Control AI data egress with policy before execution
Vayon AI applies identity, sensitivity and egress policy before external model execution, keeps sensitive context internal when policy requires it, and turns governed activity into safe, reviewable evidence.
Govern. Route. Audit.
What is checked before a model runs
Identity, sensitivity and policy are evaluated before any model runs; blocked requests can stop before execution.
Security ships in VAYON Core
Every control on this page — policy before execution, sensitivity classification, authorization, context-egress governance, output guardrails, SIEM connectivity, compliance evidence, and the Central Log and Content Audit records — is part of VAYON Core, licensed once per customer organization. The Endpoint AI Governance extension carries the same governance toward managed browsers and endpoints; it extends these Core controls, it does not unlock them.
Context-egress governance
External execution is permitted only after applicable policy and context-egress gates pass.
What the browser client covers — and what it does not
On a managed browser, text and attachments heading for listed AI services are checked before they leave. Files are read on the server — CSV, Excel, Word, PDF — so nothing needs installing on the workstation, and a file that cannot be read is refused rather than waved through. Deployment starts in observe mode, recording what would have happened without blocking anything. A personal device, an unmanaged browser, or a service outside the configured list stays outside this control. The managed-browser client is delivered by the Endpoint AI Governance extension and applies the same Core policy decisions at the endpoint.
A managed, configured browser preflights a supported AI service to Vayon AI. The server makes the decision; the client carries no policy engine.
- Managed browser (configured)
- Preflight to Vayon AI
- Server-side decision
- Allow
- Mask
- Continue in Vayon AI
- Block
- Managed, configured browsers only
- Supported, configured AI services only
- The client contains no policy engine — the server decides
- Not all browsing is inspected; unmanaged devices are not governed
- The current client governs the request path; it does not inspect the AI response
Sensitivity classification
Content sensitivity is classified and drives whether context can leave for external execution.
Watch a sensitive request handled end to end
A believable organizational question is classified sensitive, kept internal because policy requires it, answered, and recorded in the central log — where you see the sensitivity class, the reason and the routing decision, not the raw prompt. Synthetic data throughout; the log intentionally omits the sensitive content.
Permission-aware knowledge access
Authorization is enforced before retrieval. Vayon AI can combine domain access with document-level ACLs and source permissions preserved by supported enterprise connectors, so content a user is not authorized to read is filtered out before scoring and never reaches the model. A source permission the product cannot represent restricts the document rather than widening it. Connector-specific ACL synchronization depends on the source and connector.
Organizational DLP as evidence, not a second policy engine
Vayon AI can consult trusted external classification evidence, such as Microsoft Purview, on an outbound request before an approved external call — and only after Vayon AI's own routing, policy and authorization gates have already permitted that crossing, so nothing is sent for content Vayon AI keeps internal or denies. External evidence can only make the decision more restrictive: it can raise sensitivity and force a request back inside, but it can never lower a locally determined sensitivity or open a route Vayon AI denied. If the external service cannot be reached or answers unexpectedly, the request fails closed. Response inspection is not part of this path.
Safe RAG boundaries
Authorization runs before retrieval; a domain without a grant is not retrieved, and answers cite approved sources.
Audit and evidence
Governed actions leave safe metadata and reason codes — reviewable, without raw prompts, answers or secrets.
Central Log and Content Audit — two separate records
The Central Log holds safe operational metadata — route, model, provider, reason codes, latency and cost — reviewable without raw prompts or answers. Content Audit is a separate, separately-governed record: when an organization enables it, prompt and answer content is recorded into an encrypted vault (metadata-only by default), with dual-authorization reveal and write-once retention. The two are never blurred.
Compliance evidence, not certification
Vayon AI maps its controls and evidence to recognized frameworks — YAHAV, ISO/IEC 42001, NIST AI RMF and the EU AI Act — as selectable regulation profiles with crosswalks, control mappings, readiness views and gap reporting. This is evidence and mapping support; it is not certification, and it does not by itself establish regulatory compliance.
Operational security controls
Metadata-only logging, scoped access and reason-code exports support a defensible operating posture.
Customer deployment independence
The customer runtime has no dependency on any Vayon AI vendor service. Nothing on the vendor side sits in the path of a customer AI request.
Output guardrails — governance continues through the response
Governance does not stop at the prompt. Vayon AI can validate model output against organizational response rules before it is returned to the calling surface. This validates output against the response rules you configure; it does not claim to prevent every possible harmful model output.
SIEM, incident visibility and emergency controls
Vayon AI governance connects to enterprise security operations: governed events to your SIEM, incident visibility, provider and model containment, and audited emergency controls. Vayon AI is not a full SIEM or SOC platform.
Honest limitations
Vayon AI reduces risk and provides controls and evidence; it does not eliminate all AI risk, and product evidence is not external certification.
Watch a sensitive request handled end to end
Policy before execution is a claim best judged by watching it refuse something. Bring a request your organization would worry about.
