AI security · Zürich

Use AI without its blind spots.

Every AI, every agent, every data flow in and out of AI, visible and under your policies, on your infrastructure with Blindsight.

  • ETH AI Center
  • ATHENEUP26 finalist
  • CF Accelerator
  • Sovereign Mind

What AI risk actually looks like.

  • Data leaves through a prompt.

    An employee pastes a client contract into ChatGPT to summarize it. The contract is now outside your company.

  • An attack hidden in a document.

    Your AI agent reads a supplier invoice with an instruction hidden in the text. It follows it and emails out customer data.

  • A poisoned source.

    Someone edits a page in your internal knowledge base. Your AI assistant now gives employees the attacker's answer.

  • Unregistered AI accessing sensitive data.

    A sales rep connects an AI assistant to the CRM with their own login. It can read every customer record, and security doesn't know it exists.

See it, secure it, govern it.

Find every AI in use, approved or not.

Blindsight maps the AI tools your people use and the AI systems your teams build, giving you an overview of your true AI inventory and giving you control over what is approved, protected, blocked, or fully onboarded.

  • +3 already on record
  • chatgpt.com · personal account, ws-fin-01Flagged
  • agent:finance · running on ws-fin-01Flagged

One console, from first finding to audit evidence.

The four views a security team works in once Blindsight is running. Switch between them; the data is illustrative.

acme-ag inventoryzrh-1 · on-premIllustrative walkthrough
Inventory
128 AI systems · 1 awaiting decision · last scan 14:32:07
crm-assistantConnector · OAuthCRM · all records1
chatgpt.comWeb tool · browserClient contracts41Protected
agent:financeAgent · SDKERP · finance mailsvcOnboarded
kb-assistantRAG app · proxykb · 1,240 pages380Onboarded
n8n · invoicesAutomation · localSharePoint · mail3Approved
copilot · M365Assistant · M365M365 tenant212Approved
flow · hr-digestAutomation · M365HR files2Protected
deepl.comWeb tool · desktopContracts, letters27Protected
notes-extensionExtension · browserCall audio6Blocked
agent:supportAgent · proxyTickets · orderssvcOnboarded
Showing 10 of 128Decide once · Blindsight enforces it everywhere

Every AI in use, approved or not.

Deploy on your terms in no time.

Runs on

  • On-prem
  • Private cloud
  • Blindsight cloud

Detection runs on our own models, inside the deployment. No prompt, file or finding is sent to a third-party LLM.

Inside your environment, your people reach AI tools through the endpoint agent, and your AI systems reach their models and tools through the SDK or proxy. Both surfaces feed one Blindsight detection layer that runs on local models.

Your peoplelaptops · browser · desktop apps
prompts · uploads
Your AI systemsagents · RAG apps · n8n
prompts · retrievals · tool calls
Surface A: Endpoint agentOn every laptop. Pseudonymizes sensitive data before it leaves and shields people from prompt injection and poisoning.
Blindsightdetection on local models
Surface B: SDK or proxyOne line of SDK, or point traffic at the proxy.
pseudonymized
AI toolsChatGPT · Copilot · DeepL
inspected at runtime
Models & toolsLLM APIs · MCP · actions

Step by step

  1. 01

    Install.

    The endpoint agent rolls out through your existing device management. The SDK is a single change on the AI systems you build.

    Works withIntuneJamfGPOSCCM

  2. 02

    Discover.

    Blindsight maps AI use and risk across your organization. Nothing is blocked, nothing changes for your people.

  3. 03

    Govern.

    Enforce your policies and controls, mitigate your findings and risk, and let your people keep using AI, safely.

See what AI is doing in your organization.