Shadow AI
Unapproved tools and models may be used outside enterprise visibility and policy controls.

As AI applications and agents become more widespread, security and governance cannot be left solely to model providers. CID222 sits between enterprise applications and AI agents on one side and supported AI models on the other, applying data protection, content security, policy and audit controls to inputs and outputs.
As employees, enterprise applications and AI agents use different models, tracking data flows, identity and authorization context, applied policies and token consumption becomes increasingly complex. Centralized visibility and management of this usage is becoming more important for organizations.
Unapproved tools and models may be used outside enterprise visibility and policy controls.
Traditional security controls may be limited in their ability to evaluate prompts, responses, user identity and AI agent behavior within the same context.
Building separate controls into every application makes consistent policy enforcement and auditability more difficult.
Out-of-policy calls, unnecessary context and inappropriate model usage increase token consumption and cost.
5 questions · Quick check · No technical preparation required
Can you centrally see which models are being used by employees, applications and AI agents?
CID222 sits between existing applications and AI models, applying security, data protection, policy and audit controls to input and output flows. It integrates into existing AI application flows to create a centralized control point for different models and providers.
CID222 makes the models, applications, users and use cases within AI traffic passing through it centrally visible and traceable.
CID222 applies rules defined by identity, role, data type and usage context to AI interactions passing through it.
CID222 detects prompt injection, jailbreak, sensitive-data and harmful-content risks in input and output flows, then masks, blocks or flags content for review according to defined policies.
CID222 detects personal, financial and enterprise-sensitive data, as well as secrets such as API keys, passwords and private keys, in input and output flows. It supports masking, blocking or flagging this information according to defined policies.
CID222 applies data security, content control and audit policies to model calls made by AI agents through the gateway.
CID222 captures requests, responses, detections and applied policy decisions in an auditable record structure.
In multi-model and agent environments, centralized monitoring of token consumption, providers and usage rules supports cost control. CID222 brings model and usage data together in a single control layer.
Supports the use of providers such as OpenAI, Anthropic, Google Gemini and Azure OpenAI through a shared gateway, and centralized management of the models enabled for the organization.
Makes the token usage and cost impact of calls passing through CID222 visible by user, application and model.
Supports consistent enforcement of quota, access and model-usage rules across AI interactions.
Let’s assess how CID222 can be adapted to your current AI usage, security policies and technology architecture.
Request a demo ↗Add CID222 to your portfolio and let’s develop opportunities in enterprise AI security and governance together.
Explore the Partner Program ↗