt history free. Enforcement, DLP, tenant restrictions, AI-agent rules and full capture are paid, and iboss publishes no price or licence unit for them. TechBag runs the free tier first, then gets the paid quote in INR with GST.
Best for a shadow-AI baseline
Best for a broader rollout
Best for regulated teams
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Which devices run Windows or macOS, the platforms the launch release names, and what covers Linux or mobile users?
Which SASE, SSE or gateway stays in place, and has a pilot shown the agent working beside it without conflict?
Which AI tools are sanctioned, where should the rest redirect, and which data classes are banned from prompts?
Is Copilot inside Excel and Word in scope, and does the pilot show those sessions as well as browser chatbots?
Where are prompt and response histories stored, and who at iboss and in your team can read them? Get it in writing.
Which needs — redirects, DLP, tenant restrictions, agent rules, full capture — force a paid tier, and at what unit?
Can the record of AI use be kept as long as your auditors need, or should it be streamed to your SIEM instead?
What are the licence unit and term for the paid tiers? Ask for the quote in INR with GST before the pilot ends.
Start with the free tier to see your real AI use, or let a TechBag advisor run the pilot beside your current SASE and price the paid controls.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.