Use agentic AI without sending raw sensitive context to providers.
Wyloc intercepts supported agent and browser traffic, masks configured sensitive context inside your environment, and applies company policy before requests reach AI providers. The third option — allow, with control.
Ban AI, or expose unrestricted context. There is a third option.
Security teams should not have to choose between blocking agentic coding tools and letting source code, database schema, credentials, and internal architecture flow to model providers. Wyloc is a self-hosted policy, masking, and enforcement layer between company-controlled environments and supported AI tools.
How Wyloc works
Processing happens inside your environment on traffic Wyloc can observe — gateway-routed CLI and IDE clients, browser submissions, and configured egress paths. Wyloc does not claim universal interception of vendor-hosted agent backends or pinned TLS clients.
Step 1
Developer or employee
Uses a supported agentic CLI, IDE extension, or browser assistant.
Step 2
AI tool or agent
Submits prompts, tool results, and file-read content toward a provider.
Step 3
Wyloc policy layer
Self-hosted gateway and/or browser extension applies signed policy, masks configured context, and enforces actions before forward.
Step 4
Supported provider
Receives transformed traffic with your organization's provider credentials relayed — not substituted.
Step 5
Controlled response
Rehydration restores placeholders in-session; response DLP inspects model output within configured limits.
Control center for security teams
A self-hosted tenant control center for policy, fleet posture, user attribution, masking and blocking decisions, destination controls, and audit evidence — metadata only by design.
- Policies by organization, role, tool, action, and destination
- Per-user and per-device attribution on metadata events
- Exposure ledger, canary results, and tamper-evident audit chain
- Query-volume safeguards and preview-first SQL behavior
Control center
northstar-systems · policy v18
Protected requests
48,291
Interventions
1,847
Open exceptions
3
Recent decisions · metadata only
- 09:42Masked
platform-eng
Claude Code · AWS access key
- 09:35Masked
data-analyst
Codex · SQL identifiers
- 09:20Held
infra-live
Gateway · Destructive shell
- 08:54Swapped
browser-ext
ChatGPT · Stripe test key
Illustrative interface — sample categories and counts only. No prompts, secret values, or mappings are shown.
Protection capabilities
Mask when safe. Block when policy requires it. Designed to prevent configured sensitive data from reaching supported destinations — without stopping the business logic the model needs to reason about.
Data protection
Secrets
Credential detection
80+ built-in patterns plus company-defined regex — AWS, GitHub, Stripe, database URLs, JWTs, PEM keys, and high-entropy context-gated strings.
Schema
SQL schema masking
Masks proprietary table and column names while preserving query structure so models can still reason about SQL.
Code
Code-structure protection
Masks internal classes, functions, packages, and paths across supported languages while leaving library and framework APIs intact.
Agents
Agent-read file results
Content from files an agent reads locally is masked on the same path as typed prompts — configs, logs, and .env assignments included.
PII
Structured personal data
Credit cards, SSNs, email, and formatted phone numbers where configured. Free-text name/address NER is a separate optional tier.
Policy & enforcement
Policy
Mask when safe. Block when required.
Per-organization policy for SQL, code, file reads, PII, response DLP, and dangerous tool actions — signed, versioned, and fail-closed when invalid.
Actions
Dangerous-action controls
Agent Action Firewall holds or denies destructive shell commands, exfiltration-shaped uploads, and policy-defined tool actions.
SQL
Mutation and volume safeguards
Parsed SQL capability policy, preview-first behavior, scan budgets, statement timeouts, and streaming row/byte cancellation.
Destinations
Destination allowlisting
Egress routing can restrict which upstream hosts and storage endpoints a cooperative process may reach.
Scope
Path and workspace boundaries
File broker and archive controls limit which repository paths and bundles may be read or packaged for upload.
Governance
Attribution
User and device attribution
Metadata-only events carry hashed device and repo fingerprints, operator-supplied labels, and signed runtime principals — never prompt text or secret values.
Audit
Decision evidence
Tamper-evident audit chain, exposure ledger, canary results, and compliance mappings for security review.
RBAC
Role-based control center
Self-hosted tenant control center for policy, fleet posture, approvals, and metadata-only rollups.
Supported tools and honest limits
One policy layer across supported AI tools — not a claim of universal coverage. Distinctions below come from the gateway SUPPORTED_TOOLS.md matrix in the Wyloc repository.
Supported
Documented routing through the self-hosted gateway or browser extension, with masking and policy enforcement on observed traffic.
- · Claude Code (Anthropic Messages — live certification)
- · Codex CLI (OpenAI Responses — live certification)
- · Gemini CLI — API key and Vertex modes
- · Aider, Goose, OpenCode (OpenAI-compatible gateway routing)
- · Browser extension — ChatGPT, Claude, Gemini, Copilot, Perplexity, Grok, DeepSeek, Mistral, and universal text inputs
Tested / guided setup
Architecture and adapter coverage confirmed; full end-to-end proof may require local IDE or interactive setup.
- · Continue, Cline, Roo Code, Kilo Code (OpenAI-compatible — guided base-URL setup)
- · Copilot CLI BYOK mode
- · Grok Build — conditional egress-mode coverage with dedicated harness boundaries
Requires network-level or vendor integration
Vendor-locked agent backends, Bedrock re-signing, and proprietary IDE agent modes are not claimed as fully inspectable at this layer.
- · Cursor native Agent/Composer (fail-closed; BYOK chat is conditional)
- · GitHub Copilot native/cloud agent mode
- · AWS Bedrock direct routing (SigV4 body signing — re-signing not shipped)
- · Vendor-locked agents (Windsurf Cascade, Augment default backend, and similar)
Want to evaluate the browser surface now? Try the browser extension — local-only, no sign-in, metadata-only incident counts.
Not a replacement for enterprise AI. A layer before it.
Provider enterprise tiers govern what happens after data arrives. Wyloc applies pre-provider enforcement inside your environment. The two are complementary.
Enterprise AI contracts
- A promise about what the vendor does after they receive your data
- Retention and training limits — on the provider's terms
- One vendor relationship at a time
Wyloc
- Pre-provider enforcement inside your environment
- Masking, blocking, and destination controls before upstream transmission
- One policy layer across supported AI tools
Self-hosted deployment and trust boundaries
Wyloc runs on your infrastructure, uses your provider keys, and enforces signed policy before supported traffic leaves your environment. Sensitive context is processed locally to apply masking and controls — telemetry to the control plane is metadata only, with no prompt text, secret values, or real↔mock mappings.
- Self-hosted gateway and control plane in your environment
- Customer-owned provider keys — relayed, not substituted
- Signed, versioned policy with fail-closed startup
- Metadata-only telemetry — no prompt text, values, or mappings stored off-device
See how Wyloc fits your AI environment
Walk through architecture, supported tools, policy enforcement, and the metadata-only control plane with the team that built it.