Polygraf AI
Enterprise AI security platform that intercepts every AI interaction across an organization — desktop, API calls, video meetings and documents — using small language models that run entirely on-premises, so sensitive data never leaves the customer's own environment.
What is Polygraf AI?
Polygraf AI calls itself “the AI firewall your CISO needs”: an AI Behavioral Control plane that sits between an organization's staff and the AI tools they use. The problem it describes is a governance gap rather than a model gap — the company cites 89% of employees using AI tools their IT department has not approved, one in three AI queries containing sensitive data, and no traditional DLP tool having been designed for LLM interactions in the first place.
Its answer is architectural. Instead of routing traffic to a cloud service, Polygraf runs small language models locally, presented as explainable and auditable, and ships a library of 17 specialized models. Coverage is organized as four layers, each with its own module: an OS layer where Desktop Overlay intercepts text input before it leaves the machine; an API layer where Secure LLM anonymizes each call to ChatGPT, Claude, Microsoft Copilot or any other external model and restores the data afterwards; a communications layer where Meeting Guard watches Zoom, Teams and Google Meet calls in real time; and a document layer where Secret Marker redacts files before sharing. All four report into a Governance Dashboard described as a single pane of glass.
Deployment is containerized and deliberately undemanding. The company advertises going live in under two hours, with connection to an existing identity provider through AD/LDAP, SAML or OIDC, no agent on most surfaces, and no reconfiguration of the AI tools already in place, since the system behaves as a transparent proxy. Targets range from air-gapped on-premises Kubernetes and Docker through private cloud, Azure, Google Cloud and AWS to NVIDIA and Intel edge devices. Claimed figures include 98% detection accuracy, sub-100ms latency, a 40–130MB memory footprint and a 1.3GHz, 8GB minimum.
A separate Data Provenance suite handles content authenticity: AI Detector, AI Highlighter, Humanized Text Detector, Copyright Detector, Plagiarism Detector, Writing Analysis and Vexon Voice Detector. Behind the product, Polygraf Inc. is an Austin, Texas company claiming ISO/IEC 27001:2022, SOC 2 Type I and II, HIPAA, PCI-DSS, IL2–IL6, NIST RMF readiness, GDPR, CPRA, FERPA and EU AI Act conformance.
What it does
- Intercept and anonymize every outbound LLM API call, on both the input and the output, then restore the original values afterwards
- Detect sensitive data before it leaves the endpoint, capturing text input at operating-system level across any application
- Monitor video meetings in real time for audio and video deepfakes and for data disclosure
- Scan and redact documents and file shares before they are sent, across multiple file formats
- Identify and redact more than 35 types of PII, PCI, PHI and SPI, with 45+ entity types cited for the platform
- Enforce different AI policies per organization, department, group and individual user
- Detect AI-generated text, humanized text, plagiarism, copyright exposure and synthetic voice through the Data Provenance suite
When to use Polygraf AI / When not to
A quick filter to help you decide if Polygraf AI is the right fit.
When to use Polygraf AI
- CISOs and security engineers in regulated industries who must let staff use public AI tools without leaking regulated data
- Defense, intelligence and government teams working in air-gapped or classified environments, where the vendor claims IL2–IL6 alignment and zero external API calls
- Compliance, GRC and privacy officers who need audit logs and a single dashboard covering every AI interaction, with HIPAA, GDPR, PCI-DSS, SOC 2, ISO 27001 and NIST AI RMF policies available out of the box
- Healthcare, finance and insurance organizations handling PHI, cardholder data or claims documents that must be redacted before reaching an external model
- IT and platform teams that want a container-based rollout in under two hours, tied to an existing identity provider, without reconfiguring the AI tools already in use
When not to use Polygraf AI
- Individuals and freelancers: the platform has no published price and no self-service sign-up, only a demo request
- Small businesses without an infrastructure team, since deployment assumes Kubernetes or Docker plus an AD/LDAP, SAML or OIDC identity provider
- Anyone looking for a free or trial-based tool: no permanent free plan and no free trial is documented for the platform
- Mobile-first users, as no iOS or Android application is published and no app store listing exists
- Teams wanting a general-purpose AI assistant: Polygraf AI governs and filters AI usage rather than generating work for you
How to use Polygraf AI
A typical end-to-end flow, from setup to results.
- Request a demonstration through the Book a Demo form, presented as a 30-minute session, since the platform has no self-service sign-up
- Optionally run the Free AI Risk Assessment offered from the site header to scope your exposure first
- Choose a deployment target: air-gapped on-premises with Kubernetes or Docker, private cloud on VMware or OpenStack, Azure, Google Cloud, AWS, or an NVIDIA or Intel edge device
- Deploy the containerized components, budgeting at least 1.3GHz of CPU and 8GB of RAM per instance
- Connect the platform to your identity provider through AD/LDAP, SAML or OIDC to import users immediately
- Select which control layers to switch on — Desktop Overlay, Secure LLM, Meeting Guard, Secret Marker — leaving your existing AI tools untouched
- Define policies at organization, department, group and user level, choosing entity types, thresholds and enforcement actions for each
- Decide on fail-open or fail-closed behavior, so that an outage either passes traffic with an alert or blocks AI use until recovery
- Add Meeting Guard to a Google Meet, Zoom or Teams call when needed, which the company says requires no software installation
- Monitor everything from the Governance Dashboard, using real-time alerts, audit logs and compliance reporting, and integrate the REST API or SDKs where you need protection inside your own applications
Pros & Cons
Pros
- Processing stays local: on-premises small language models, no external API calls for processing, and full air-gap compatibility — the strongest answer available to the “where does our data go” question
- Four surfaces covered at once (operating system, API, meetings, documents) where most competing tools protect only one
- Fast, low-friction rollout: containerized, advertised at under two hours, no agent on most surfaces and no reconfiguration of existing AI tools
- An unusually broad certification base for a young company: ISO/IEC 27001:2022, SOC 2 Type I and II, HIPAA, PCI-DSS, IL2–IL6, NIST RMF readiness, GDPR, CPRA, FERPA and EU AI Act
- An explicit “No-Training” policy, with configurable retention windows, auto-deletion and encryption at rest
- Genuinely granular policy control, down to individual users, with configurable fail-open or fail-closed behavior
- External validation beyond the vendor's own claims: a 2026 USPTO patent, a mention as a Representative Vendor in a 2026 Gartner Market Guide, an IDC Market Note, and awards including SXSW Best in Show 2025
Cons
- No platform pricing is published: the /pricing/ URL serves a contact form, and the only published rates cover the API
- No permanent free plan and no free trial is documented; the API's “start free” wording is never quantified
- No public technical documentation — the Documentation and White Papers entries in the Developers menu both point at an empty anchor
- No Data Processing Agreement is published or offered, and no subprocessor list is disclosed, despite the privacy policy allowing sharing with providers and partners
- No Article 27 EU representative, no named DPO and no EU address, which is a real gap for a product sold on GDPR compliance
- Performance claims (98% accuracy, 90.2% across 27 PII types, beating Amazon, Google and Microsoft) rest on the vendor's word, as no benchmark report is published
- One published email address for the whole site and no support address: everything routes through a form, and the site itself is behind a bot challenge that blocks automated review of even its legal pages
Pricing & Plans
Pricing is split. The enterprise platform has no public price: the pricing URL resolves to a contact form, and every call to action leads to a demonstration request, so the platform is quoted individually. The API is the only offering with published rates. Its entry point is a base subscription fee of USD 5.00 per user per month, after which usage is billed at a fixed rate: USD 10 per million tokens or per 100 pages for the Standard Privacy API, and USD 15 per million tokens or per 100 pages for the Contextual Privacy API. The API section states “start free, upgrade anytime”, but neither the volume nor the duration of that free entry is specified, and no permanent free plan or time-limited free trial is documented anywhere on the site. Prices are quoted in US dollars only, with no annual discount mentioned.
- USD 5.00 per user/month
- after which a fixed rate applies based on usage
- USD 10 per 1 million tokens
- or USD 10 per 100 pages — essential privacy protection detecting and redacting over 35 types of PII
- PCI
- PHI and SPI
- USD 15 per 1 million tokens
- or USD 15 per 100 pages — adds biometric
- financial and geolocation data
- contextual detection
- advanced document analysis and customizable redaction rules
- no published tier — priced on quotation after a demonstration
Data, GDPR & hosting
A consolidated view of how Polygraf AI handles your data.
GDPR overview
GDPR compliance is claimed explicitly. The compliance center states that Polygraf AI complies with the GDPR, with personal data collected, processed and stored lawfully and transparently, and the privacy policy names European Commission-approved standard contractual clauses as the safeguard for transfers out of the EEA and Switzerland. Legitimate interests are the basis invoked for much of the processing. Alongside this sit ISO/IEC 27001:2022 and SOC 2 Type I and II certifications, plus a claimed EU AI Act alignment. Three gaps are worth naming: no Article 27 EU representative is designated, no data protection officer is named, and the company publishes no EU address — its only postal address is in Austin, Texas. The single published contact for privacy and CCPA requests is policy@polygraf.ai. GDPR is also sold as a product outcome, through PII detection, audit logs and per-department policies.
Who owns the data?
The terms are explicit on the customer's side: you retain ownership of any prompts you submit through the services, and Polygraf states it does not assert ownership over your profile information, which stays fully yours subject to the licence granted in the terms. The reverse also holds — all Polygraf Content remains Polygraf's property under worldwide copyright law, and the terms grant you no intellectual-property rights in it. In an on-premises deployment the practical answer is stronger still: processing happens inside your own infrastructure, with the vendor claiming zero external API calls and no third-party data exposure. A stated “No-Training” policy adds that proprietary data is never used to train models.
Reuse rights
For your own material, reuse is unrestricted: because you keep ownership of your prompts and profile information, nothing in the terms requires you to ask Polygraf's permission before using them elsewhere. The limit runs the other way — Polygraf Content may not be reused, since the terms grant no licence or intellectual-property rights over it. Two cautions are spelled out. Where content is submitted to the AI Humanizer, you alone remain responsible for complying with the terms of any third-party page it was copied from, and for any confidentiality obligations attached to it; Polygraf disclaims liability for either. And results are advisory only: the terms state that the AI Humanizer guarantees nothing about whether content will be flagged as AI-generated, that its output is not an endorsement or determination, and that any action you take on the strength of a score is yours alone. Separately, personal data collected through the website may be transferred to Polygraf's offices and servers in the United States and shared with affiliates, service providers and business partners; the policy states no CCPA “sale” currently takes place.
Data retention & training
Hosting summary
Two different things need separating. The product itself is hosted by the customer: the small language models run on-premises, and Polygraf states there are no external API calls for processing and no third-party data exposure. Customers choose the target — air-gapped on-premises Kubernetes or Docker, private cloud on VMware or OpenStack, Azure, Google Cloud, AWS, or NVIDIA and Intel edge devices — so no vendor hosting country applies. For Meeting Guard, on-premises storage, custom retention windows and auto-deletion are configurable, with data encrypted at rest in infrastructure described as SOC 2 Type II and ISO 27001 certified. The website is the exception: the privacy policy states that personal data provided through the services may be transferred to Polygraf's offices and servers, and those of authorized third parties, located in the United States. Transfers out of the EEA and Switzerland are covered by European Commission-approved standard contractual clauses. No EU hosting option is advertised.
Things to keep in mind
Risks and trade-offs to weigh before adopting Polygraf AI.
- The USD 5.00 per user per month entry price belongs to the API, not to the enterprise platform, whose cost is not public — do not budget from it
- A governance layer that reads every prompt, meeting and file share is itself a concentration of sensitive material; scrutinise who inside your organization can query those audit logs, and treat the tool as monitoring infrastructure with the oversight that implies
- Interception at OS level and in meetings has employee-surveillance implications: works-council consultation, transparency notices and a lawful basis need settling before rollout, not after
- The “No-Training” commitment and the retention controls appear on product pages rather than in contract terms; get both in writing
- No DPA, no subprocessor list, no Article 27 EU representative and no EU address — a European controller cannot complete its own compliance file from what is published
- Accuracy is not perfection: at a claimed 98%, some sensitive data will pass and some benign text will be blocked, so avoid treating the tool as a licence to relax human judgement about what belongs in a prompt
- Fail-open mode leaves AI traffic flowing during an outage, and website personal data is transferred to United States servers — two defaults worth checking against your own risk appetite
Setup & Integrations
Technical difficulty
Straightforward for end users, an infrastructure task to install. Employees need do nothing: the platform acts as a transparent proxy, existing AI tools are unchanged and most surfaces need no agent. The work sits with IT and security — deploying containers on Kubernetes, Docker or a managed cloud, connecting an AD/LDAP, SAML or OIDC identity provider, and defining policies per department and group. Hardware is modest at 1.3GHz and 8GB of RAM. Polygraf advertises full operation in under two hours. Realistically: easy for a team that already runs containers, out of reach without one.
Deployment
Integrations
Behind Polygraf AI
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Frequently asked questions
Does Polygraf AI work with our existing AI tools without reconfiguring them?
Does any of our data leave our environment?
How long does deployment take?
Can we enforce different policies per department or user group?
Which compliance standards are supported out of the box?
What happens if the service becomes unavailable? Does it block AI usage?
How much does Polygraf AI cost?
Is our data used to train Polygraf's models?
What does it need to run?
Should you pick Polygraf AI?
Polygraf AI is a credible answer to a problem most organizations now recognize: staff are already pasting regulated data into public AI tools, and traditional DLP was never built to see it. What sets this platform apart is that its central claim is architectural rather than promotional. Because the small language models run inside the customer's own infrastructure, the assertion that no data leaves the environment is testable at deployment, and the air-gapped and IL2–IL6 positioning follows from it rather than being bolted on. Covering four surfaces at once — endpoint, API, meetings and documents — is genuinely less common than the single-surface tools it is measured against.
The company is young: the domain dates from May 2023 and the first web capture from July 2023. Against that, it has assembled an unusually wide certification base, a USD 9.5 million seed round led by Allegis Capital, a 2026 USPTO patent and a mention as a Representative Vendor in a Gartner Market Guide.
The reservations are about disclosure rather than capability. Platform pricing is invisible, there is no public documentation, no DPA and no subprocessor list, and the headline accuracy figures rest on the vendor's own testing with no published benchmark. For a product sold substantially on GDPR compliance, the absence of an Article 27 representative, a named DPO and any EU address deserves a direct question. The “No-Training” policy is stated on a product page, not in a contract.
This is a tool for organizations with a real security function, evaluated through a demonstration and a proof of concept. Ask for the SOC 2 and ISO certificates, the benchmark methodology, a DPA and a written training commitment before signing.
- Choosing a selection results in a full page refresh.
- Opens in a new window.