Stop PII from leaking into prompts.
Lutril's DLP for LLMs inspects every prompt headed to a model, detects PII, secrets, and keys, and applies inline prompt redaction before the model ever sees them, without blocking the work.
- Detect
- PII, secrets, API keys, and custom patterns.
- Redact inline
- Replace each sensitive span with a placeholder like [EMAIL] before the model receives it.
- Per-model policy
- Different rules for public models vs. your private endpoints.
- Immutable audit
- Every redaction recorded, nothing stored in the clear.
Draft a refund email to maria.lopez@acme.com for the charge on card 4111 1111 1111 1111, and use key sk-live_9fXa…2bQ to look up the order.
Draft a refund email to [EMAIL] for the charge on card [CARD], and use key [SECRET] to look up the order.
2026-06-23 09:41:02.118 usr_4kQ REDACT email,card,secret,name (4 entities, gpt-4o)
A checkpoint on the way to every model.
DLP runs at the same layer that governs your agents, so it applies to chat, copilots, and MCP tool calls alike.
Detection that fits your data
Built-in detectors for emails, cards, national IDs, and secrets, plus regex and keyword patterns for your own sensitive fields.
Redact, mask, or block
Choose per policy: redact the span, mask to a token the model can reason about, or block the request outright.
Works across every model
One policy covers ChatGPT, Claude, Gemini, and your self-hosted models, applied consistently everywhere.
Provable compliance
An immutable log of what was detected and redacted gives auditors evidence without exposing the original data.
Questions buyers ask
What is LLM DLP?
LLM DLP is data loss prevention applied to the prompts people send to large language models. Classic DLP watches email, file shares and uploads; DLP for LLMs inspects the text typed or pasted into a model, which is where customer records, keys and tokens now leave the company. Lutril runs this check in the browser, on the prompt box of ChatGPT, Claude and Gemini.
What does Lutril detect in a prompt?
Email addresses, card numbers validated with the Luhn checksum, IBANs validated with the mod-97 checksum, JSON Web Tokens, provider API keys (OpenAI, AWS, Google, GitHub, Slack) and PEM private keys. Every detector is high confidence: a match is either structurally validated or has a unique shape. Bare words such as password or token are deliberately not flagged, because they fire on ordinary prose and code.
How does inline prompt redaction work?
As a prompt is typed or pasted, the Lutril extension scans it on the device and shows a banner naming what it found. One click replaces each match in the prompt box with a placeholder such as [EMAIL] or [SECRET], and Undo restores the original. The prompt is never rewritten silently: redaction is always the user's action, taken before the prompt is sent.
Does LLM DLP block the work?
Not by default. The browser DLP has two modes, set through your MDM: warn shows a non-blocking banner, and redact holds the first send until the user redacts or explicitly chooses to proceed. Either way the person keeps working, and the outcome is recorded.
Does the prompt text leave the device?
No. Detection runs locally in the browser, and neither the prompt nor the matched values are sent to Lutril. For each send, Lutril receives a summary: which data types were found and how many, whether the user was warned or redacted, the AI tool and the user. Your security team sees every detection without the content ever being stored.
How is DLP for LLMs different from traditional DLP?
Traditional DLP watches files, email and network traffic. A prompt is typed into a web page and sent in the same gesture, often from a personal account that never passes through your proxy or your mail gateway. LLM DLP has to act inside the prompt box, before the send, which is why Lutril runs it in a browser extension deployed through your MDM.