Polygraf operates simultaneously across four distinct interception layers — OS, API, communication, and document — ensuring no sensitive data escapes, regardless of path.
Coverage
Every path sensitive data can take is covered. Polygraf sits between the user and the destination at every layer simultaneously.
Desktop Overlay
Secure LLM
Meeting Guard
Secret Marker
Governance Dashboard
All layers report here — policies, alerts, audit logs
Data Flow
From the moment a user acts to the moment a response returns — every step protected.
STEP 2
Polygraf intercepts at the appropriate layer before any transmission occurs
STEP 3
SLM identifies entity types with context-aware detection — 49+ entity types
STEP 4
Cross-reference with org policies — allow, block, or anonymize based on group/role rules
STEP 5
PII replaced with reversible tokens e.g. [PERSON_1], [SSN_1] — original data never transmitted
STEP 7
Tokens replaced with originals in the response returned to user — seamless experience
Design Principles
All SLMs run on-premises. Zero external API calls for processing.
Each layer operates independently. One component down does not disable others.
Policies default to deny-all. Access is explicitly granted per group, role, and entity type.
Every event is cryptographically signed and stored in tamper-evident logs.
No external dependencies
Zero outbound network calls
No cloud telemetry
Via signed package delivery
FAQ
The Desktop Overlay requires a lightweight client on endpoints. Secure LLM, Meeting Guard, and Secret Marker are agentless — they operate at the network/API level or via integration hooks. Most organizations deploy selectively based on their highest-risk surfaces first.
Each layer supports configurable fail-open or fail-closed modes. In fail-open, traffic flows through unimpeded while alerting your team. In fail-closed, interactions are blocked until the system recovers. The mode is set per-layer and per-policy.
Yes. The Governance Dashboard exports events via syslog, webhooks, and native integrations for Splunk, Microsoft Sentinel, IBM QRadar, and other major SIEMs. All log formats are configurable.
Yes. Policies are configurable at the org, department, group, and individual user level. Each policy can have its own entity types, thresholds, and enforcement actions.
Polygraf ships as a Helm chart. Each component (Secure LLM proxy, Secret Marker scanner, Meeting Guard listener, Governance Dashboard) deploys as independent pods with configurable resource limits. Horizontal scaling is supported.
For the Secure LLM proxy layer, average added latency is under 80ms measured on standard server hardware. Desktop Overlay adds imperceptible latency (<20ms) at the OS level. Meeting Guard operates asynchronously and does not add latency to the call.
We'll walk your security team through the full technical design
© 2026 Polygraf AI. All rights reserved.
Your download will start now.
Please provide information below and we will send you a link to download the white paper.