Skip to main content

How does FortressAI protect data in a web browser?

Beta capability. Browser-based AI usage detection and enforcement is currently in beta. It is functional and in active use, but evaluate it in your environment before depending on it as a control.

Short answer: FortressAI monitors browser activity from the kernel and evaluates it against policy. If the browser, a website, or an extension tries to access data outside of policy, permission is revoked at the kernel layer — and if the browser shows signs of exploitation, all data rights are revoked and the process is suspended.

The sequence

  1. A user opens a web browser — Edge, Chrome, or Firefox.
  2. Kernel-level monitoring evaluates the browser and any page or extension activity against the assigned FortressAI policy.
  3. If the browser, site, or extension attempts to access data outside policy, permission is revoked at the kernel layer.
  4. If the browser shows signs of exploitation, all data rights are revoked and the process is suspended.

Why the browser is the critical control point

The browser is where most generative AI use actually happens, and it's also a heavily targeted attack surface. Cyber Crucible has seen this directly: from Q4 2023 onward, automated responses against Chrome, Edge, and Chromium activity climbed from zero into the thousands, with related CVEs subsequently published by Google and Microsoft. At one company the pattern escalated from a handful of blocked attacks to nearly 4,000 across almost every workstation.