Protect
Stop secrets before they reach a provider.
People paste passwords and keys into AI tools without meaning to. With scanning on, Selan finds the ones it recognises and swaps them out on the way, before the request leaves for the provider.
Book a demoWhat Selan is, in one go. Your company already pays for several AI accounts and models. Selan puts them in one setup, shows what each person spends, lets you set limits, and removes secrets it recognises before a request is sent.
This page is about the secrets.
Nothing is scanned until you say so.
Scanning ships switched off. An owner turns it on once for the whole company, and the switch keeps the date it was moved and the name of the person who moved it.
- One decision for everybody. Nobody has to install or configure anything.
- The same is true of every other switch here. New abilities arrive off.
- Turn it back off and scanning stops with the next request.
It replaces the secret, not the work.
A matched value is swapped for a placeholder and the request carries on to the provider. Nobody gets an error, nobody loses a conversation, and the provider never sees the real value.
- The rules are the ones the industry's own leak scanners use, not regular expressions we invented.
- They are kept inside Selan, so a check does not depend on fetching a list from somewhere else.
- Only what goes out is read. The model's answer coming back is never scanned.
You see that it happened, not the secret.
The feed records who sent it, when, and which kind of credential matched. The value itself is not kept, so reading the record does not leak the thing it is about.
- Treat a row as a job to do. A redaction is a reason to rotate that key, not an incident already closed.
- The exact list of what is stored, and the one case where a provider's reply is written down, is on Trust.
- The technical detail is in the secret scanning docs.
How it works
- An owner turns scanning on for the company. Until then nothing is scanned.
- Selan checks the request on its way out and replaces anything it recognises.
- The request goes on to the provider, and the swap is noted in the feed.
What to know
- The secret does leave the laptop. It is caught at Selan, on the way to the provider, which is the last point we control.
- It catches secrets that match a known shape. A password that looks like ordinary text is not something any scanner can recognise.
- The request is held for as long as the check takes, so scanning adds a little delay.
- Selan receives the whole request, including your prompts. The text of it is not stored: there is no field that holds a prompt. What does reach our log is about failures. When a provider rejects a request, up to 2 KB of its reply is written down, and a provider's message can quote the part of your request it objected to. When a stream breaks halfway, the provider's error is written down too, along with a shape record of what we had sent: how many items, what kind each was, and how many bytes. Never the words.
- Selan is built and hosted in the EU. The provider you send a request to is not, and that hop is theirs.
The other three
Know what your team spends on AI
Every request costed with a person's name on it, and a limit you can set before the number grows.
UnifyOne company setup for every AI model
Connect the accounts you already pay for, give each person one sign-in, and decide which models they can reach.
InsightsKnow where your team's AI time goes
Which repository the hours went to, who was in it, and how much of the context came back out of the cache.
Turn it on and watch one week.
Half an hour with the people who built it. We will show you what the feed catches, and what it honestly cannot.
Book a demo