BitDrip inspects supported AI traffic your team sends to ChatGPT, Claude, Gemini and other LLMs — where configured policies can detect and block PII, credentials, PHI, and proprietary data in supported paths. The current product is for organizations and their authorized workforce; it is not currently offered for personal or consumer use.
BitDrip's proxy and policy components run in your network. A lightweight proxy daemon inspects configured supported HTTPS traffic, the policy engine evaluates it against your rules, and the configured action is applied before forwarding. The separate commercial portal manages licensing and release delivery.
Nine capabilities that make BitDrip the right choice for organisations that take data privacy seriously.
Supported traffic to ChatGPT, Claude, Gemini and other configured AI services is checked before it leaves the device. Sensitive data — names, medical records, card numbers, passwords, and proprietary content — can be detected and blocked in real time. Tested browsers and applications that use the system proxy are protected with no browser add-on required.
On supported configured response paths, BitDrip can evaluate documented PII patterns, jailbreak-success signals, and data-exfiltration artifacts. Coverage and detector outcomes require deployment-specific validation; no feature-parity claim is made about other products.
The proxy, policy engine, dashboard, and their content-processing path run in your infrastructure. Supported configured requests go from the device through those customer-controlled components to the AI provider. The separate commercial portal is not in the documented prompt-content path.
Built-in profiles and technical-control mappings can support an organization's GDPR, HIPAA, PCI DSS, SOC 2, ISO 27001, and CCPA work. Validated audit records can use hash-chain and signature evidence where the deployed release provenance confirms those features are enabled; the documented verifier can detect changes when verification runs.
Export audit events to Splunk (HEC/CEF), Elastic/OpenSearch, and Azure Sentinel in real time. Configurable per organisation — violations land in your existing security toolchain automatically.
Evaluate early MCP tool-call traffic through the policy layer for selected agent workflows. Full agentic AI discovery and monitoring remains on the product roadmap while the preview matures.
Track AI usage volume by organisation and time period. Per-GB scanning metrics and time-series charts give security teams visibility into AI exposure across the entire organisation.
Enroll workstations with a one-time token. The admin dashboard shows enrolled devices reported through the supported heartbeat path — including hostname, OS, proxy version, and online/offline status. Revoke a device in one click if it's lost or decommissioned.
A native app for macOS, Windows and Linux lives in your system tray and manages the BitDrip proxy daemon without any terminal required. Supports system proxy mode for centrally managed devices and PAC-based routing for BYOD and unmanaged devices. Shows live connection counts and blocked-request totals in the tooltip, with a built-in preferences window for proxy mode, policy engine URL, and CA certificate status.
Coverage depends on how each application connects. Validate every managed application before rollout.
Covered routes and controls are implemented and tested to documented scope. Defense-in-depth is continuously assessed as the product evolves.
Validated audit configurations can use hashes and bounded metadata instead of full matched content. Confirm the deployed schema, logs, diagnostics, and retention before relying on that behavior.
Authenticated release evidence includes SHA-256 checksums for promoted installer bundles. License JWT verification uses ed25519; verify the deployed release and issuer evidence before use.
Policy decisions for supported configured traffic run in your environment. The commercial portal has a separate, bounded account, licensing, deployment, billing, and release-delivery data path described in the privacy notice.
Documented, tested capabilities can support selected technical-control objectives on validated paths; this is not certification or complete control coverage. Read the documentation →
BitDrip provides configurable detectors, policy actions, and evidence that can support selected framework objectives on validated paths. It does not determine legal compliance or guarantee detection or blocking.
Designed to support compliance — not a substitute for legal review.
Register once, deploy anywhere. No SaaS. Your AI data stays in your infrastructure, always.
./install.sh — it starts all services automatically. Then run bitdrip cert generate && bitdrip cert install to install the CA certificate, and bitdrip proxy start to begin intercepting traffic (or use the system tray app).Full installation guide, configuration reference, and troubleshooting are in the documentation.
Read the Docs →The dashboard presents policy events, technical-control mappings, and enrolled-workstation state from the customer-controlled deployment. Validate deployed audit fields, logs, diagnostics, and retention; the dashboard does not establish legal compliance.
Start free. No credit card required for the Community tier.
For licensing, one user means one enrolled workstation or device seat.