The AI CEO Brief

Tools / AI Security and Governance

iboss AI Security Platform Review: Free Shadow AI Visibility

iboss launched a free AI Security Platform on July 1, 2026 that gives any organization real-time visibility into every AI tool its employees are using. Signup is instant, deployment takes an afternoon, complete AI footprint appears within hours. Paid tiers add policy enforcement, data leak prevention, and AI agent governance. HIPAA, PCI, and FedRAMP compliant.

Prabjeet Singh Anand · Last reviewed July 5, 2026 · 6 min read

IMPORTANT: This page was last verified on July 5, 2026. Tool pricing, features, and compliance certifications change frequently. Before making any procurement decision, verify current details directly at aisecurityplatform.ai.

Quick facts

CategoryAI security and visibility platform (Zero Trust SASE)
HQOrlando, Florida, USA
LaunchedAI Security Platform launched July 1, 2026 (parent company established 2003)
CEOPaul Martini
Best forAny organization that wants to know which AI tools its employees are actually using. Regulated industries (healthcare, finance, government) that need audit-ready AI usage records
Not forOrganizations that already have full AI usage visibility through existing SASE or CASB deployments
PricingFree tier for core discovery. Paid tiers for policy enforcement, DLP, and AI agent governance
ComplianceHIPAA. PCI. FedRAMP. Trusted by government agencies
DeploymentInstant signup, complete AI footprint within hours
Product URLaisecurityplatform.ai

What is the iboss AI Security Platform?

The iboss AI Security Platform is a new service launched on July 1, 2026 that gives organizations complete visibility into the AI tools their employees are using. The free tier is genuinely free (not a trial), covering discovery and visibility. Paid tiers add policy enforcement.

The platform is built on the iboss Zero Trust SASE (Secure Access Service Edge) cloud platform, which consolidates VPN, Secure Web Gateway, SD-WAN, branch firewalls, Browser Isolation, and CASB (Cloud Access Security Broker) capabilities into a single cloud-based service.

iboss CEO Paul Martini framed the launch around a specific problem: "Every organization is asking the same first question about AI: what is actually running here? That answer should not require a procurement cycle or a six-figure contract. Free does not mean lightweight."

What does the AI Security Platform actually do?

The platform operates across two tiers.

Free tier (discovery and visibility):

  • Tracks prompts, sessions, users, and risk in real time across ChatGPT, Microsoft Copilot, Gemini, Claude, Perplexity, and dozens of other services
  • Covers both browser-based tools and desktop AI applications such as Cursor
  • Automatically inventories every AI tool the moment it appears on an endpoint
  • Classifies each tool by risk level
  • Attributes usage to individual users
  • Provides full prompt and response history searchable by user, vendor, message, or date

Paid tiers (enforcement):

  • Per-AI-category policies (allow, block, or redirect) with service-specific exceptions
  • In-the-moment coaching messages that appear to users when they violate policy
  • Controls over copy, paste, upload, and download actions per AI service
  • Tenant restrictions to keep employees within company-managed AI accounts
  • Default-deny connection policies for AI agents running on endpoints and servers
  • Domain allow-lists and block-lists for AI agent outbound connections
  • Data Loss Prevention (DLP) covering content sent to AI services
  • Mass deployment via MDM (Windows and macOS) without individual device enrolment

Who is iboss AI Security Platform for?

The free tier fits any organization that meets one of the following:

  • Has never mapped which AI tools its employees actually use
  • Suspects but cannot prove that sensitive data is being shared with unvetted AI services
  • Faces audit requirements that will soon ask "which AI is running in your environment"

The paid tiers fit organizations where all of the following are true:

  • Free tier discovery has revealed material shadow AI usage
  • Policy enforcement (not just visibility) is required
  • The organization operates in a regulated industry (finance, healthcare, government) or handles sensitive data
  • The internal capability to build equivalent monitoring in-house does not exist

Because the free tier costs nothing, there is no reason for most organizations to skip the discovery step. The paid decision comes later, informed by what the free tier finds.

How does iboss AI Security Platform fit APAC operations?

Three considerations for APAC-specific deployment.

Regulatory alignment.

iboss meets HIPAA, PCI, and FedRAMP standards, which are US-centric certifications. For APAC regulated industries, this translates well into Singapore's Cybersecurity Act requirements, Australia's Essential Eight framework, and general enterprise SOC2 expectations. Buyers should confirm specific data residency options with iboss for jurisdiction-specific compliance, particularly for Australia's evolving AI transparency requirements and Vietnam's AI Law.

Multi-country workforce coverage.

If your organization operates across Singapore, India, Malaysia, and Indonesia, the platform maps AI usage across your entire distributed workforce in a single pane of glass. This matters for regional HQs trying to enforce consistent AI governance without country-by-country tooling.

Shadow AI baseline.

Every APAC enterprise our advisory practice has assessed in the last 6 months has significant unmanaged AI usage. Employees running ChatGPT on personal accounts. Marketing teams using AI tools no one in security has vetted. Developers running Cursor on production code. The free tier of iboss is the fastest way to get a factual baseline before making any AI governance decisions.

The honest limitations

No paid placement disclosure: this review is not sponsored.

Does not fix data residency or sovereignty by itself.

The platform gives visibility and control over AI usage. It does not automatically comply with jurisdiction-specific data localization requirements. If employees are sending sensitive information to US-hosted or China-hosted models, iboss will show you that, but you still need to decide what is allowed per jurisdiction.

Visibility depends on integration with your network and endpoint stack.

SMEs with highly fragmented IT, heavy mobile-only workforces, or extensive BYOD may need additional configuration to achieve full coverage.

Flags usage and risk. Does not build your policy.

The platform tells you what is happening. You still have to build your organization's own allowed-tools list, escalation workflow, and disciplinary framework. iboss provides the enforcement engine once you have the policy.

US-first product roadmap.

Feature velocity and compliance certifications lean toward US regulations (HIPAA, FedRAMP). APAC-specific overlays (Vietnam AI Law compliance modules, Australia AI transparency reporting) are not yet built-in.

Pricing reality

Free tier.

Genuinely free (not a trial). Includes core discovery, real-time AI tool inventory, user attribution, risk classification, prompt and response history. Sign up at aisecurityplatform.ai. No sales contact required.

Paid tiers.

Add policy enforcement, DLP, AI agent governance, and mass deployment tooling. Pricing depends on organization size, number of users, and specific features required. Contact iboss for a tailored proposal.

The free tier is genuinely useful on its own. Many organizations will get significant value from discovery alone without ever paying. This is one of the few enterprise security tools where "free" is not a trial funnel.

How the AI Security Platform compares to alternatives

Three main competitor categories APAC CEOs should also evaluate:

Existing SASE and CASB platforms (Zscaler, Netskope, Palo Alto Networks Prisma).

If you already have one of these deployed, check whether AI usage visibility is included or requires an additional module. Many are adding AI-specific capabilities in 2026.

Standalone AI governance tools (Nightfall AI, Prompt Security, Wald.ai).

Some focus specifically on the AI usage problem without the broader SASE stack. May be simpler if you do not need the network security consolidation iboss provides.

Endpoint DLP with AI extensions (Digital Guardian, Forcepoint DLP).

Cover AI as one data flow among many. Better if data loss prevention is your primary problem and AI is one channel; less useful if AI-specific visibility is what you need.

iboss's positioning is distinct: the free tier is a genuine on-ramp with no time limit, backed by a full SASE platform available for enterprises that want to consolidate.

The decision question for your CIO

Do we actually know which AI tools our employees are using today, or are we managing AI usage by assumption?

If the answer is "by assumption," the free tier of iboss is the fastest way to get facts before deciding on any broader AI governance investment.

Frequently asked questions

Is the free tier really free forever?

Yes. iboss's public positioning is that discovery and visibility are free with no time limit. Paid tiers add enforcement capabilities. iboss made discovery free to establish an industry baseline for AI security.

Does iboss capture actual prompt content?

The platform captures prompts, responses, and session data with full search capability. Whether this data is stored, how long it is retained, and where it is stored depends on your configuration and jurisdiction. Review the platform's data handling documentation before deployment for sensitive environments.

Can I deploy iboss across a mixed Windows and macOS workforce?

Yes. Mass deployment is supported via existing MDM solutions for both Windows and macOS. Pre-configured installers can be distributed across large fleets without individual device enrolment.

Does iboss cover AI agents running on servers, not just user devices?

Yes. The platform includes default-deny connection policies for AI agents running on endpoints and servers, with domain allow-lists and block-lists. This addresses the growing risk of autonomous AI agents making outbound connections security teams cannot detect.

What is the difference between the AI Security Platform and the broader iboss Zero Trust SASE platform?

The AI Security Platform is delivered on the same iboss Zero Trust SASE cloud infrastructure but focuses specifically on AI usage visibility and control. Organizations can adopt the AI Security Platform alone (free tier) or combine it with iboss's broader SASE capabilities.

Which AI services does iboss track?

ChatGPT, Microsoft Copilot, Gemini, Claude, Perplexity, and dozens of other services. Both browser-based tools and desktop AI applications including Cursor. New AI tools are automatically detected and classified as they appear on endpoints.

Related resources

iboss AI Security Platform was featured in Issue 17 of The AI CEO Brief (July 5, 2026)

Related: Kolsetu Elba Review - enterprise voice AI for regulated operations

Related: Meta Business Agent Review - AI for WhatsApp Business

Related: Vietnam AI Law Compliance Guide

Concerned about shadow AI in your organization?

I advise APAC CEOs on AI governance and tool selection. If you are trying to build an AI usage policy without knowing what your team is actually using, we should talk.

Not ready to talk yet? Subscribe to The AI CEO Brief for weekly APAC AI signals.

Subscribe to the newsletter

Sources: iboss press release (July 1, 2026), PRNewswire distribution, Help Net Security coverage, StartupHub coverage, CIO Influence coverage, iboss company website.

Disclaimer: This review is based on publicly available information as of July 5, 2026. Features, pricing, and compliance certifications may change. Verify current details with iboss directly for any procurement decision.

The AI CEO Brief is read by 1,000+ CEOs and senior leaders across Asia Pacific. Subscribe free at the-ai-ceo-brief.beehiiv.com →