Platform
CLS++ sits between your staff and whichever AI they already use. It captures the interaction, seals it on the device, and writes it to an append-only ledger you can hand to an auditor.
Architecture
Extension or MCP client intercepts the interaction, derives keys locally, and encrypts under ZPML before any network call.
Encrypted index supports retrieval without decryption. We hold no key capable of reading your content.
Decryption happens client-side for your authorised users. Auditors receive a hash-chained export in your region.
Capture surfaces
Gateways see traffic. Vendor consoles see their own API. Neither sees an employee on a personal login — which is where most of your exposure actually sits.
47 KB, deployed by group policy or MDM. Detects ChatGPT, Claude and Gemini sessions, including personal accounts on managed devices.
Registers as a connector in Claude Desktop, Cursor and Cline. Agent tool calls and their results enter the same ledger as chat.
Three endpoints for anything you build yourself — internal copilots, support tooling, batch agents. Any language, any model.
Audit console
Metadata is queryable by anyone with the right role. Content stays sealed until an authorised user decrypts it locally, and that decryption is itself an entry in the log.