Upload a DNS, proxy or firewall export. Get back every AI tool reached from your network, matched against 20,399+ AI-tool domains. No agent, no SSL inspection, first results in minutes. By Alpha Quantum, the team behind the AI Tools Blocklist.
Every hostname in your export is checked against the full commercial database, subdomains included. Not a hobby list from GitHub.
Umbrella, Zscaler, Palo Alto, Fortinet, Cloudflare Gateway, NextDNS, DNSFilter, Pi-hole, SonicWall, Squid, plain CSV. Upload and go.
Trains-on-your-data · sovereignty · NSFW · deepfake/abusive. Know which findings are dangerous, not just which exist.
We read the vendor terms so you do not have to. Every verdict carries the date the terms were checked.
Category totals, risk counts and the top findings from a 5,000-line export. Email address is all it takes.
Every tool, every user, sanctioned split, CSV and PDF. One-time, no subscription. Cheaper by 3s and 5s.
Staff adopt chatbots, code assistants and file converters long before IT hears about them. Policy documents and blocking rules come second. The first question is what is actually in use today.
Staff sign up with corporate email the moment a tool trends, and grant OAuth access to mailboxes and drives. Most of it never touches procurement. By the time IT notices, sensitive data has already crossed the perimeter.
700+ AI tools train on customer input by default, and 85.5% say nothing about training at all. For GDPR, HIPAA or client-confidential data, a single paste can be a reportable event.
Compliance frameworks and cyber-insurance questionnaires increasingly demand evidence of AI-usage controls. "We blocked ChatGPT" is not an answer when thousands of alternatives exist.
Asking staff which AI tools they use produces the list they think you want to hear. DNS and proxy logs record what actually happened, hostname by hostname.
Consulting-led shadow AI assessments take weeks and are quoted in the thousands. The same evidence already sits in the logs your network writes every day.
Every finding is tied to a hostname seen in your own logs. These example rows use the same real classifications as the 4-page sample report: flip through it before you upload anything.
| domain | category | sovereignty | abusive | trains_on_your_data | users | sanctioned |
|---|---|---|---|---|---|---|
| chatgpt.com | General assistants & chatbots | low | none | yes | 41 | yes |
| openai.com | Foundation models & APIs | low | none | no | 7 | yes |
| deepseek.com | Foundation models & APIs | high | none | yes | 3 | no |
| fireflies.ai | Meeting assistants | low | none | opt-out | 12 | no |
| deeplivecam.net | Face swap & effects | unknown | deepfake | unknown | 1 | no |
| crushon.ai | AI companions & character chat | unknown | nsfw | yes | 2 | no |
Note rows one and two: chatgpt.com trains on your data and openai.com's API does not. That nuance, on every row, is what turns a domain list into a decision.
Category totals, risk counts and a fifth of the tools found, at least five. Every withheld tool appears as its own masked row, so you count exactly what is missing. Preview PDF included.
Every tool named, the per-user breakdown, the sanctioned vs unsanctioned split against your own approved list, CSV export and the PDF evidence pack.
Each vendor verdict carries the date its terms were checked, from a register of 13,000+ reviewed policies. Evidence an auditor can actually cite.
The audit runs on files your network equipment already produces. Nothing is installed and nothing is inspected in transit.
Take a DNS, proxy or firewall export covering a normal week. A CSV, syslog file or plain hostname list all work.
Create a free account with an email address and upload. The file is parsed in one pass and discarded.
Minutes later: totals by category, risk counts and the top findings, with the rest shown as withheld rows.
Unlock the full report when it finds something worth chasing. Re-run quarterly to track drift.
Start free and unlock the complete report only if the preview finds something worth chasing. Reports are one-time PayPal purchases; credits stay in your account until used.
| Free preview | Full report | |
|---|---|---|
| Totals by category and risk flags | included | included |
| AI tools named | a fifth of those found, at least five | all of them |
| Per-user breakdown | withheld | included |
| Sanctioned vs unsanctioned split | withheld | included |
| Vendor training verdicts, dated | on named tools | every tool |
| preview PDF | full evidence pack | |
| CSV export | no | yes |
| Export size | 5,000 lines / 2 MB | 2,000,000 lines / 25 MB |
| Price | $0 | $99, less in packs |
Running audits monthly? The plans on aitoolsblocklist.com include 1 to 10 full audits a month, and the MSP plan labels each report with the client name. Larger exports are handled on request.
Detection is only as good as the list behind it. Ours is maintained daily as a commercial product, distilled from a 120M-domain corpus, not scraped once from a directory.
Explore the research behind the audit: the Policy Silence Index, training-terms verdicts and where AI tools send your data.
The same audit answers a board question, a compliance finding or a client engagement.
Turn a suspicion into a dated inventory before the next board or risk meeting. Track the unsanctioned count quarter over quarter.
Typical run: last week's DNS export, full report, PDF to the boardEvidence of which vendors receive staff input and what their terms say about training, each verdict dated. Feeds DPIAs and AI registers directly.
Typical run: proxy export with usernames, CSV into the registerDeliver shadow AI assessments as a paid engagement without building tooling. The MSP plan includes 10 audits a month, each labeled with the client name.
Per-report cost: from $24.90 on the MSP plan, $60 in the 5-packYou already own the log source. Twenty minutes end to end, no new vendor onboarding, and the findings map straight onto your existing filtering policy.
Follow-up: block the findings with the AI Tools BlocklistCASB and endpoint platforms are excellent at continuous enforcement. The audit answers a different question: what is already happening, today, with zero deployment.
| Shadow AI Audit | CASB / SSE discovery | Endpoint agents | Staff survey | |
|---|---|---|---|---|
| Time to first result | minutes | weeks of deployment | weeks of rollout | days, then follow-ups |
| Needs installation | nothing | proxy or API integration | agent on every device | nothing |
| AI-specific intelligence | 20,399+ tools, 4 risk flags | generic app catalog | process-level only | none |
| Training-terms verdicts | 13,000+ vendors, dated | not covered | not covered | not covered |
| Measures actual behavior | yes, from logs | yes, once deployed | yes, once deployed | self-reported |
| Cost to try | $0 | enterprise licensing | per-seat licensing | staff time |
Already running a CASB? Run the audit on its logs. The AI-specific enrichment stacks on top of whatever you have.
The audit is designed so the sensitive artifact, your raw log, never persists on our side.
The uploaded export is parsed in a single pass and deleted. It is never stored, resold or used for anything else.
Finished reports stay in your account for 90 days, then they are removed. You can delete them earlier yourself.
A report is visible only to the account that produced it. Share it deliberately, as a PDF or CSV, or not at all.
Run the free preview on last week's export. If it finds nothing, you have your evidence. If it finds something, you will want the full report.