The paste is the leak
Company data pasted into any AI tool leaves no trace in any log. Organisation policy sees a seat, not a paste. Blocking claude.ai at the proxy moves the paste to a phone.
Claude for Enterprise connects to Google Drive, Slack, Jira, Confluence and GitHub through MCP, adds custom connectors to internal tools, and holds company context in Projects. BrowserShield stops company data at the paste. The MCP Gateway decides every connector call that reaches your systems. Your people keep Claude.

In an enterprise plan, Claude is connected to the systems your people work in. Each connector is a door, and custom connectors mean the list is open-ended.
Claude's enterprise controls are the right controls to keep. They cannot see what a person pastes, and they cannot judge what a custom connector does to your systems.
Company data pasted into any AI tool leaves no trace in any log. Organisation policy sees a seat, not a paste. Blocking claude.ai at the proxy moves the paste to a phone.
An MCP server added by a team is an integration with no registry entry, no owner and no review. Each one widens what a single prompt can reach into your systems.
A connector call runs on the user's authorisation. The audit log shows a user and a connector, not who is accountable for what the call did.
You can see who used Claude and which connector. You cannot show an auditor which pastes were stopped, which calls were judged, against which policy, and what was decided.
The gateway decides. Shield enforces where the gateway cannot see. For Claude that means BrowserShield at the paste, and the MCP Gateway on every custom connector call that reaches your systems.
For Claude in the browser the leak is the paste, so BrowserShield does the work. AgenShield covers the Claude desktop app and Claude Code on managed devices with the same policy.
Out-of-policy actions like touching production secrets or mass-deleting files are stopped before they execute. Everything else flows. Ships through your MDM.
Keys and sensitive data are recognised as they are pasted into AI tools, and the paste is blocked. Employees keep their tools. Only the leak stops.
Illustrative verdicts for common Claude actions under a typical policy. Paste rows are BrowserShield. Connector rows are the MCP Gateway.
| Claude action | Verdict | Why |
|---|---|---|
| Ask a question with no company data in the prompt | allow | Nothing sensitive in the paste. The tool in use is recorded, the person keeps working. |
| Paste an API key or access token into a prompt | deny | Recognised at the paste and blocked before it leaves the tab. The person sees why. |
| Upload a customer export containing personal data | deny | Recognised at the upload and blocked. The person is pointed to a governed path. |
| Use a personal Claude account with company data | deny | Outside the governed organisation. Blocked at the paste, the person is pointed to the enterprise account. |
| Custom connector reads an internal wiki through the gateway | allow | Scoped to the person's entitlement. Logged, not interrupted. |
| Custom connector queries a customer database | mask | The query runs. Personal data is masked at the gateway before it enters the model context. |
| Custom connector writes to a production system | step-up | The connector's named owner confirms from their phone. Approved, policy remembers. |
| A team adds a custom MCP server not on the approved list | human-in-the-loop | A new door. Reviewed once by the connector's owner, then policy remembers. |
Verdicts are illustrative defaults. Every row is a policy you write once and Agen enforces per action, per identity.
Thirty minutes on the way your teams already use Claude. We show the verdict on each action, the named human behind the session, and the record it leaves. Bring your hardest question.
An engineer pastes a config block into claude.ai to ask a question. BrowserShield recognises cloud credentials in the paste and blocks it. The rest of the session continues.
Your admin settings, SSO and connectors stay exactly as they are.
The same three capabilities govern Claude and every other agent you run, internal and external.
Continuous discovery across your IdP, gateway, devices, cloud, and registries. Nothing has to self-register: agents are found, risk-scored, and resolved to a named human before they act.
Company data stopped at the paste, custom connectors decided at the gateway, a named person behind every one.