Meet us at AI Everything Abu Dhabi6–7 October 2026 · ADNEC Centre · Stand H4-P100See the LLMGuard demoMeet us in Abu Dhabi6–7 Oct · H4-P100

AI usage control for Windows devices

Control what
your organisation
sends to AI

LLMGuard by HACS checks every request your devices send to AI services and blocks the ones containing intellectual property or confidential information before they reach the provider.

The LLMGuard Policy Engine dashboard. Requests from 35 enrolled devices converge on the engine and leave on three lanes: 13,166 allowed, 7 held for approval and 42 blocked before reaching the provider.
Runs on
Your own servers
Devices
Windows at launch
Deployed through
Your existing Intune
Inspection
Before the request leaves

01 / WHY THIS EXISTS

Nobody did anything wrong.

Someone on your team has a contract open and a deadline. They paste a clause into ChatGPT and ask it to check the indemnity wording. It takes four seconds, the answer is good, and the work gets done.

The client name, the contract value and the account numbers are now held by an AI company.

No policy was broken, no attacker was involved, and nothing in your security stack recorded it. There is no log to find, because nothing was watching this route.

Can you check the indemnity wording in this clause?

12.3 Indemnity. client name shall indemnify the Supplier against all losses arising from the Services, up to a total of contract value. Payments under this clause are made to account account number.

Client nameContract valueAccount number

Every other route out is covered.

You have spent years closing these. The controls work, they are audited, and they are why data does not walk out through email or a file share.

  • EmailSecure gateway
  • File serversData loss prevention
  • SharePointSensitivity labels
  • Removable mediaDevice control
  • An AI chat boxNo controlAI provider

You decide what confidential means.

LLMGuard reads each request for meaning against rules like this one. It is not matching a keyword list, so a client name it has never seen before is still a client name.

Written in plain English
Client names, contract values and account numbers are confidential.

LLMGuard works alongside your endpoint security and DLP tools. It covers the one route they were not built for.

02 / WHERE IT RUNS

The engine is yours,
and it sits on your hardware.

Your rule has to be read against the actual content of a request, so that content goes to the Policy Engine. The Policy Engine is installed in your environment, on your own hardware, and it is the only place a decision is made.

Your devices send the content of each AI request to the Policy Engine, which is installed on your hardware inside your organisation, and the engine sends back a decision. Only allowed requests cross your organisation’s boundary to the AI provider. Separately, the LLMGuard agent connects out to HACS for authentication, a configuration file and the signed AI service catalogue. No customer content travels that way, and HACS never connects into your network.

If a device cannot reach the engine, you decide what happens.

Devices reach the Policy Engine on your network or over your VPN. When one cannot, AI traffic either pauses or continues, and you choose which in advance.

What gets opened
Only traffic to AI services. Banking, health and personal traffic is left sealed.
On the record
Every decision is logged with the device, the service and a fingerprint of what was sent.
The Policy Engine Settings screen, When the engine cannot be reached. Two choices: AI traffic pauses, where requests to AI services are held on the device until the engine answers, and AI traffic continues, where requests go through without a decision.
Settings in the Policy Engine

03 / EVERY APP. EVERY AI.

Use every AI tool.
Your rules decide what it receives.

From browser assistants to desktop apps, command-line agents and API calls, LLMGuard reads the content itself, not just the destination. Your own policy decides what reaches the provider.

  • Browsers
  • IDE coding assistants
  • Desktop AI apps
  • Command-line agents
  • Scripts
  • SDK and API calls

A browser plug-in would see only the first of these.

LLMGuard Endpoint AgentBeneath every application, at the device’s network layer
LLMGuard Policy EngineOn your hardwareDecides every request before it reaches the provider

Can you check the indemnity wording in this clause?

12.3 Indemnity. client name shall indemnify the Supplier against all losses arising from the Services, up to a total of contract value. Payments under this clause are made to account account number.

LLMGuardBlocked

This request was not sent. It contains information your organisation does not allow to leave for an AI service. IT has been notified.

chat.openai.com
What the person at the keyboard sees.
More than 50 AI services
Recognised by the agent. New ones arrive by signed update, with nothing reinstalled on devices.
The service, not the cloud
It identifies the AI service itself, so business applications on the same cloud are not caught.
One policy
Set centrally, it applies to every device and every AI provider.
No application changes
No SDK, no proxy settings, no developer work.

04 / DEPLOYMENT

We install it on site,
with your IT team.

Our deployment team installs the Policy Engine in your environment, trains it there, and handles setup and integration until LLMGuard is live. Your IT team pushes the agent through the device management it already runs. How long setup takes depends on your environment, so we agree the plan with you before anything is installed.

Who does what, in four stages. LLMGuard goes live between the second and the third.
01

Agree

Before anything is installed

Your team

  • Windows devices, managed through Intune or similar
  • A server for the Policy Engine, to our stated requirements
  • Devices that reach it on your network or VPN
  • An IT contact for installation and coordination

HACS

  • Scope, costs and terms, agreed in writing before we start
  • The rollout plan and your starting policy, set with your IT contact
02

Install

On site, in your environment

Your team

  • Push the agent to a device group through Intune
  • Devices enrol themselves

HACS

  • Installs the Policy Engine on your server and handles setup and integration
  • Trains it there, on your own material
  • Takes its training setup and temporary equipment away. The system stays with you.

LLMGuard is live

03

Evaluate

For a period agreed with you

Your team

  • Your administrators run the Policy Engine: held requests, policy, exceptions and business context

HACS

  • Works through the evaluation with you
  • Collects your feedback on its decisions
04

Run

From then on

Your team

  • Send feedback on decisions. It improves the models in the next training iteration.

HACS

  • Runs each training iteration on site
  • Review visits planned every six months, with support between them
  • Never connects into your network

Check the rollout from the Policy Engine.

The Intune screen compares every Windows device Intune manages with the devices the engine has actually heard from. A device the push missed is listed, with the reason.

The Intune screen in the Policy Engine: every Windows device Intune manages, and whether this engine has heard from it. 41 managed by Intune: 34 protected, 2 waiting, 3 not assigned, 2 not eligible.
Intune in the Policy Engine

05 / THE COMPANY

HACS is the company
behind LLMGuard.

HACS was founded to help organisations adopt AI without exposing confidential information. We’re building protection that runs within the customer’s own environment, with the needs of small and medium businesses in mind.

The product came first.

LLMGuard began as an answer to one problem: letting people use AI at work without confidential information reaching AI companies. We felt that problem was poorly served, especially for smaller organisations, so HACS was founded to take LLMGuard to market.

The team that builds LLMGuard is the team that installs it in your environment, trains it there and supports it afterwards.

The founders

  • Harshini VarmaDirector and CEO
  • RamrajuFounder
Registered as
HACSCO AI Private Limited
Based in
Hyderabad, India
Early-access pilots
India, the UAE and Qatar
EARLY ACCESSINDIA / UAE / QATAR

Bring protection
inside.

Apply for an on-premises pilot supported by the HACS team.

Request early access