No agent, no browser extension, no network change. You upload an export your stack already produces, and every hostname is matched against a live register of 20,399 AI tool domains.
Most teams finish their first audit in under 20 minutes. The slowest step is usually finding who owns the log console.
Decide the period the audit should answer for. A week shows habits, a quarter shows trends.
Pull a CSV or syslog export from the DNS filter, proxy or firewall you already run.
The parser detects the format, reads hostnames and identities, and discards the file after the run.
Every matched AI tool with category, risk level, training verdict and who reached it.
The window decides what question your report answers. Pick it before you touch the export screen.
Rule of thumb: audit the same window you report on. If leadership asks quarterly questions, a 7-day export will undersell the exposure.
Any log that records hostnames works. You do not need every field, and you do not need to clean it up first.
Cisco Umbrella, Cloudflare Gateway, DNSFilter, NextDNS, Pi-hole. Query logs with domain plus identity.
Zscaler, Squid. URL-level records, the richest per-user evidence.
Palo Alto, Fortinet, SonicWall. Web-filter or URL logs, CSV or key=value syslog.
Any CSV with a header row, or a plain list with one hostname per line.
One column matters more than the rest: identity. If the export carries a user, device or source IP column, the report adds a per-user breakdown.
A generic CSV export. Highlighted rows are the ones the audit will match. See the per-platform guides for what your vendor's export looks like.
Drop the file on the upload panel. Everything after that is automatic.
CSV headers, key=value syslog and plain hostname lists are recognized automatically. No mapping screens.
URLs are reduced to hostnames. Duplicates collapse into hit counts per domain.
A hostname is matched at the most specific level first, then walked up. Our methodology page explains why that matters.
| Limit | Free preview | Full Audit Report |
|---|---|---|
| File size | 2 MB | 25 MB |
| Lines per export | 5,000 | 2,000,000 |
| Runs | 1 a day, 3 a month | Per purchased report or plan allowance |
| Larger exports | Handled on request via contact |
The uploaded file is read once and discarded. It is never stored or reused. The finished report stays in your account for 90 days and can be deleted earlier.
Every section exists to answer one question a stakeholder will actually ask.
A slice of the tool table, sample data.
Tools found, high-risk count, training exposure, abusive-purpose tools, unsanctioned count. The one-glance version for leadership.
Every matched tool with category, risk level, data-sovereignty flag and the vendor's training verdict, dated to when the terms were checked.
Your approved-tool list against reality. What is sanctioned, what is tolerated, what nobody knew about.
When the export carries identities: which users or devices reached which tools, with hit counts. Full report only, plus CSV export.
Each has a shorter answer than you expect.
The audit still works. You get the full tool inventory by hits; only the per-user table needs an identity column.
Shorten the window or filter to allowed traffic. Above 25 MB, ask us, larger exports are handled on request.
Then the audit is your proof. Blocked categories still show attempts, and embedded AI domains often slip past category filters.
The file is read once, in memory, and discarded. No log content appears in the report beyond matched hostnames and identities.
The sample report is a real evidence pack on sample data: summary tiles, the tool table, the per-user breakdown and the control evidence statement. Three pages, no signup.
The report sorts every tool into one of three moves. That is the meeting agenda, written for you.
Tools that are already safe enough, or worth an enterprise tier. Add them to the approved list so the next audit measures policy, not guesswork. See sanctioned vs unsanctioned.
Tools allowed only with conditions: SSO, no-training terms, logging. Usually the biggest group in the report.
High-risk and abusive-purpose tools. Why this comes last, not first: detect before you block.
Sample data, but a realistic Tuesday. This is what the four steps look like when someone actually does them.
That report, on the same sample numbers, is the exact PDF your board would receive. Flip through it here.
Each column exists because someone has to make a decision with it. Here is the decision each one feeds.
| Column | What it tells you | The decision it feeds |
|---|---|---|
| Domain | The AI tool's hostname as seen in your log. | The unit everything else attaches to. |
| Category | One of 18 functional categories, from text and code to image and agents. | Which department conversation this belongs in. |
| Risk level | The register's combined risk rating for the tool. | Sort order for the triage meeting. |
| Training on user data | The vendor's stated position, with the date the terms were checked. | Whether pasted content may become training data. |
| Data sovereignty | A flag for jurisdictions rated high exposure. | Legal and procurement escalation. |
| Abusive purpose | Deepfake, nudify, NSFW or uncensored generation flags. | Immediate block candidates, HR involvement. |
| Sanctioned | Whether the tool is on the approved list you provided. | Policy compliance measurement. |
| Hits and users | Volume, and how many identities reached the tool. | Whether this is one curious person or a department habit. |
Risk level and training verdict disagree sometimes, and that is intentional. A low-risk tool can still train on your data, and a high-risk tool can have clean terms.
Knowing the edges makes the results defensible in front of an auditor or a skeptical CISO.
The audit reads hostnames and identities, never what anyone typed. That is a feature: no new sensitive data store is created.
Phones on cellular data and home networks bypass your log source. The audit measures the network you actually log.
Training verdicts summarize vendor terms on a stated date. They feed your review; they do not replace counsel.
The audit is read-only evidence. Enforcement stays in your existing stack, informed by the findings.
Mixed lines, odd delimiters and noise are expected. Unparseable lines are skipped and counted, not fatal.
One upload produces one report. There is no resident collector and nothing to uninstall.
The identity column has a different name in every console. This table saves you the search.
| Log source | Typical identity field | Per-user table possible |
|---|---|---|
| Cisco Umbrella | Identities column in the activity CSV | Yes, users and devices |
| Zscaler | User field in web logs | Yes, users |
| Palo Alto | src_user in URL logs | Yes, when User-ID is on |
| Fortinet | user= in web-filter syslog | Yes, when authentication is on |
| Cloudflare Gateway | User email in DNS or HTTP logs | Yes, users |
| DNSFilter / NextDNS | Profile or device name | Devices rather than users |
| Pi-hole | Client IP in the query log | Per device, via IP |
| SonicWall | usr= in syslog | Yes, when SSO agent runs |
| Squid | Third field of access.log | Yes, when proxy auth is on |
| Plain hostname list | None | No, inventory only |
Every source above has a dedicated walkthrough, starting with Cisco Umbrella and Zscaler. Each one covers the export shape, the fields that matter and a worked scenario.
Rough line counts per window, so you can pick the right tier before exporting.
These are planning numbers, not limits. Pre-filtering the export to allowed web traffic shrinks any of them dramatically.
Three roles run most audits, each with a different first question. All three read the same report.
Owns the log console, so the whole loop is self-service. First question: which tools do we not know about? The IT manager page covers the operator angle.
Wants the dated inventory and the quarter-over-quarter trend. First question: what changed since last time?
Needs evidence that stands up in an audit file. First question: when were these vendor terms checked?
Five checks before you hit export save the second attempt.
Reporting to a quarterly meeting? Export the quarter, not last week.
Tick user, device or source IP in the export options if your console offers it. It unlocks the per-user table.
An export of blocked-only events measures your filter, not your exposure. Include allowed traffic.
Free preview: 5,000 lines or 2 MB. Full report: 2,000,000 lines or 25 MB. Trim the window if you are over.
Optional, but pasting your sanctioned tools before the run turns the report into a policy scorecard.
Uploading and matching takes minutes. Most of the 20-minute total is exporting the log from your console.
No. There is no agent, no browser extension and no network change. The audit reads an export your stack already produces.
Any CSV with a header row works, and so does a plain list of hostnames. The parser detects the shape automatically.
Totals by category, risk-flag counts and a fifth of the tools found, at least five, named. The rest appear as withheld rows. Details on the free audit page.
Yes, and you should. Repeat the same window monthly or quarterly and the reports become a trend line.
One-time purchases from $99, no subscription. Packs and plan inclusions are on the pricing page.
The second report is worth more than the first. It turns a number into a direction.
Run the first full report. File the PDF, load the CSV into your risk register, set the sanctioned list.
Same window, same source. New tools since the baseline are your early-warning list.
Tools you blocked should show attempts falling toward zero. If they do not, the control is leaking.
Three reports make a trend line for the board. Plans on the pricing page include monthly audits for exactly this loop.
Keep the export window and source constant between runs. Change one variable at a time, or the trend line stops meaning anything.
The free preview needs only an email address and a log export. You will have your first shadow AI inventory today.
Start the free audit