AI security coverage: discovery, prompts, and files
Use this factual reference to separate a known AI tool from observed employee use, prompt controls, and file controls. Every decision still needs the exact application, action, endpoint, and deployment path.
For technical evaluators who need to map a proposed environment. This is a public, bounded reference—not a universal feature matrix or a substitute for a current test.
Read coverage by state, not by a green tick
Start with the employee surface. Then separate four different facts: a tool may be catalogued, usage may be observed on a deployed route, a prompt action may be evaluated, and a file action may have documented scope. None automatically proves the next state.
Name the environment
Bring the app, employee interface, OS/browser, deployment option, action, and file type being considered.
Classify the state
Separate catalogued, observed, prompt-action, and file-action evidence instead of treating them as one coverage claim.
Close the gaps
Run a current synthetic test for unverified paths and record the result with an evidence date.
Coverage states used on this page
- Catalogued: the AI tool is recognised in Aona’s 10,000+ tool catalogue. This is not usage observation or enforcement.
- Observed: activity can be evaluated only on the agreed, deployed endpoint path; it is not a claim about every device or app interface.
- Prompt/file action: assess the exact application, surface, data type, and policy response in a current synthetic test.
Public coverage states
| Scope | Public state | What to verify |
|---|---|---|
| AI tool catalogue | Catalogued · 10,000+ tools | Catalogue recognition is not observed use or enforcement. |
| Employee activity | Conditional · managed endpoint path | Browser, OS, deployment state, and the exact surface. |
| Prompt action | Evaluate per app and action | Typed/pasted path, policy response, and recorded evidence. |
| File redaction | Documented formats · DOCX, XLSX, PDF | Upload route, modified-file behavior, and unsupported or unusual content. |
| macOS managed install | Not shipped at last verification | Current MDM availability before adding macOS to a pilot. |
This reference is deliberately bounded. Product and security should validate the exact row for a proposed environment and record the evidence date before a coverage claim is used in a rollout decision.
Important boundaries
No unexplained blanks should be read as support. An unverified path remains unverified until product and security review it.
DOCX, XLSX, and PDF are documented redaction formats; file behavior still needs route-specific validation.
The catalogue is not a universal-enforcement list, and the page does not claim app, OS, browser, plan, or native coverage that has not been verified.
Useful evidence and next steps
Questions to resolve before a pilot
Map coverage for your environment
Bring the app, surface, endpoint, policy action, and file type you need to evaluate. We will map the current evidence and name what remains unverified.