Developers paste secrets, customer data, and proprietary source into AI agents all day. MoorAI is data-loss prevention that runs on the endpoint — it reviews every prompt locally and redacts or blocks sensitive data before it reaches Claude Code, Codex, or Copilot CLI. The difference from cloud DLP: nothing has to leave the machine.
One local check on the device, before a prompt reaches the AI — then only content-free signals flow to the console.
The moment a prompt is sent, MoorAI checks it locally against policy — a 40+ threat matrix plus content rules. If it carries an API key, a private key, an email, a national ID, a payment card, or PHI, MoorAI can redact the sensitive span and forward a clean prompt, coach the user, require a logged justification, or block outright — per policy, per tenant, per device. When a prompt is blocked, the user can still send it with the sensitive parts redacted, so work isn't stopped needlessly.
MoorAI groups detections into four data classes, so you can set one default action per class instead of tuning every rule — and a per-threat setting still overrides it.
The core invariant: prompts and conversations never leave the device. Security teams receive only redacted, content-free signals — a category, a risk level, and a one-way hash — through a central web console. You get evidence of what class of data was at risk and what action was taken, without ever exposing what anyone typed.
No. Detection and redaction happen locally; only content-free metadata is reported.
Yes — MoorAI redacts the sensitive spans and forwards a clean prompt when possible, so blocked prompts can still be salvaged.
The AI agents developers run locally — Claude Code, Codex, and GitHub Copilot CLI — as a thin native host in front of them.
More: shadow-AI detection · OWASP LLM Top 10 tooling · MoorAI vs Lakera
Redact or block before the prompt reaches the agent.