Everything in Pro, plus the enterprise layer: connect Salesforce, Slack, Notion, SQL, Workday and more to protect your company's secrets and IP. Privacy Agents that travel with every employee, agent governance for Claude Code, Microsoft Copilot & Private MCP, the world's first on-device DSPM, and org-wide AI policy. Built for orgs where AI moves at agentic speed.
On-device agents that reason about privacy, intent and risk in real time: out of the box, custom-built, or from the marketplace.
Max connects to the platforms where your most critical data lives. PrivacyPal learns what's sensitive at the source (customer records, employee data, IP, secrets), so the moment it surfaces in any AI, in a prompt, a paste or an agent's tool call, it's intercepted before it leaves the device.
Accounts, contacts, pipeline and deal terms stay out of every prompt, even when your team puts AI to work on the CRM.
Customer dataChannels are where secrets leak. Keys, credentials and internal chatter are recognized and protected everywhere AI reads or writes.
Secrets & commsCompensation, reviews and personal employee records: governed wherever HR and managers put AI to work.
Employee dataERP and financials (vendor terms, margins, forecasts): shielded from exfiltration across every AI surface your org touches.
FinancialsRoadmaps, specs and internal wikis: your IP and know-how stay yours while your team drafts with AI on top of them.
IP & know-howContracts, board decks and shared files: classified at the source and protected the moment they meet a model.
Files & contractsMax keeps everything you love about Pro (Privacy Twins, real-time on-device interception, SSO) and adds connections to Salesforce, Slack, Notion, SQL, Workday and more, plus the four governance pillars that turn the CISO from blocker into enabler.
Staff devices are the biggest data-breach surface in the enterprise. Max turns every laptop into its own DSPM sensor: discover, classify and continuously monitor sensitive IP, PII, PHI and PCI where it actually lives. No one else does this. It's the wedge that lets you adopt AI safely as on-device language models become the new edge.
Real on-device agent governance, not just a chat wrapper. Max sits inside Claude Code, Microsoft Copilot, ChatGPT and Gemini at the device level. Govern what agents can read, write and exfiltrate. Block, redact or steer in real time across every model and every endpoint.
Run a Private MCP that lets your team's agents reach internal tools, data and APIs without those connections leaking back to a public host. Your context. Your tools. Your control plane. Built for the agentic era.
Block models, gate access behind training paths or certifications, intercept and steer prompts, redact at the wire. Discover shadow AI before it hits the breach report. Define what your employees can do with AI, and prove it to your auditors with one click.
On-device. Autonomous. Purpose-built to reason about privacy, intent and risk in real time, across every AI your team touches. The agents ship out of the box, you build your own, or you pull from the marketplace. This is what governance looks like when it's built for the AI OS instead of bolted onto a legacy stack.
Understand what an agent is actually trying to do before it does it. Authorize, alert or quietly redact based on intent, not just keywords.
Catch jailbreaks, tool-call hijacks and exfiltration patterns at the endpoint. The agent reasons about adversarial intent so your humans don't have to.
Drop in a Legal Agent that knows privilege, or a Financial Agent that knows MNPI. Agents bring vertical intelligence to every interaction, without retraining a model.
Customize and ship your own agents, or enable privacy, security and AI agents from the marketplace. Enrich any AI conversation across Claude, ChatGPT, Gemini, Copilot and more.
Privacy Agents run on-device, so the same governance applies whether your team is in Claude Code, ChatGPT, Gemini, Microsoft Copilot, or a custom MCP stack you built yesterday. Visibility and control of AI, regardless of which AI.
Agent governance recognizes the repo, the on-device DSPM knows the secrets and PII inside it, and Privacy Twins substitute customer identifiers before any prompt or tool call leaves the laptop. Claude Code keeps moving. Your IP stays put.
Intent Detection recognizes the workflow, the Legal Agent flags an NDA clause, and Privacy Twins scrub vendor names, all before the request leaves the device. The CISO sees the event in the audit log. Nobody loses time.
On-device DSPM has already classified the data as MNPI. Org-wide controls require Copilot users to be in the "client-facing" training cohort. Not enrolled? Blocked at the endpoint. Enrolled? Privacy Twins keep the names out. Either way: no exfiltration.
Engineers, analysts and a custom Financial Agent all share the same internal context, without that context ever leaving the org. Same fluency. Zero exfiltration. Full audit.
Max is a strict superset of Pro. Use Pro for real-time PII protection on every seat. Use Max when you need connections to your business stack, on-device DSPM, agent governance, and one policy plane across the whole org. For sovereign self-host, see Cloud.
| Capability | Pro | Max |
|---|---|---|
| Privacy Twins on-deviceReal-time interception across every AI app, web & desktop | Included | Included |
| PII, HIPAA, PCI & GDPR coverage | Included | Included |
| SSO support | Included | Included |
| ConnectionsSalesforce, Slack, Notion, SQL, Workday & more: protect your secrets & IP | – | Max only |
| On-device DSPMFirst of its kind. Every staff device becomes a DSPM sensor | – | Max only |
| Agent governance · Claude Code & CopilotNative control across real on-device agents, not just chat | – | Max only |
| Private MCP | – | Max only |
| Org-wide AI policy & privacy policiesBlock models, require training, intercept, shadow-AI discovery | – | Max only |
| Privacy Agents (intent, injection, vertical, custom) | – | Max only |
| Agent marketplace | – | Max only |
| PricingPer seat · save 17% billed annually | $18/mo · $180/yr | $60/mo · $600/yr |