Understand AI use
See how employees, assistants, and agentic tools are actually using AI.
Runtime AI Governance for discovery, classification, policy evaluation, and evidence.
Your organisation owns the controls over reachable tools, credentials, shared state, and delegated authority. 3LS brings AI use into view for users, assistants, and agentic workflows through discovery and policy evaluation.
See how employees, assistants, and agentic tools are actually using AI.
Find PII, secrets, and risky interactions in the observed evidence available to policy evaluation.
Turn observed evidence into an explainable policy evaluation and retain the result.
How it works
Instead of treating AI as a black box, 3LS helps teams understand how AI is being used, where sensitive data is involved, and how organisational policy applies.
Available evidence shows where a user, assistant, OAuth app, or tool is using AI.
3LS classifies what the interaction appears to be for and how the AI is being used.
Sensitive content and risky behaviour are surfaced for evaluation.
Teams evaluate the available context and risk against organisational policy, then retain the result.
What the story answers
Prompt classification answers how your users are using AI. Sensitive-content detection answers what information is present. Policy evaluation answers what the available evidence means.
Prompt classification
Classify drafting, coding, research, data handling, and tool-driven behavior into clear operating patterns.
PII detection
Highlight personal information, secrets, and restricted content inside prompts, tool inputs, and outputs.
Policy evaluation
Evaluate the available context against organisational policy and keep the reasoning operators need to review.
Operator view
Give security teams a readable trail of what was detected, how policy was evaluated, and which evidence supported the result.
Recent findings
Intent, sensitivity, and policy evaluation
Solutions
Start with one visual story on the homepage, then explore the capabilities that help teams understand AI use, detect sensitive data, and make defensible policy decisions.
Prompt classification
See whether AI is being used for drafting, coding, research, summarization, data handling, or tool-driven work.
Explore capabilityPII detection
Surface personal information, credentials, and restricted content inside prompts, tool inputs, and outputs.
Explore capabilityPolicy evaluation
Evaluate organisational policy with the context available. Pre-execution grant or deny is limited to a supported managed MCP stdio path.
Explore capabilityCompliance evidence
Collect runtime evidence for prompts, uploads, OAuth grants, tool actions, supplier exposure, and high-risk AI decisions.
Explore capabilityFrom the blog
A few articles that explain the operating model behind the product: where AI use becomes visible, why incidents expand, and how control decisions should be made.

AI chat feels private to users, but providers and operators control storage, sharing, indexing, and transcript exposure. That makes chat security a governance and data-exposure problem.

After an AI exposure, the hardest question is usually what your organization cannot answer: where AI is active, what was pasted in, and what was shared. That visibility gap turns shadow AI into an incident multiplier.

Microsoft is adding native AI controls while OpenAI is turning ChatGPT into a shared agent workspace. Both trends point to the same requirement: one runtime governance layer across prompts, files, memory, tools, and actions.
Start with visibility, move to clear findings, and introduce controls only where they matter.