Secure AI for your whole company.

One safe place for your whole company to use AI. Sensitive data is masked before it leaves your company, every use is audited, and you choose which data may be shared. Runs on your servers or in our secure cloud.

Built for regulated environments

🏠Self-hosted · on-prem or your cloud 🪪SSO (OIDC) + MFA 🛡️LLM firewall on every request 📋Full audit trail 🔑Bring your own AI provider 🔍DLP for AI · sensitive data detected & masked

Where does your company's data go today?

Your people already use AI. The question is whether it happens in fifty personal accounts you can't see — or in one place you control.

your company legal · contract.pdf clinical · patient notes eng · source + .env finance · Q3 figures public AI chat personal accounts no policy · no maskingno audit · no visibility you find out about it in the incident report

Fifty accounts you can't see

Employees paste contracts, patient notes and source code into whatever chatbot is fastest, under personal logins, with no record of what left.

  • ✕Confidential data leaves the company unmasked
  • ✕No audit trail — you can't answer "what was sent, by whom, when"
  • ✕No access control; a leaver keeps their history
  • ✕Banning AI just pushes it further underground
your company legal clinical engineering finance ARX RUN SSO · workspaces LLM firewall audit log self-hosted AI provider masked data only one door out — guarded, logged, yours

One door, guarded and logged

Everyone signs in with company SSO to a workspace for their team. Every request passes through the firewall; every flow of data is recorded. The platform runs on your servers.

  • ✓Sensitive data masked or withheld before it leaves your network
  • ✓A complete audit trail of who sent what, under which policy
  • ✓Access follows your identity provider — leavers lose access instantly
  • ✓A better tool than the shadow one, so people actually use it

Every request passes through the LLM firewall

Prompts, attachments and tool results are checked against your policies before they leave your network, and model responses are checked on the way back.

Personal data, secrets and classified figures are masked or withheld. Prompt-injection attempts in documents and web content are flagged. What flowed, and under which policy, is written to the audit log — while the content itself stays visible only to its owner.
arx audit · role: securitycontent: hidden
requests today4 812
items masked1 207
blocked / flagged3 / 41
legal · k.dvorak🙈masked 5 · legal-eu
clinical · dr.hajek🙈pseudonymized 3
eng · m.novak🙈secret stripped
finance · a.kral🙈restricted withheld

How it works

Connect identity and policies

Plug in your SSO, create workspaces for teams, and define firewall policies: what is personal data, what is confidential, what may never leave.

Teams work in their workspace

Lawyers, clinicians, engineers and analysts use one familiar AI tool. Each request is checked and masked by the firewall on the way to the model you chose.

Security sees the flow, not the content

Your security team gets the audit trail — who, when, which policy, what was masked — and exports for compliance. Content stays with its owner.

employee→ workspace→ LLM firewall→ AI provider · audit log

Three things you should know about ARX RUN

🏢

One tool for the whole company

Instead of fifty personal accounts, one workspace per team behind company SSO — with roles, MFA and access that ends the day someone leaves.

🛡️

Every step guarded and recorded

The LLM firewall checks each request and response against your policies. The audit log records every flow of company data — and is built for auditors, not just engineers.

🏠

It runs on your infrastructure

On-prem or in your cloud, with the AI provider of your choice. Even the platform admin can't read anyone's conversations or documents.

Compared with public AI chat

The same capabilities your people already want — inside your perimeter.

public AI chat · personal accountsARX RUN
Where data goesStraight to a third party, unmaskedThrough your LLM firewall: personal data, secrets and classified figures masked or withheld first
Visibility & auditNone — you don't know what leftFull audit trail of every request: who, when, workspace, policy, what was masked; exportable for compliance
Access controlPersonal logins, no offboardingCompany SSO with MFA, role-based workspaces per team, access revoked with the identity
DeploymentSaaS, their termsSelf-hosted on-prem or in your cloud, with the AI provider you choose
Who sees contentThe provider, and anyone with the loginOnly its owner — not even your platform admin
∵ ⩆
[b.64]b25lIGRvb3Igb3V0LiBndWFyZGVkLCBsb2dnZWQsIHlvdXJzLiAtLSBhcnggcnVu

1 sandbox per session.
0 shared keys.
100% of requests audited.

*structural properties of the platform, not benchmark results. Each session gets its own isolated worker; every user connects their own provider key; every request and connector call passes through the firewall and is written to the audit log.

isolation1sandbox per session — container, micro-VM or Pod
credentials0shared API keys on the server
firewall100%of requests checked before leaving your network
content boundary0 Bof session content visible to platform admins
⩆ ∵

We give a FAQ

Is ARX RUN an AI model?

No. It is the layer between your people and the AI models you allow. You bring your own provider account (today Claude; more coming). ARX RUN adds identity, workspaces, the LLM firewall, the audit trail and sandboxed agents around it.

Where does our data actually go?

From the user's workspace through the firewall, which masks or withholds sensitive data according to your policies, then to the provider you chose. The audit log records the flow — who, when, which policy, what was masked — but not the content.

How is this different from Copilot or Notion AI?

Those are AI features inside one vendor's app. ARX RUN covers work that spans systems, data those tools cannot reach (DMS, hospital systems, ERP, file shares), autonomous agents, self-hosted deployment and full auditability. It does not replace the AI button inside Outlook — and doesn't try to.

Can the platform admin read our conversations?

No. Operators see state and counts — sessions running, policy hits, projects — never the content of sessions or documents. The boundary is enforced by the server, not by policy.

Do we have to run it ourselves?

You can. Self-hosting on your own servers (podman compose) or cluster (Helm) is the primary model. A secure cloud option exists for teams that prefer not to operate it.

Which AI providers are supported?

Claude, through the official Claude Agent SDK. Codex, Cursor and OpenCode are planned. You decide which providers your company allows; all of them get the same firewall, audit and workspaces.

[b.64]c2FuZGJveCBwZXIgc2Vzc2lvbiAvIGZpcmV3YWxsIHBlciByZXF1ZXN0IC8gYXVkaXQgcGVyIGZsb3cgLyBjb250ZW50IHZpc2libGUgdG8gb3duZXIgb25seQ==

Works with the AI providers you choose

ARX RUN sits between your people and the model. You decide which providers your company allows — and every one of them gets the same firewall, the same audit trail and the same workspaces.

ClaudeAnthropic available
CodexOpenAI coming soon
CursorAnysphere coming soon
OpenCodeopen source coming soon

Give your company one secure AI

See the firewall, the audit trail and the workspaces on your own data.