Runtime AI Governance for discovery, classification, policy evaluation, and evidence.

See how AI is being used. Govern what AI can reach.

Your organisation owns the controls over reachable tools, credentials, shared state, and delegated authority. 3LS brings AI use into view for users, assistants, and agentic workflows through discovery and policy evaluation.

Observe
AI use
Detect
Sensitive content
Evaluate
Policy
Security analyst reviews prompt, upload, OAuth, and tool activity as evidence for a policy evaluation.
Controlled PL-1 composite: broad AI activity becomes discovery, classification, and policy-evaluation evidence.
Visibility:
On-device collection brings supported AI activity into view for classification and policy evaluation.
Policy ownership:
Your organisation owns the policy evaluation and the resulting evidence.

Understand AI use

See how employees, assistants, and agentic tools are actually using AI.

Detect sensitive content

Find PII, secrets, and risky interactions in the observed evidence available to policy evaluation.

Evaluate policy

Turn observed evidence into an explainable policy evaluation and retain the result.

How it works

Move from vague AI risk to visible, understandable decisions.

Instead of treating AI as a black box, 3LS helps teams understand how AI is being used, where sensitive data is involved, and how organisational policy applies.

Phase 1

AI activity is observed

Available evidence shows where a user, assistant, OAuth app, or tool is using AI.

Phase 2

Purpose is classified

3LS classifies what the interaction appears to be for and how the AI is being used.

Phase 3

Risk evidence is surfaced

Sensitive content and risky behaviour are surfaced for evaluation.

Phase 4

Policy is evaluated

Teams evaluate the available context and risk against organisational policy, then retain the result.

What the story answers

Three questions every security team needs answered

Prompt classification answers how your users are using AI. Sensitive-content detection answers what information is present. Policy evaluation answers what the available evidence means.

Prompt classification

How are your users using AI?

Classify drafting, coding, research, data handling, and tool-driven behavior into clear operating patterns.

Outcome: Visibility into AI usage

PII detection

What sensitive data is present?

Highlight personal information, secrets, and restricted content inside prompts, tool inputs, and outputs.

Outcome: Fewer accidental exposures

Policy evaluation

What does policy say?

Evaluate the available context against organisational policy and keep the reasoning operators need to review.

Outcome: Explainable policy evaluation

Operator view

Turn AI interactions into clear decisions

Give security teams a readable trail of what was detected, how policy was evaluated, and which evidence supported the result.

Operator evidence view highlights PII in a customer CSV upload and records a policy evaluation with its rationale.

Recent findings

Intent, sensitivity, and policy evaluation

3 evaluations captured
Activity
Intent
Sensitivity
Policy result
Customer records pasted into an assistant
Data handling
PII detected
Needs review
Prompt requests external tool access
Tool use
No sensitive data
Within policy
Prompt includes an API token and a request to share it
Data sharing
Secret detected
Escalate

Solutions

Go deeper on the capabilities behind the story.

Start with one visual story on the homepage, then explore the capabilities that help teams understand AI use, detect sensitive data, and make defensible policy decisions.

SD-3 / Classify Detect Classify Evaluate Intent Lanes Evidence In policy Review Policy issue Evidence retained for the policy decision
SD-3: Square thumbnail with capability card, evidence chip, event arrow, and prompt classification symbol. Production metadata: 3ls-sd-3-solutions-prompt-card-diagram.svg; SVG square master rendered in fixed card aspect ratio; crop-safe to 1200x630 for future social thumbnails.; task-1093-inline-svg-master

Prompt classification

Understand how your users are using AI

See whether AI is being used for drafting, coding, research, summarization, data handling, or tool-driven work.

Explore capability
SD-3 / Detect Detect Classify Evaluate PII Secrets Warn In policy Review Policy issue Evidence retained for the policy decision
SD-3: Square thumbnail with sensitive-data card, highlighted entity chip, event arrow, and evidence symbol. Production metadata: 3ls-sd-3-solutions-pii-card-diagram.svg; SVG square master rendered in fixed card aspect ratio; crop-safe to 1200x630 for future social thumbnails.; task-1093-inline-svg-master

PII detection

Spot sensitive data before it spreads

Surface personal information, credentials, and restricted content inside prompts, tool inputs, and outputs.

Explore capability
SD-3 / Policy evaluation Detect Classify Evaluate Evidence Risk Result In policy Review Policy issue Evidence retained for the policy decision
SD-3: Square thumbnail showing available evidence, risk context, a policy result, and retained evidence. Production metadata: 3ls-sd-3-solutions-controls-card-diagram.svg; SVG square master rendered in fixed card aspect ratio; crop-safe to 1200x630 for future social thumbnails.; task-1093-inline-svg-master

Policy evaluation

Decide what the evidence means

Evaluate organisational policy with the context available. Pre-execution grant or deny is limited to a supported managed MCP stdio path.

Explore capability
SD-2 / Detect, classify, evaluate Detect Classify Evaluate Activity Analysis Policy result Evidence In policy Review Policy issue Evidence retained for the policy decision
SD-2: Three-step visual showing observed activity, analysis, then policy evaluation and evidence. Production metadata: 3ls-sd-2-solutions-policy-flow-diagram.svg; SVG master rendered fluidly with explicit 1600x900 dimensions; usable as 16:9 desktop panel and full-width mobile diagram.; task-1093-inline-svg-master

Compliance evidence

Prove AI governance before the review

Collect runtime evidence for prompts, uploads, OAuth grants, tool actions, supplier exposure, and high-risk AI decisions.

Explore capability

Understand AI behavior before it becomes an incident.

Start with visibility, move to clear findings, and introduce controls only where they matter.