Wyloc

Use agentic AI without sending raw sensitive context to providers.

Wyloc intercepts supported agent and browser traffic, masks configured sensitive context inside your environment, and applies company policy before requests reach AI providers. The third option — allow, with control.

Ban AI, or expose unrestricted context. There is a third option.

Security teams should not have to choose between blocking agentic coding tools and letting source code, database schema, credentials, and internal architecture flow to model providers. Wyloc is a self-hosted policy, masking, and enforcement layer between company-controlled environments and supported AI tools.

How Wyloc works

Processing happens inside your environment on traffic Wyloc can observe — gateway-routed CLI and IDE clients, browser submissions, and configured egress paths. Wyloc does not claim universal interception of vendor-hosted agent backends or pinned TLS clients.

Step 1

Developer or employee

Uses a supported agentic CLI, IDE extension, or browser assistant.

Step 2

AI tool or agent

Submits prompts, tool results, and file-read content toward a provider.

Step 3

Wyloc policy layer

Self-hosted gateway and/or browser extension applies signed policy, masks configured context, and enforces actions before forward.

Step 4

Supported provider

Receives transformed traffic with your organization's provider credentials relayed — not substituted.

Step 5

Controlled response

Rehydration restores placeholders in-session; response DLP inspects model output within configured limits.

Control center for security teams

A self-hosted tenant control center for policy, fleet posture, user attribution, masking and blocking decisions, destination controls, and audit evidence — metadata only by design.

  • Policies by organization, role, tool, action, and destination
  • Per-user and per-device attribution on metadata events
  • Exposure ledger, canary results, and tamper-evident audit chain
  • Query-volume safeguards and preview-first SQL behavior

Protection capabilities

Mask when safe. Block when policy requires it. Designed to prevent configured sensitive data from reaching supported destinations — without stopping the business logic the model needs to reason about.

Data protection

Secrets

Credential detection

80+ built-in patterns plus company-defined regex — AWS, GitHub, Stripe, database URLs, JWTs, PEM keys, and high-entropy context-gated strings.

Schema

SQL schema masking

Masks proprietary table and column names while preserving query structure so models can still reason about SQL.

Code

Code-structure protection

Masks internal classes, functions, packages, and paths across supported languages while leaving library and framework APIs intact.

Agents

Agent-read file results

Content from files an agent reads locally is masked on the same path as typed prompts — configs, logs, and .env assignments included.

PII

Structured personal data

Credit cards, SSNs, email, and formatted phone numbers where configured. Free-text name/address NER is a separate optional tier.

Policy & enforcement

Policy

Mask when safe. Block when required.

Per-organization policy for SQL, code, file reads, PII, response DLP, and dangerous tool actions — signed, versioned, and fail-closed when invalid.

Actions

Dangerous-action controls

Agent Action Firewall holds or denies destructive shell commands, exfiltration-shaped uploads, and policy-defined tool actions.

SQL

Mutation and volume safeguards

Parsed SQL capability policy, preview-first behavior, scan budgets, statement timeouts, and streaming row/byte cancellation.

Destinations

Destination allowlisting

Egress routing can restrict which upstream hosts and storage endpoints a cooperative process may reach.

Scope

Path and workspace boundaries

File broker and archive controls limit which repository paths and bundles may be read or packaged for upload.

Governance

Attribution

User and device attribution

Metadata-only events carry hashed device and repo fingerprints, operator-supplied labels, and signed runtime principals — never prompt text or secret values.

Audit

Decision evidence

Tamper-evident audit chain, exposure ledger, canary results, and compliance mappings for security review.

RBAC

Role-based control center

Self-hosted tenant control center for policy, fleet posture, approvals, and metadata-only rollups.

Supported tools and honest limits

One policy layer across supported AI tools — not a claim of universal coverage. Distinctions below come from the gateway SUPPORTED_TOOLS.md matrix in the Wyloc repository.

Supported

Documented routing through the self-hosted gateway or browser extension, with masking and policy enforcement on observed traffic.

  • · Claude Code (Anthropic Messages — live certification)
  • · Codex CLI (OpenAI Responses — live certification)
  • · Gemini CLI — API key and Vertex modes
  • · Aider, Goose, OpenCode (OpenAI-compatible gateway routing)
  • · Browser extension — ChatGPT, Claude, Gemini, Copilot, Perplexity, Grok, DeepSeek, Mistral, and universal text inputs

Tested / guided setup

Architecture and adapter coverage confirmed; full end-to-end proof may require local IDE or interactive setup.

  • · Continue, Cline, Roo Code, Kilo Code (OpenAI-compatible — guided base-URL setup)
  • · Copilot CLI BYOK mode
  • · Grok Build — conditional egress-mode coverage with dedicated harness boundaries

Requires network-level or vendor integration

Vendor-locked agent backends, Bedrock re-signing, and proprietary IDE agent modes are not claimed as fully inspectable at this layer.

  • · Cursor native Agent/Composer (fail-closed; BYOK chat is conditional)
  • · GitHub Copilot native/cloud agent mode
  • · AWS Bedrock direct routing (SigV4 body signing — re-signing not shipped)
  • · Vendor-locked agents (Windsurf Cascade, Augment default backend, and similar)

Want to evaluate the browser surface now? Try the browser extension — local-only, no sign-in, metadata-only incident counts.

Not a replacement for enterprise AI. A layer before it.

Provider enterprise tiers govern what happens after data arrives. Wyloc applies pre-provider enforcement inside your environment. The two are complementary.

Enterprise AI contracts

  • A promise about what the vendor does after they receive your data
  • Retention and training limits — on the provider's terms
  • One vendor relationship at a time

Wyloc

  • Pre-provider enforcement inside your environment
  • Masking, blocking, and destination controls before upstream transmission
  • One policy layer across supported AI tools

Self-hosted deployment and trust boundaries

Wyloc runs on your infrastructure, uses your provider keys, and enforces signed policy before supported traffic leaves your environment. Sensitive context is processed locally to apply masking and controls — telemetry to the control plane is metadata only, with no prompt text, secret values, or real↔mock mappings.

  • Self-hosted gateway and control plane in your environment
  • Customer-owned provider keys — relayed, not substituted
  • Signed, versioned policy with fail-closed startup
  • Metadata-only telemetry — no prompt text, values, or mappings stored off-device

See how Wyloc fits your AI environment

Walk through architecture, supported tools, policy enforcement, and the metadata-only control plane with the team that built it.