How it works

From a log export to a shadow AI inventory, in four steps

No agent, no browser extension, no network change. You upload an export your stack already produces, and every hostname is matched against a live register of 20,399 AI tool domains.

20,399AI tool domains matched against
18functional categories in the register
4steps from export to evidence
90 daysreport retention, deletable earlier
The whole process

Four steps, one afternoon

Most teams finish their first audit in under 20 minutes. The slowest step is usually finding who owns the log console.

1

Pick an export window

Decide the period the audit should answer for. A week shows habits, a quarter shows trends.

2

Export the log

Pull a CSV or syslog export from the DNS filter, proxy or firewall you already run.

3

Upload it

The parser detects the format, reads hostnames and identities, and discards the file after the run.

4

Read the report

Every matched AI tool with category, risk level, training verdict and who reached it.

Step 1

Choosing the export window

The window decides what question your report answers. Pick it before you touch the export screen.

7 days

  • Answers: what is in active use right now.
  • Best for a first look or a spot check after a policy change.
  • Smallest files, well inside the free preview cap.

30 days

  • Answers: what a normal month looks like.
  • Catches weekly and month-end patterns the 7-day window misses.
  • The most common choice for a full report.

A quarter

  • Answers: is usage growing, and where.
  • Pairs with quarterly reviews and board reporting.
  • Larger networks may need the 25 MB full-report ceiling.

Rule of thumb: audit the same window you report on. If leadership asks quarterly questions, a 7-day export will undersell the exposure.

Step 2

Getting the export

Any log that records hostnames works. You do not need every field, and you do not need to clean it up first.

DNS filters

Cisco Umbrella, Cloudflare Gateway, DNSFilter, NextDNS, Pi-hole. Query logs with domain plus identity.

Proxies and SWGs

Zscaler, Squid. URL-level records, the richest per-user evidence.

Firewalls

Palo Alto, Fortinet, SonicWall. Web-filter or URL logs, CSV or key=value syslog.

Anything else

Any CSV with a header row, or a plain list with one hostname per line.

One column matters more than the rest: identity. If the export carries a user, device or source IP column, the report adds a per-user breakdown.

timestamp,identity,domain,action 2026-09-15T09:12:04Z,ENG\j.keller,chatgpt.com,allowed 2026-09-15T09:12:31Z,ENG\j.keller,github.com,allowed 2026-09-15T09:14:02Z,MKT\d.silva,midjourney.com,allowed 2026-09-15T09:15:47Z,FIN\a.brandt,otter.ai,allowed 2026-09-15T09:16:20Z,MKT\d.silva,canva.com,allowed 2026-09-15T09:18:09Z,10.20.4.31,deepseek.com,allowed

A generic CSV export. Highlighted rows are the ones the audit will match. See the per-platform guides for what your vendor's export looks like.

Step 3

Upload and parsing

Drop the file on the upload panel. Everything after that is automatic.

Format detection

CSV headers, key=value syslog and plain hostname lists are recognized automatically. No mapping screens.

Normalization

URLs are reduced to hostnames. Duplicates collapse into hit counts per domain.

Subdomain walk-up

A hostname is matched at the most specific level first, then walked up. Our methodology page explains why that matters.

LimitFree previewFull Audit Report
File size2 MB25 MB
Lines per export5,0002,000,000
Runs1 a day, 3 a monthPer purchased report or plan allowance
Larger exportsHandled on request via contact

The uploaded file is read once and discarded. It is never stored or reused. The finished report stays in your account for 90 days and can be deleted earlier.

Step 4

Reading the report

Every section exists to answer one question a stakeholder will actually ask.

ToolTraining on dataRiskUsers
chatgpt.comOpt-out switchmedium19
character.aiTrains by defaulthigh3
claude.aiDoes not trainlow9
otter.aiOpt-out switchmedium7
deepseek.comOpt-out switchhigh3

A slice of the tool table, sample data.

Summary tiles

Tools found, high-risk count, training exposure, abusive-purpose tools, unsanctioned count. The one-glance version for leadership.

The tool table

Every matched tool with category, risk level, data-sovereignty flag and the vendor's training verdict, dated to when the terms were checked.

Sanctioned split

Your approved-tool list against reality. What is sanctioned, what is tolerated, what nobody knew about.

Per-user breakdown

When the export carries identities: which users or devices reached which tools, with hit counts. Full report only, plus CSV export.

Objections

The four things teams worry about

Each has a shorter answer than you expect.

"Our logs have no usernames."

The audit still works. You get the full tool inventory by hits; only the per-user table needs an identity column.

"The export is too big."

Shorten the window or filter to allowed traffic. Above 25 MB, ask us, larger exports are handled on request.

"We already block AI tools."

Then the audit is your proof. Blocked categories still show attempts, and embedded AI domains often slip past category filters.

"Is uploading a log safe?"

The file is read once, in memory, and discarded. No log content appears in the report beyond matched hostnames and identities.

See what a finished audit looks like

The sample report is a real evidence pack on sample data: summary tiles, the tool table, the per-user breakdown and the control evidence statement. Three pages, no signup.

Open the sample PDF
After the audit

From findings to decisions

The report sorts every tool into one of three moves. That is the meeting agenda, written for you.

Sanction

Tools that are already safe enough, or worth an enterprise tier. Add them to the approved list so the next audit measures policy, not guesswork. See sanctioned vs unsanctioned.

Control

Tools allowed only with conditions: SSO, no-training terms, logging. Usually the biggest group in the report.

Block

High-risk and abusive-purpose tools. Why this comes last, not first: detect before you block.

Worked scenario

A 400-person company runs its first audit

Sample data, but a realistic Tuesday. This is what the four steps look like when someone actually does them.

9:05, the decision

  • The IT manager picks a 30-day window, because the CFO asked "what are we exposed to" at month end.
  • She owns the DNS filter console, so no tickets are needed.

9:12, the export

  • Activity log, last 30 days, allowed traffic only, CSV. The file is 4,400 lines.
  • It has an identity column, so the per-user table will populate.

9:16, the upload

  • Drag, drop, done. The parser reports the format, the line count and 163 distinct hostnames.
  • The file itself is discarded after the run.

9:21, the surprise

  • 37 AI tools. IT expected roughly ten.
  • 5 are high risk, 15 train on user data by default or until someone opts out, 2 are abusive-purpose tools.

9:40, the triage

  • 5 tools get sanctioned, most get "allow with controls", 5 get queued for blocking.
  • The tool table's verdict column already suggests the split.

10:00, the meeting

  • The PDF evidence pack goes to the CFO unedited. The CSV goes into the risk register.
  • The same export window is now booked as a quarterly routine.

That report, on the same sample numbers, is the exact PDF your board would receive. Flip through it here.

Column by column

What every report column means

Each column exists because someone has to make a decision with it. Here is the decision each one feeds.

ColumnWhat it tells youThe decision it feeds
DomainThe AI tool's hostname as seen in your log.The unit everything else attaches to.
CategoryOne of 18 functional categories, from text and code to image and agents.Which department conversation this belongs in.
Risk levelThe register's combined risk rating for the tool.Sort order for the triage meeting.
Training on user dataThe vendor's stated position, with the date the terms were checked.Whether pasted content may become training data.
Data sovereigntyA flag for jurisdictions rated high exposure.Legal and procurement escalation.
Abusive purposeDeepfake, nudify, NSFW or uncensored generation flags.Immediate block candidates, HR involvement.
SanctionedWhether the tool is on the approved list you provided.Policy compliance measurement.
Hits and usersVolume, and how many identities reached the tool.Whether this is one curious person or a department habit.

Risk level and training verdict disagree sometimes, and that is intentional. A low-risk tool can still train on your data, and a high-risk tool can have clean terms.

Honesty section

What the audit does not do

Knowing the edges makes the results defensible in front of an auditor or a skeptical CISO.

It does not see prompt content

The audit reads hostnames and identities, never what anyone typed. That is a feature: no new sensitive data store is created.

It does not cover unlogged paths

Phones on cellular data and home networks bypass your log source. The audit measures the network you actually log.

It is not a legal verdict

Training verdicts summarize vendor terms on a stated date. They feed your review; they do not replace counsel.

It does not block anything

The audit is read-only evidence. Enforcement stays in your existing stack, informed by the findings.

It does not need clean data

Mixed lines, odd delimiters and noise are expected. Unparseable lines are skipped and counted, not fatal.

It does not phone home

One upload produces one report. There is no resident collector and nothing to uninstall.

Source cheat sheet

Where the identity lives, per log source

The identity column has a different name in every console. This table saves you the search.

Log sourceTypical identity fieldPer-user table possible
Cisco UmbrellaIdentities column in the activity CSVYes, users and devices
ZscalerUser field in web logsYes, users
Palo Altosrc_user in URL logsYes, when User-ID is on
Fortinetuser= in web-filter syslogYes, when authentication is on
Cloudflare GatewayUser email in DNS or HTTP logsYes, users
DNSFilter / NextDNSProfile or device nameDevices rather than users
Pi-holeClient IP in the query logPer device, via IP
SonicWallusr= in syslogYes, when SSO agent runs
SquidThird field of access.logYes, when proxy auth is on
Plain hostname listNoneNo, inventory only

Every source above has a dedicated walkthrough, starting with Cisco Umbrella and Zscaler. Each one covers the export shape, the fields that matter and a worked scenario.

Sizing

Export window math

Rough line counts per window, so you can pick the right tier before exporting.

~50 usersA month of DNS logs usually stays under 5,000 relevant lines. The free preview often covers it.
~250 usersA month lands in the tens of thousands of lines. Full-report territory, far under the 25 MB cap.
~1,000 usersA month can reach hundreds of thousands of lines. Still within 2,000,000 lines, or shorten to two weeks.
5,000+ usersQuarter exports may pass 25 MB. Ask us, larger exports are handled on request.

These are planning numbers, not limits. Pre-filtering the export to allowed web traffic shrinks any of them dramatically.

Ownership

Who usually runs the audit

Three roles run most audits, each with a different first question. All three read the same report.

The IT manager

Owns the log console, so the whole loop is self-service. First question: which tools do we not know about? The IT manager page covers the operator angle.

The CISO

Wants the dated inventory and the quarter-over-quarter trend. First question: what changed since last time?

The compliance officer

Needs evidence that stands up in an audit file. First question: when were these vendor terms checked?

Before you export

A five-line pre-flight checklist

Five checks before you hit export save the second attempt.

1. Window matches the question

Reporting to a quarterly meeting? Export the quarter, not last week.

2. Identity column included

Tick user, device or source IP in the export options if your console offers it. It unlocks the per-user table.

3. Allowed traffic included

An export of blocked-only events measures your filter, not your exposure. Include allowed traffic.

4. Size within the tier

Free preview: 5,000 lines or 2 MB. Full report: 2,000,000 lines or 25 MB. Trim the window if you are over.

5. Approved list at hand

Optional, but pasting your sanctioned tools before the run turns the report into a policy scorecard.

FAQ

How it works: common questions

How long does a shadow AI audit take?

Uploading and matching takes minutes. Most of the 20-minute total is exporting the log from your console.

Do I need to install anything?

No. There is no agent, no browser extension and no network change. The audit reads an export your stack already produces.

What if my log format is not listed?

Any CSV with a header row works, and so does a plain list of hostnames. The parser detects the shape automatically.

What does the free preview include?

Totals by category, risk-flag counts and a fifth of the tools found, at least five, named. The rest appear as withheld rows. Details on the free audit page.

Can I run the audit again later?

Yes, and you should. Repeat the same window monthly or quarterly and the reports become a trend line.

What does the full report cost?

One-time purchases from $99, no subscription. Packs and plan inclusions are on the pricing page.

Make it a routine

One audit is a snapshot, a cadence is a control

The second report is worth more than the first. It turns a number into a direction.

Month 1: baseline

Run the first full report. File the PDF, load the CSV into your risk register, set the sanctioned list.

Month 2: policy check

Same window, same source. New tools since the baseline are your early-warning list.

Month 3: enforcement check

Tools you blocked should show attempts falling toward zero. If they do not, the control is leaking.

Quarterly: report up

Three reports make a trend line for the board. Plans on the pricing page include monthly audits for exactly this loop.

Keep the export window and source constant between runs. Change one variable at a time, or the trend line stops meaning anything.

Run the four steps on your own logs

The free preview needs only an email address and a log export. You will have your first shadow AI inventory today.

Start the free audit