The AI reads it. Never sees it.

Privacy for
the AI era.

Argos · by FluidPrism · a transparent proxy on every device START A PILOT →
What the model sees
scanning as you type
Your prompt · edit it
through the Argos proxy · forwarded to the LLM
0 findings · k-anonymity · risk 0/100 PASS
Monitors 16 endpoints
OpenAI · Anthropic · Gemini · Mistral · Cohere · Groq · Together · Perplexity · OpenRouter · Bedrock · Azure · Vertex · HuggingFace · Replicate · DeepSeek · xAI
What Argos does, plainly

Your team keeps using ChatGPT, Claude, Copilot and Gemini. Argos swaps the sensitive values for safe placeholders on the way out, and puts the real ones back on the way in. The model does its work. Your data stays yours.

One roundtrip: tokenize, shield, forward, rehydrate.

The proxy rewrites sensitive bytes before they leave the box and restores them in the response, so your users never notice. Here is the whole trip.
01 · Tokenize

Every detected span (names, IDs, keys, medical codes) is swapped for a stable placeholder before anything leaves the device.

02 · Shield

Sensitive figures (revenue, headcount and other business numbers) are protected before anything leaves the device. The model still does useful work; the real figures stay home.

03 · Forward

The tokenized payload travels to the model over the normal wire. To the AI it is an ordinary, fully readable prompt.

04 · Rehydrate

The response comes back and placeholders are restored to the real values. Your team never notices the trip.

Regex catches the obvious. K-anonymity catches the rest.

Detection runs end-to-end in under 50ms. Nothing is sent off-device for analysis: every layer ships with the agent.
Layer 01
Pattern matching
SSN, credit card, IBAN, ICD-10, API keys, JWT, private keys, DB connection strings, emails. Deterministic, sub-millisecond.
Layer 02
Semantic detection
AI-based detection for personal names, medical conditions, minors and special categories that escape simple pattern matching.
Layer 03 · K-anonymity
The combination attack. Where pattern matching stops, re-identification analysis begins.

"John Smith" is safe. "94304" is safe. "1987-03-12" is safe. Put them in one prompt and 87% of the US population is uniquely identifiable. Argos models re-identification risk using k-anonymity and HIPAA Safe Harbor principles, and blocks the dangerous combinations that pattern matching alone misses.

# prompt: "patient John Smith, DOB 1987-03-12, ZIP 94304, ICD F32.1"
findings: 4 · re-identification risk: HIGH
combination: name + DOB + ZIP + diagnosis
verdict: CRITICAL → action: BLOCK
Always
Metadata only
The central reporter sends counts, scores and labels, never raw findings. The PII string never crosses the network.
Both ways
Response-side scan
Models hallucinate emails and paraphrase names. Argos independently rescans the model's output and logs it as a separate model-generated PII event.
0
LLM endpoints monitored
OpenAI, Anthropic, Gemini, Mistral, Cohere, Groq and 10 more.
0
Detection layers
Pattern matching, then semantic detection, then k-anonymity.
0ms
P50 detection latency
Optimized pipeline engineered for imperceptible overhead.
0
Regulations tracked
GDPR, HIPAA, PCI-DSS, SOC2, CCPA, FERPA.

Sentinel: the executive view

OPEN PORTAL →
Every installation includes Sentinel. It aggregates anonymized metadata from every reporting agent: org-wide visibility with zero raw data exposure. Seven views, from fleet overview to board-ready compliance reports.
01
Org Overview
Total scans, devices, blocked, redacted, risk distribution, 7-day trend.
02
Device Browser
Per-device peak risk, blocked count, last seen, sortable across every agent.
03
Departments
Engineering vs. Sales vs. Data Science: where the leaks live.
04
Org-wide Scan Log
Every intercepted request with domain, model, regulations, action.
05
Network Monitoring
Outbound traffic, alert rules, flagged events, SMTP notifications.
06
Executive Report
Board-ready compliance posture, key findings, recommendations.
07
Server Settings
Ingest keys, retention, digest email, agent install commands.
Runs client-side. The demo portal runs entirely in the browser against realistic demo data.
sentinel · org overview
ARGOS SENTINEL
44 online · 3 stale
Acme Corporation
Account ciso@acme.com
Total scans
0
Blocked
0
Critical
0
Findings
0
Redacted
0
Posture
0/100
Risk distribution
Critical373
High1,475
Medium2,946
Low5,011
14:32 · judy · Engineering · api.openai.com · REDACTED · GDPR · PCI-DSS
14:29 · alice · Data Science · api.anthropic.com · PASSED · none
14:21 · carol · Product · api.cohere.ai · REDACTED · GDPR
DeviceDeptScansPeakBlocked
macOS-leo
leo@acme.com
Sales611798
Ubuntu-elena
elena@acme.com
Sales573778
macOS-olivia
olivia@acme.com
Marketing540864
macOS-judy
judy@acme.com
Engineering5349611
Windows-walter
walter@acme.com
Product532817
Windows-niaj
niaj@acme.com
Engineering5068412
TeamScansCriticalRisk
Engineering
18 devices · 18 users
5,40013185
Product
8 devices · 8 users
2,9395682
Data Science
11 devices · 11 users
2,83510086
Marketing
6 devices · 6 users
1,9335291
Sales
4 devices · 4 users
1,6253488
UserDomainLLMRiskAction
zane@acme.comapi.perplexity.aigemini-pro99BLOCK
mallory@acme.comapi.cohere.aigpt-3.5-turbo79REDACT
xavier@acme.comapi.anthropic.comclaude-3-opus62REDACT
diana@acme.comapi.perplexity.aigemini-pro59WARN
erin@acme.comapi.cohere.aigpt-4-turbo49WARN
ravi@acme.comapi.anthropic.comgpt-429LOG
elena@acme.comapi.together.xyzgpt-4-turbo0LOG
Events (24h)
44
Volume out
67.9 MB
Flagged
5
Traffic by category
LLM API14
Telemetry12
Unknown SaaS8
Dev Tools7
File Upload3
Flagged events
walter@acme.com → wetransfer.com
FILE UPLOAD · 12.1 MB · dev-019
2d ago
elena@acme.com → wetransfer.com
FILE UPLOAD · 21.9 MB · dev-028
3d ago
zoe@acme.com → cdn.synthhub.io
UNKNOWN SAAS · 296.1 KB · dev-046
3d ago
Executive Security Summary
Weekly summary · Apr 11–17, 2026 · Acme Corporation · 47 devices
ELEVATED
14,732 SCANS339 BLOCKED373 CRITICAL4,420 FINDINGSGDPR · HIPAA · PCI-DSS
Key findings
Engineering leads critical incident count · 131 critical detections (35% of total)
474 HIPAA triggers across org · all redacted or blocked by the agent
112 k-anonymity violations · below the org-wide k=5 threshold
Department risk breakdown
Marketing91/100
Sales88/100
Data Science86/100
Engineering85/100
Organization
Organization nameAcme Corporation
Ingest URLhttps://argos.acme.com/api/ingest
Agent retention90 days
Global policies
Block CRITICAL everywhere · Override agent enforcementON
Require minimum k-anonymity · k ≥ 5 org-wideON
Weekly email digest · To ciso@acme.comOFF
Superusers
ciso@acme.com · Admin · youOWNER
security@acme.com · Admin · added Mar 12REMOVE
compliance@acme.com · Viewer · added Jan 15REMOVE
OPEN THE LIVE PORTAL →

Every endpoint treated like a target.

Argos ships with the OWASP API Top-10 mitigations the average self-hosted security tool quietly ignores.
Adaptive rate limiting

Per-IP and per-identity controls on every API surface. Ingest, dashboard, login and admin each enforce separate thresholds automatically.

Strict input validation

Every request is gated by a strict schema that rejects unexpected fields. Errors never echo raw input back to the caller.

Hashed token storage

Authentication tokens are stored only as cryptographic hashes. A database leak exposes nothing usable.

Hardened session management

Auth cookies are inaccessible to client-side scripts, auto-secured, and rotated on privilege changes.

Start with
a conversation.
A 30-minute call, then a two-week pilot with one team. contact@fluidprism.com ARGOS · MMXXVI