Find unapproved AI.
Control what it can expose.
Virtus Sentinel is Imperum’s AI asset discovery and exposure management module. It brings reported AI use into one view, surfaces risky activity, and gives your team controls for sensitive data and agent tool calls.
Find AI use that needs a decision.
A browser sighting identifies an unapproved AI provider. Review whether this use belongs on your approved list.
The endpoint reports the tool and its discovery evidence. An analyst can review its approval status.
A denied tool call makes this gateway sighting suspicious. Inspect the detection before deciding what to approve.
A registered platform agent is a known asset. Its classification is separate from the verdict on any individual call.
Bring reported AI use into one inventory. Inspect the evidence, then review approval status.
Explore AI discoverySeparate protection from exposure.
With redaction configured, matched personal data is masked before the browser sends the prompt.
In warn mode a user can send anyway. That event remains visible as a leak, with actor and destination in the audit trail.
When Virtus Veil is enabled for the provider, matched values are replaced before the model call.
Inspect the actor, destination and outcome in the audit trail. A redacted prompt is different from a leak.
Explore data controlsTurn an injection finding into evidence.
An instruction-override attempt in the browser prompt editor raises a warning under monitor policy. The finding is recorded; it is not a blocked send.
A routed tool response matches injection checks. The record carries the reason and the decision for review.
Configured inspection flags suspicious content entering an agent workflow. Use the evidence to decide whether to tighten policy.
Monitor is the starting mode. Blocking requires administrator enablement and the relevant enforcement configuration.
Explore injection protectionVisibility depends on enrolled endpoints, browser extensions, platform activity and traffic routed through the gateway. The radar displays their findings; it does not scan the network.
Know the asset. Keep the evidence.
The endpoint probe, browser extension, gateway and Imperum agents report into one inventory. See the AI tool or MCP server, where it was observed and why it received its classification.
MCP server discovered
Denied tool call
Both sources retained
Illustrative match. Only supported, unambiguous pairs merge; browser sightings remain separate.
Classification explains the risk.
Enterprise, Shadow, Suspicious, Malicious and Unknown describe what the evidence says. Approval is a separate decision, so approving a tool does not erase a suspicious finding.
Discovery informs exposure work.
With Defensum licensed, unapproved endpoint AI tools and MCP servers can feed AI exposure findings. Your team can follow up in the context of the affected asset.
Explore Defensum →Set the boundary before
data or a tool call leaves.
Virtus Veil masks matched personal data when enabled. The inline gateway applies policy to traffic routed through it. These are distinct controls, configured for the sources your team uses.
Investigate activity for analyst@example.com.
Investigate activity for [REDACTED_EMAIL_1].
Keep sensitive values out of prompts.
Matched values are replaced with tokens and can be restored in the reply. Browser policy can warn, transparently redact or block; in warn mode, sending anyway is recorded as a leak.
Decide what a tool may do.
The gateway can allow, redact, hide, monitor, require approval, deny or quarantine. A configured approval decision waits for an authorized reviewer. Eligible detections can open or update a Casebook case.
Explore Casebook →Endpoint payload capture defaults to none. Redacted extracts are configurable; raw capture requires administrator authorization.
Inspect the attempt.
Test the protection.
Prompt-injection checks look for instructions that try to redirect an AI workflow. Review detections and their evidence, adjust policy, and use Red Team to test selected targets.
Select a target
Choose the classifier or a supported model, agent, MCP tool or HTTP endpoint.
Run selected probes
Run selected attack patterns against a target you control. Agent or tool tests with live side effects require explicit opt-in.
Review the evidence
Inspect findings and measured outcomes. An unsupported or unmeasured result is not a clean bill of health.
Prompt-injection policy starts in monitor mode. An administrator must permit blocking before it can be selected. Coverage and results depend on enabled surfaces, routing and target configuration.
Start with a defined part of your estate.
Activate the standalone Virtus Sentinel license, connect the relevant discovery and protection surfaces, and review what they report. Set approved providers, data-handling policy and gateway controls for that scope before expanding coverage.
Questions about Virtus Sentinel.
1Does it see AI use without deployment?
Coverage comes from the sources you connect: endpoint probes, browser extensions, platform activity and routed gateway traffic. Unenrolled devices and traffic that bypasses these surfaces are outside that visibility.
2Is protection switched on by default?
Virtus Veil masking must be enabled and configured. Prompt-injection policy starts in monitor mode, with blocking requiring administrator enablement. Browser and gateway policy determine the action for their respective traffic.
3Does Red Team prove an AI system is safe?
It tests selected probes against supported targets and reports the evidence obtained in that run. Results depend on the target, configuration and probes; missing or unscored results are not proof of safety.
4Is Virtus Sentinel included in a platform tier?
Virtus Sentinel is licensed separately. Access also depends on user permissions. Related Casebook and Defensum workflows require their corresponding platform capabilities.
Have any other questions?
Talk to our team
See where AI is used.
Decide what it may expose.
Bring an AI workflow or an area of your estate. We’ll walk through discovery, data protection and the controls it needs.