Platform · ICAP / DLP

Do not replace your DLP strategy. Put it inside the AI path.

AI Warden can call ICAP-supported DLP platforms, including common enterprise DLP and SSE inspection services where supported, before AI requests leave and before responses return. Your DLP outcomes can allow, modify, block or trigger session-level controls according to policy.

Request and response enforcement

Inspect before egress. Inspect before delivery.

AI risk is bidirectional. Users can send sensitive data to a model or tool, and models or tools can return content that should not be delivered. AI Warden gives ICAP inspection points on both sides.

LLMPromptsInspect prompt text, attachments and request metadata before provider egress.
LLMResponsesInspect model outputs before the client, agent or application receives them.
MCPTool callsInspect JSON-RPC arguments and tool requests before upstream tool execution.
MCPTool resultsInspect tool responses, files and generated content before returning to the agent.

Inspection lifecycle

ICAP decisions become AI Warden enforcement events.

AI Warden can sit between employees, apps, hosted agents, LLM providers and MCP servers. The gateway resolves identity and policy, sends the relevant body and context to ICAP where configured, applies the DLP decision, then continues with AI Warden scanners, routing and audit.

  • Allow: continue through AI Warden policy, budget, routing and response inspection.
  • Modify: forward the redacted or rewritten body when the ICAP service supplies one.
  • Block: short-circuit the AI request with a clean policy response and audit outcome.
  • Error or timeout: fail closed where configured so unavailable inspection does not become silent bypass.

AI-aware actions

DLP decisions can control the AI session, not just a single packet.

A hosted chatbot receiving a file upload can send that content to ICAP. If the DLP response is modify or block, AI Warden can decide what happens next in the AI experience.

allow

Continue normally

The DLP service allows the content. AI Warden still applies native AI policies, budgets, model routing, MCP controls and request logging.

modify

Warn or restrict

Deliver the modified body, warn the user, remove sensitive content, or disable selected tools such as internet search, external connectors or file export for that session.

block

Stop or contain

End the chat session, block the tool call, quarantine an agent, require approval, notify SOC, or auto-disable a risky user or agent after repeated events.

Fail-safe default

If ICAP does not respond, AI Warden can fail closed.

For regulated enterprises, an unavailable inspection path should not silently become no inspection. AI Warden can treat ICAP timeouts, connection failures, malformed responses and configured body-size violations as deny outcomes, with audit detail for the failed inspection attempt.

Behaviour-based controls

Repeated ICAP outcomes become a user, agent and workflow risk signal.

AI Warden knows the authenticated user, delegated user, hosted agent, MCP server, provider, model and session behind each event. That makes it possible to act on patterns, not just individual blocks.

  • Alert SOC when a user or agent receives a high number of ICAP block or modify decisions.
  • Trigger review or disablement for an agent that repeatedly attempts to disclose customer-identifiable data.
  • Move a session into restricted mode after the first serious DLP event.
  • Disable only the risky tools, such as internet search, external MCP connectors or file export.
customer-insights-agent12 blocks
external-search tooldisabled
finance-expense-agent0 blocks

Example action: disable internet search for the active session, notify SOC and route the agent owner through review.

Audit evidence

Governed AI requests can show whether ICAP inspected them and what happened.

Request logs can retain the gateway outcome, AI Warden policy outcome, ICAP request decision, ICAP response decision, service status, latency, flags, principal, delegated user, agent and target system.

request-log outcomeDenied by ICAP
traffic_type: mcp
principal: aiwadmin
agent: aiw-demo-customer-insights-assistant
tool: customer_profile_export
icap.request: allow · 204 · 24ms
icap.response: blocked · 200 · 31ms
action: disable external export tools for session
outcome: denied before client delivery
evidence: queryable · exportable

Use your DLP investment

Run AI Warden policies and enterprise DLP together.

AI Warden does not ask regulated customers to trust a separate AI-only policy layer instead of their DLP programme. It lets both operate in the request path, with configurable fail-closed enforcement and AI-aware session actions.