30 Days Gen AI Risk Trial -Start Now
Skip to main content

THE RIGHT PRODUCT. THE RIGHT PLACE.

Secure AI where
your team works.

Browser plugin, desktop apps or APIs. Start with what you want to secure, not a product checklist.

Compare advantages & trade-offs
START WITH

Browser plugin

Browser coverage

  • Chrome
  • Edge
  • Safari

Prompt and file coverage varies by site and input path.

AI website · supported path
EMPLOYEE PROMPT

Draft a renewal note for Maya Patel.
Account 481-209.

Aona policy check

A checkpoint before sending.

Review a sensitive-data rule on this supported submission path.

Text and identifiers ready for evaluation
Inside the browser interaction
InputCheckResponse

Synthetic illustration · no prompt is sent.

Example ready. No prompt is sent.

Browser coverage, not protection for every app on the device.

Find the right fit

COMPARE THE THREE PRODUCTS

Different entry points.
A clearer decision.

You can combine products. Match each one to an actual workflow, then verify the coverage that matters to you.

Browser plugin, Windows/macOS apps and APIs: platform coverage, advantages, trade-offs and rollout.
Your decisionBrowser pluginWindows / macOS appsAPIs
Best fitEmployees using AI websitesManaged computers using native AITeams building an AI integration
Platforms & scopeGoogle Chrome · Microsoft Edge · SafariChatGPT, Claude, Gemini and Copilot / Bing web experiences. Prompt and file actions depend on the supported site and input path.Windows x64 · macOS · Apple SiliconSupported browser and native AI traffic. Validate the provider, prompt or file action, operating system and installed release together.Your applications · Scripts & agents · Backend workflowsCalls explicitly integrated with Aona evaluation APIs. Your application receives the verdict and applies the resulting decision.
Advantages
  • Policy feedback inside the AI page
  • Prompt checks and supported file redaction
  • Focused rollout for browser-based AI use
  • Coverage beyond browser-only interactions
  • A device-level path for supported AI traffic
  • Local agent and MCP visibility in limited rollout
  • Choose the checkpoint in your own workflow
  • Evaluate text and supported files
  • Use returned verdicts and redactions in your application
Trade-offs
  • Does not cover native apps or local agent inspection
  • Requires the plugin in the browser being used
  • Firefox release is not confirmed; validate each browser and input path
  • Requires device installation, proxy and certificate setup
  • Protection depth differs by app, OS and release
  • Agent inspection is not automatic control of every action
  • Engineering must apply the verdict and handle failures
  • Unintegrated model or tool calls are outside this path
  • Stateless evaluations do not create an analytics event
RolloutDeploy the extension for Chrome, Edge or Safari. Confirm the rollout method for your selected browser.Windows: Intune or direct install. Mac: assess the manual package rollout.Connect the evaluation call and implement the response handling.

Browser plugin

Employees using AI websites

Google Chrome · Microsoft Edge · Safari

ChatGPT, Claude, Gemini and Copilot / Bing web experiences. Prompt and file actions depend on the supported site and input path.

Advantages

  • Policy feedback inside the AI page
  • Prompt checks and supported file redaction
  • Focused rollout for browser-based AI use

Trade-offs

  • Does not cover native apps or local agent inspection
  • Requires the plugin in the browser being used
  • Firefox release is not confirmed; validate each browser and input path
Rollout details

Deploy the extension for Chrome, Edge or Safari. Confirm the rollout method for your selected browser.

Windows / macOS apps

Managed computers using native AI

Windows x64 · macOS · Apple Silicon

Supported browser and native AI traffic. Validate the provider, prompt or file action, operating system and installed release together.

Advantages

  • Coverage beyond browser-only interactions
  • A device-level path for supported AI traffic
  • Local agent and MCP visibility in limited rollout

Trade-offs

  • Requires device installation, proxy and certificate setup
  • Protection depth differs by app, OS and release
  • Agent inspection is not automatic control of every action
Rollout details

Windows: Intune or direct install. Mac: assess the manual package rollout.

APIs

Teams building an AI integration

Your applications · Scripts & agents · Backend workflows

Calls explicitly integrated with Aona evaluation APIs. Your application receives the verdict and applies the resulting decision.

Advantages

  • Choose the checkpoint in your own workflow
  • Evaluate text and supported files
  • Use returned verdicts and redactions in your application

Trade-offs

  • Engineering must apply the verdict and handle failures
  • Unintegrated model or tool calls are outside this path
  • Stateless evaluations do not create an analytics event
Rollout details

Connect the evaluation call and implement the response handling.

Tool names alone do not establish coverage. Confirm the interface, action, operating system and release.

ONE ORGANISATION. DIFFERENT PATHS.

You don’t have
to choose only one.

A browser-based team, a native AI workflow and an internal agent can need different control points.

Check the coverage reference
AI websiteBrowser plugin
Native applicationDesktop apps
Integrated AI workflowAPIs

Keep the boundary clear: inspection, evaluation and enforcement are not interchangeable.

YOUR INFRASTRUCTURE, TOO

Choose the product.
Then choose where it runs.

Backend hosting and prompt processing are separate decisions. Confirm the supported configuration for your features.

01

Backend hosting

Your cloud / On-premises / Aona-managed

02

Prompt processing

User device (edge) / Your cloud or on-premises / Aona-managed

This does not determine where the destination AI provider processes data.

Review deployment options

Meet the guardrail models behind supported sensitive-data and policy checks.

Explore Orbital Models

BEFORE YOU DECIDE

The details that
change the choice.

Bring your apps, devices and one representative workflow. We’ll help scope the right evaluation.

Event API & webhook docs

For reporting integrations, not prompt evaluation instructions.

Which Aona product should we start with?

Start with the workflow you need to protect. Choose the browser plugin for supported AI websites in Chrome, Edge or Safari, the Windows/macOS app for supported desktop traffic, or APIs when your team owns the application checkpoint. A mixed environment may need more than one product. Validate a representative prompt or file before expanding the rollout.

Can the browser plugin and desktop app run together?

Yes. They are separate endpoint products designed to run together. Supported coordinated paths mark requests already processed by the plugin so the native app can avoid processing them again. Confirm this behavior with the client versions and specific request path in your rollout.

Which AI platforms can the desktop app secure?

Coverage is provider-, action-, operating-system- and release-specific. ChatGPT, Claude, Microsoft Copilot, M365 Copilot, Gemini, Cursor and Codex appear in the audited native provider matrix, but that source/staging matrix is not proof of uniform production support. Cursor and Codex have narrower paths; do not assume file, response or agent tool-action coverage. Ask us to verify the installed release against your exact workflow.

Does an API integration automatically block unsafe AI calls?

No. Framework and guardrail APIs evaluate submitted text; framework APIs also check supported files. Your application must apply the verdict, use any returned redaction, and decide how to handle timeouts or errors before continuing. Calls that bypass your integration are not covered. These stateless evaluation endpoints do not automatically record an analytics event.

Are policy evaluation APIs the same as the event API and webhooks?

No. Evaluation APIs check supplied text against a framework or guardrail, or supported files against a framework. The event API and outbound webhooks deliver existing security-event evidence to your systems. Reading events or receiving a webhook does not, by itself, intercept or block an AI request.

Are Safari, Firefox, mobile devices and Intel Macs supported?

The browser plugin supports Chrome, Edge and Safari. Prompt and file coverage depends on the AI site and input path; confirm your chosen browser and rollout method. Firefox requires release verification before being treated as shipped. The native targets covered here are Windows x64 and Apple Silicon Macs. Do not assume Intel Mac, Linux, iOS or Android endpoint coverage. APIs can be integrated into an application workflow, but that does not create device-wide protection.

Can Aona run in our cloud or on-premises?

Yes. Aona backend hosting can use your cloud, your on-premises environment or Aona-managed servers. Separately, prompt processing can run on the user device (edge), in your cloud or on-premises, or on Aona-managed servers. Confirm the supported feature and integration configuration; the options do not imply identical capabilities everywhere. A third-party AI provider's processing remains a separate consideration.

A DEMO BUILT AROUND YOUR WORK

Bring one workflow. Find your fit.

Tell us the AI tool, the device and the action you want to protect. Compare the right product and see what needs validating.

Compare Aona Products: Browser Plugin, Desktop Apps & APIs