Guide · Privacy
How can I govern employee AI use without reading their chats?
Last reviewed:
Short answer
Govern from usage metadata and on-device checks instead of chat content. To govern AI you need to know which tools are used, whether rules fired and who accepted the policy — not what people wrote. VAHTOR is built that way: prompt text is never collected, and admins see the tool, a detection type and a risk level, not the message.
How to do it
- 1
Decide what you actually need to know
Tool names, time of use, policy acceptance and rule alerts answer most governance questions. Chat content rarely does.
- 2
Run checks on the device
Evaluate files and secrets in the browser before they are sent, so the content does not have to reach a server.
- 3
Default to aggregated reporting
Show trends by team or company first, and turn on individual names only where you have a reason to.
- 4
Set retention
Decide how long metadata is kept, and say so in your AI policy.
- 5
Tell employees exactly what is collected
Being open about what is and isn’t collected builds trust and makes the policy easier to accept.
How VAHTOR does it
VAHTOR never stores what people type into ChatGPT, Copilot, Claude or other AI tools. The workspace stores tool names, timestamps, detection categories, risk levels, policy versions and acceptance records. Security alerts carry the detection type, risk level, application name and a masked sample only, as described in the Privacy Policy.
- Prompt text is never collected
- Checks happen in the browser
- Aggregated reporting by default
- Identifiers only if you enable them
- Retention set by the owner
- No root certificate, no SSL interception
Frequently asked questions
Can admins read ChatGPT or Copilot conversations in VAHTOR?
No. Prompt bodies are not recorded. Admins can see which tools were used and whether a rule fired — not the message.
What is actually stored?
Tool names, timestamps, detection categories, risk levels, policy versions, and acceptance records. Retention is set by the workspace owner.
Can we keep reports anonymous?
Yes. Privacy controls let owners keep aggregated reporting and turn individual identifiers off. Department rollups are optional.
Where does a file or secret check run?
On the device. If a Files rule is on, the attach is cancelled in the browser, a banner is shown, and an alert is logged without the file contents.