AI oversight for business

Your team is already using AI. Are they putting your company at risk?

Customer lists. Financials. Contracts. Employee records — pasted into ChatGPT and Copilot every day by people just trying to work faster. CircleScope shows you exactly what’s leaving, flags what’s risky, and turns it into a quiet word with the person involved. Nothing blocked. Nobody interrupted.

on-device redactionno blocking, no interruptionsalert → your ticketing system in minutesyour data never trains AIshadow AI discovery built inone-script deploy — no reboot
The reality

The exposure is already here.

Independent research on how employees actually use AI at work — and what it costs when no one is watching.

more employees use AI at work than their leaders realize.

McKinsey, 2025
42%

feed non-public company information into public AI tools.

Cisco, 2025
63%

of breached organizations had no policy governing AI use.

IBM, 2025
+$670K

added cost of a data breach that involves ungoverned “shadow” AI.

IBM, 2025

Sources: McKinsey Superagency in the Workplace 2025; Cisco 2025 Data Privacy Benchmark Study; IBM Cost of a Data Breach Report 2025.

Why this is hard to solve

Blocking AI fails. Ignoring it is worse.

Banning it backfires

Block the sites and people use their phones or personal accounts instead. You lose the productivity gains and the visibility at the same time.

The rules are catching up

Sensitive data leaving through an AI prompt is a data-handling incident. Insurers and clients have started asking, in writing, how you govern AI use.

A policy is not evidence

An AI acceptable-use policy means nothing if nobody can tell whether it’s being followed. Most companies find out through the incident itself.

What that looks like in practice

One afternoon, start to finish.

Illustrative example.

2:14 PMSomeone in billing pastes a customer spreadsheet into ChatGPT to clean up the formatting. It contains hundreds of Social Security numbers. She isn’t doing anything malicious — she’s trying to finish before the end of the day.
InstantlyEvery Social Security number is stripped out on her laptop, before anything leaves the building. CircleScope never receives one, so there is nothing sensitive on our side to lose.
Under a minuteThe event is flagged as critical. Your IT team and whoever you designate get an email explaining what happened, why it matters, and how to raise it.
That afternoonHer manager has a two-minute conversation. It gets logged and closed. No blocked tool, no help-desk ticket, no breach notification. Next month it’s a line in your report instead of a problem.
How it works

Three pieces. Deployed in minutes.

01 · CAPTURE

A silent browser extension, plus a Microsoft 365 connection

Deployed by IT policy to managed Chrome and Edge — employees can’t remove it — the extension watches the major AI services (ChatGPT, Claude, Gemini, Copilot, Perplexity) and nothing else: no browsing history, no keystrokes, no screenshots. For Copilot inside Teams, Outlook, Word, and the Edge sidebar there is nothing to install at all: one admin consent connects your Microsoft 365 tenant, read-only, and Copilot activity starts arriving the same day — on every device, managed or not.

02 · SCORE

An AI risk pipeline

Every prompt is scored 0–100 and classified — PII, PHI, credentials, source code, financials, HR, legal. High-severity incidents get an AI-written summary: what happened, why it matters, and the suggested coaching conversation.

03 · ACT

Alerts where you work

Email digests within a minute, tickets straight into your PSA, branded PDF reports for QBRs and compliance reviews — and a portal for triage, review notes, and the audit trail that proves you looked.

Security & privacy

What we look at, and what we don’t.

What CircleScope sees

  • What people type into ChatGPT, Claude, Gemini, Microsoft Copilot, and Perplexity
  • The name, size, and type of files they upload there
  • Copilot activity inside Microsoft 365 — who used it, where, whether it searched the web, and which files it read. Prompt text too, for users licensed for Microsoft 365 Copilot
  • Which third-party AI apps have been granted access to your Microsoft 365 data — meeting bots, AI connectors, “assistants” — and whether an admin approved it or an employee clicked through
  • Which other AI tools are being used — by site name only, so you learn about them early

What it never touches

  • Regular web browsing, email, or any other tab
  • Keystrokes, screenshots, passwords
  • Camera, microphone, location
  • The contents of any file
  • Copilot’s answers — we record what was asked and what was read, never what Copilot wrote back

Redacted before it leaves

Social Security numbers, payment cards, and API keys are stripped on the device, before transmission — our servers never see them.

Your data never trains AI

Risk scoring runs under agreements that prohibit training on your data — and it’s never sold or used for advertising.

Coverage keeps itself current

When AI sites redesign or new tools appear, detection updates from the server — no redeployment, no waiting on an agent update. Microsoft 365 coverage needs no agent at all, so it reaches the phones and unmanaged devices an extension never can.

Want the full picture — retention, tenancy, deployment, and honest coverage boundaries? Read the technical overview.

What you get back

A dashboard instead of a surprise.

  • An early warning. The serious events reach a human in under a minute, not at the end of the quarter.
  • A paper trail. Every flagged event shows what was seen, what was decided, and what was done about it.
  • Who has access to your Microsoft 365. Every third-party AI app holding a connection to your tenant, what it can reach, and whether an administrator approved it or an employee clicked through — with the ones nobody uses any more easy to remove.
  • A report you can hand over. Branded PDFs for board meetings, audits, and client reviews — including the connected-apps list, ready to send.
  • Employees who are told. Managed company devices only, under your acceptable-use policy — we ship the disclosure language with it.
For MSPs

A new service line that runs itself.

White-label the portal and reports under your brand, deploy through the RMM you already run, and wire it into your PSA — CircleScope is purpose-built for the MSP stack.

Partner Program: discounted licenses · protected pricing · white-label · PSA integration

Alerts become tickets

Native PSA integrations — Autotask, ConnectWise, HaloPSA: qualifying alerts open fully-detailed tickets on the right company, queue, and priority — your techs triage without leaving the board.

Invoices write themselves

Monthly endpoint counts sync to your PSA contracts as one clean adjustment — bill the real number with zero reconciliation, and no over-deployment penalties, ever.

Deploy in an afternoon

One PowerShell script, four paths — any RMM, Intune, GPO, or manual. Per-customer enrollment keys, revocable instantly. Devices appear in minutes; offline machines queue and sync.

Become a partner
Pricing

Per endpoint. Metered to reality.

Fleet sizePer endpoint / month
1 – 50 endpoints$5.00 / endpoint / mo
51 – 100$4.44 / endpoint / mo
101 – 250$4.11 / endpoint / mo
251 – 500$3.75 / endpoint / mo
501 – 1,000$3.40 / endpoint / mo
1,001+Get a quote

Month-to-month at full retail — cancel any time. Commit to 12 months and save 10%.

Billing follows your actual monthly endpoint count — devices that stop reporting age out of billing automatically. Includes AI analysis of up to 1,000 prompts per endpoint per month, pooled across your fleet (roughly 9× typical heavy usage) — we notify you as pooled usage approaches the allowance, and capture and alerting never pause. 14-day pilot. MSPs: the Partner Program includes discounted licensing, white-label, and PSA integration — see the program.

Start now — 14-day pilot

Sign up with your work email, add a card, and deploy today. Walk away any time in the first 14 days.

Book a demo

See what your company is sending to AI.

30 minutes, your questions answered — or tour it yourself first.

Just have a question? Email us instead.

Know what your company sends to AI — starting tomorrow.

Ten computers, fifteen minutes, and you’ll have real answers by tomorrow. 14-day pilot, no commitment.

Start your 14-day pilotBook a demo