Zero-Firewall Deployment

Start protecting AI in an afternoon. No firewall ticket.

Three deployment paths. Pick one, or run them side by side.

Three parallel luminous deployment routes converging into a single enforcement gate
How it works

Choose a path and start enforcing today.

  1. 01

    SELECT

    Choose PAC file, Browser Shield or API proxy based on where your AI traffic originates.

  2. 02

    CONFIGURE

    Set policies, risk thresholds and detector packs in the console — no code required.

  3. 03

    DEPLOY

    Push a file, install an extension or change one base URL. No firewall change window and no agent rollout — each path is reversible.

  4. 04

    EVIDENCE

    Verdicts and decisions flow into the tamper-evident audit chain from day one.

Capabilities

What it does.

DP-01

PAC file deployment

Generate a proxy auto-config file and push it via Windows GPO or macOS MDM.

DP-02

Browser Shield extension

Manifest V3 extension for Chrome, Edge, Brave and Arc with local prompt inspection.

DP-03

OpenAI-compatible API proxy

Change one base URL and every SDK call is governed without model or vendor lock-in.

DP-04

Mixed-mode operation

Run PAC, Browser Shield and API proxy side by side for layered coverage.

DP-05

Generated policy artifacts

.reg and .mobileconfig files are created automatically for managed rollout.

DP-06

Same-day evidence

Audit-chain entries start accumulating the moment the first prompt is processed.

In practice

One line of code.

policy · verdictlive

policy > "Switch the OpenAI SDK base URL to route every completion through XAIGuard"

client: OpenAI(base_url="https://api.xaiguard.com/v1")

model: "gpt-4o"

policy: "block-pii-and-secrets"

prompt_risk: HIGH — PII detected

verdict: "BLOCK_AND_REDACT"

audit_hash: "ed25519:7d1a…e03b"

Framework mapping
No firewall changeNo NGFW ruleNo agent rolloutReversible in minutes

Deployment is designed to be low-risk and reversible, not a six-month network project.

Deployment paths

Three ways in. One policy everywhere.

01

PAC file

  1. Generate a proxy auto-config file from the console.
  2. Push it with Windows GPO or macOS MDM.
  3. .reg and .mobileconfig files are generated for you.
  4. AI traffic routes through XAIGuard enforcement.

Good for: full org coverage without touching the network edge.

02

Browser Shield

  1. Install the Manifest V3 extension for Chrome, Edge, Brave or Arc.
  2. Prompts are inspected locally before submission.
  3. Six built-in detectors plus your custom patterns.
  4. Blocks are reported to your tenant and written to the audit chain.

Good for: fast pilots and BYOD.

Chrome Web Store listing is in review. The signed package is available for managed install today.

03

API proxy

  1. Use the OpenAI-compatible endpoint.
  2. Change one base URL in your SDK or agent code.
  3. Every model call is scored, redacted or blocked.
  4. Works with any model that speaks the OpenAI chat format.

Good for: your own applications and agents.

Compare paths

Pick the fit for your environment.

CriteriaPAC fileBrowser ShieldAPI proxy
CoverageAll browser AI trafficBrowser-based assistantsYour apps and agents
Setup timeHoursMinutesMinutes
Network change requiredNoNoNo
Works off-networkNoYesYes
Best forFull org rolloutFast pilots / BYODCustom applications
Rollout timeline

From pilot to evidence in three weeks.

Day 0

Pilot group

Deploy Browser Shield or API proxy to a small team and run first prompts.

Week 1

Policy tuning

Tune thresholds, add custom detectors and review false positives.

Week 2

Org-wide

Roll out PAC file or push extension to all users and agents.

Week 3

First evidence export

Generate a signed evidence package for auditors or board review.

Next step

See it run against your own prompts.