Why Prism checked what you sent

Your organisation uses Prism DLP to keep sensitive information out of AI tools. You saw its message because something you pasted, uploaded or sent looked like it shouldn't leave. You haven't done anything wrong by seeing it.

What happened

Before the AI tool received it, Prism checked the content for things like passwords and API keys, card or bank numbers, NHS and National Insurance numbers, dates of birth, and other details your organisation has asked it to look for. The message told you what it found and where it was going.

What you can do

Send it without the sensitive parts
If offered, Prism swaps each sensitive value for a placeholder like [EMAIL_1] and sends the rest. Usually the AI tool can still help.
Continue with a reason
If you're asked for a reason, say why it's fine to send this here. Your security team can read it.
Use the approved tool
If the AI tool isn't allowed, the message may suggest one that is. Your company's account usually comes with better protection for your data.
Ask for an exception
If you genuinely need to do this for your job, ask your IT or security team. They can allow it for you for a set time. Please don't work around Prism.

What's kept, and who sees it

  • Your security team sees that it happened: who, which AI tool, what kind of information, and what you chose.
  • The sensitive values themselves aren't kept. They're replaced with placeholders before anything is stored.
  • Prism doesn't record your keystrokes, your screen or your browsing. It only checks what you paste, upload or send to the AI tools your organisation chose.

Full details are in the privacy policy.

Questions?

Ask your IT or security team: they decide what Prism checks at your organisation and can change it. We make Prism, but we can't see your messages or change your organisation's settings.