We block it. ZDZAIShield is a DLP with local AI that inspects every prompt and stops CPF and CNPJ numbers, cards, passwords, and secrets from reaching public AIs — with an HTTP 403, before the data leaves your network.
It is not an attack. It is routine. Every day, well-meaning people paste customer data into a public AI to "speed things up" — and the data leaves your network without passing through any control.
"Summarize this record for me." A CPF, a CNPJ, an entire contract pasted into a text box that sends everything to third-party servers, outside the country.
"Why doesn't this code run?" — and along go API keys, passwords, and connection strings. What was a bug becomes corporate secret exposure.
Medical records, reports, financial and legal data. Categories the LGPD treats as sensitive (art. 11) leaving without a legal basis, without a trail, without consent.
Blocking public AI at the firewall does not work: people use their phone, their personal account, the next tool. What is missing is inspecting the content of what goes out — and deciding, in real time, what is allowed and what is not.
ZDZAIShield sits in the path between your network and the public AIs. It inspects each prompt in two layers and, if sensitive data is found, returns an HTTP 403 — the request never reaches the external provider.
Every prompt bound for a public AI goes through the proxy before leaving the network. ChatGPT, Gemini, Claude, Copilot, DeepSeek, Perplexity, HuggingFace — 7 services covered.
→Known patterns (CPF, CNPJ, cards, keys) are caught by regex. Whatever slips through goes to NLP sensitivity classification on a local LLM.
→If the content is classified as sensitive, the proxy blocks it with an HTTP 403 and explains why. The data does not leave. Clean prompts go through normally.
→Every block becomes an auditable event: what was stopped, to which service, when. Governance to prove compliance, not just promise it.
NLP classification runs on a local LLM via Ollama — the inspection of your data is never outsourced to the cloud.
See what happens when someone pastes personal data into a prompt bound for a public AI.
(illustrative example · fictitious, masked CPF · values do not represent real customer data)
A DLP that ships your content to the cloud for "analysis" recreates the very problem it is supposed to solve. ZDZAIShield runs the classification LLM inside your network, with Ollama. Private inference, isolated per client.
Compliance is not a PDF in a drawer. ZDZAIShield turns your AI usage policy into a technical control that acts on its own — and leaves a trail.
The rule of "never paste customer data into a public AI" stops depending on training and goodwill: it is enforced in real time, on the way out.
Every attempt and every block is logged: which data category, to which service, when. The DPO gets evidence of compliance, not assumptions.
Directly addresses the processing of sensitive categories — including health data — preventing them from leaving the network without a legal basis.
A risk assessment to map where your team uses public AI, what kind of data is exposed, and how ZDZAIShield closes that door. AI + People: the machine blocks, your governance decides.