[inoqube]
StructLine

AI GOVERNANCE

See what your team puts into AI, and prove you govern it.

Staff paste customer data, contracts and code into AI tools every day, often on personal accounts nobody can see. StructLine shows what leaves and whose account it is on, then turns it into an audit-ready record mapped to the EU AI Act and GDPR.

Live in an afternoon. No security team required.

7,800+
findings recorded
37%
on personal accounts

Across early deployments

The governance dashboard. Sample data, illustrative.

  • EU AI Act and GDPR mapped
  • Zero-retention by default
  • No third-party AI
  • Warn, coach, block or mask

THE QUESTIONS YOU WILL BE ASKED

The risk sits in the tools you cannot see.

Most staff who use AI on a work device reach it through a personal account. A client list goes into a personal ChatGPT and surfaces weeks later by accident. Then an enterprise prospect sends a security questionnaire, the cyber insurer asks at renewal, or an auditor wants the AI register, and the honest answer is a guess.

  1. 01Which AI tools does our team actually use?
  2. 02What kind of data flows into them?
  3. 03Can we prove we handle that responsibly?

See it, prove it, stop it. The first two on every paid plan, the third with Enforce.

WHAT IT DOES

See it. Prove it. Stop it.

See itDiscover

Shadow-AI discovery

Every AI tool your team touches, with personal, corporate and other-organisation accounts told apart. Anything undetectable is marked unknown rather than assumed.

  • Every tool in use, including the ones nobody approved
  • Personal vs corporate accounts, inferred from login domains
  • Which kinds of sensitive data go where, by tool and by person
  • Every event scored low, medium or high
Prove itComply

The compliance record

Every observation becomes an audit-ready artefact: the AI Register, an Exposure Report, vendor due-diligence records and an audit trail, mapped to the EU AI Act and GDPR.

  • AI Register and Exposure Report, exported as PDF
  • EU AI Act Art. 50 and GDPR Art. 30 alignment built in
  • DPIA recommendations with named reasons
  • Full audit trail, metadata only
Stop itEnforce

Control at the moment of send

Your policies act before anything leaves the browser: warn, coach towards the approved tool, block, or mask the sensitive values out of the prompt. Off by default, and it fails open, so a broken rule never takes a work tool down.

  • Warn, coach, block or mask, decided on-device
  • Policy engine per team, role and tool
  • Tokenisation with the keys on your side
  • Tamper-evident log of every decision

Masking, on the wire

What your teammate sends

Chase the overdue payment on DE89 3704 0044 0532 0130 00 and draft a polite reminder

What the AI tool receives

Chase the overdue payment on [REDACTED:IBAN] and draft a polite reminder

Mask rewrites the outbound request itself, on the device. With tokenisation on, the value becomes a reversible token instead, and the key never leaves your side.

Off by default

Enforce never silently intercepts. An admin authors the rules, per team, role and tool, and flips the switch.

Fails open

If a decision cannot be made in time, the send proceeds and the stand-down is recorded. Governance never takes a work tool down.

Proof of prevention

Every decision lands in a tamper-evident, hash-chained log: which policy, which action, when. Metadata only, never the content.

IN THE BROWSER

An extension your staff can read.

StructLine runs as an extension on every enrolled browser. Each person can open it and see, in plain language, exactly what their organisation sees. That transparency is often what gets a DPO or works council to say yes.

StructLine extension popup in zero-retention mode on chatgpt.com
Zero-retention mode. Incidents are reported as tool, account type and categories. The text itself never leaves the device.
The extension notice titled What your organisation will see
Every employee sees what is shared: which tools, work or personal account, and the kinds of data detected. Never the values.
StructLine extension popup with content collection switched on
With collection on, sensitive values are redacted on the device before anything is sent.

WHAT IT LOOKS FOR

It catches the sensitive data and ignores the noise.

Nearly every check has to add up: a real payment card, a valid passport number, an IBAN that passes its checksum. Everyday text does not set it off. StructLine names what it found, flags what the whole paste looked like, and estimates the size of a bulk one, all without keeping the text itself.

  • Personal data

    Names, email addresses, phone numbers and postal addresses. A list with no card numbers in it is still personal data, and StructLine flags it.

  • Bank and payment details

    IBANs, credit and debit cards, VAT numbers and routing numbers, each validated so an ordinary number never trips the alarm.

  • Identity documents

    National ID and passport numbers across the EU, UK, US and the Gulf, each checked against its real format.

  • Passwords and keys

    Passwords, API keys and tokens for 15+ vendors, private keys, and database logins with embedded passwords.

  • Crypto wallets

    Bitcoin and Ethereum addresses, checksum-verified.

  • Your own policies

    No customer names, no unreleased code-names, no internal financials. Flagged in findings on every paid plan, enforced in real time on Enforce.

PRIVACY BY DESIGN

Governance without collecting what your team types.

Most tools that watch AI usage store everything your staff write. StructLine is built the other way round, and each guarantee is precise about what it covers.

On-device

Basic detection runs on the device

The pattern engine runs locally in the browser. In zero-retention mode the raw text is analysed there and never sent anywhere.

Default

Zero-retention, out of the box

Which tools, personal or corporate accounts, the kinds of sensitive data, how much and when. All without storing a single word your team typed.

No third-party AI

AI detection without feeding a vendor

Opt into deeper AI detection and it runs on an open-weights model StructLine hosts, or that you host. Your data never goes to OpenAI, Anthropic or Google.

Transparent

Your workforce sees what you see

Right after enrolling, the extension shows each person what the organisation can see: the kinds of data and counts, never the values.

Full data control

Configurable retentionOne-click org-wide erasurePer-person GDPR exportStrict tenant isolation

COMPLIANCE OUTPUTS

The evidence a regulator, or a client's security review, asks for.

Other tools give you an alert. StructLine gives you the record: clean, self-contained documents you can hand to an auditor or attach to a security questionnaire.

AI Register

One entry per discovered tool: purpose, deployment type, accounts seen, data categories, risk, the vendor profile, EU AI Act transparency notes (Art. 50) and a GDPR block (Art. 30, plus DPIA recommended yes or no, with named reasons).

Exposure Report

What is actually happening: totals, the categories flowing out and to which tools, top risks, and per-tool and per-person breakdowns. Both export as PDF.

Admin

Manages everything across the organisation.

Compliance

Read-only, org-wide, for auditors and DPOs.

Users

See only their own activity.

A full audit trail records every privileged action, as metadata only, never content or secret values.

Mapped to the frameworks you are audited against

  • EU AI ActArt. 50 · Art. 4
  • EU GDPRArt. 25 · 30 · 35 · 44 to 49
  • UK GDPRArt. 25 · 30 · 35 · 44 to 49
  • ISO/IEC 27001:2022A.8.12 · A.8.23 · A.5.10
  • SOC 2 Type IICC6.6 · CC6.7
  • ISO/IEC 42001:2023Clause 6.1 · Annex A.10
  • PCI-DSS 4.0Req. 3 · Req. 4
  • HIPAA Security Rule§164.312(a)(2)Sovereign
  • NIST AI RMF 1.0GOVERN · MAP · MEASURESovereign

Mappings show where StructLine helps you meet each framework. They are not a certification, an audit or legal advice. Regulatory references current as of mid-2026.

EARLY DEPLOYMENTS

What the first week shows.

AccountingSlovenia

Five AI tools found in week one where the firm expected two or three, with 33% of activity on personal accounts.

Now when a client asks how we govern AI, we have the register to show them.
Venture studioUnited Kingdom

Fifteen people with due-diligence material and portfolio financials in the browser all day. The first scan flagged 20% of activity on personal accounts.

When a founder asks how we handle their numbers, the answer is on file.

Across all early deployments: 7,800+ findings recorded, 37% involving personal accounts.

PRICING

Priced on headcount. Flat for small teams.

Governance covers everyone's AI use, so the price follows total headcount and the rate steps down as you grow. Discover is free. Above 250 people, or for in-region and on-premise deployment, we scope a Sovereign contract with you.

Discover

Free

The way in.

€0

Any team size

  • Full shadow-AI discovery
  • Personal vs corporate accounts
  • Starter AI Register
  • On-device, zero-retention detection

Comply

Live

The evidence layer.

€125/month flat

Teams up to 25, then €4.50 per employee per month

  • Everything in Discover
  • AI Register and Exposure Report (PDF)
  • DPIA recommendations with named reasons
  • Vendor risk profiles, roles and audit trail
  • Optional self-hosted AI detection

Enforce

Live

Active control, on your terms.

€375/month flat

Teams up to 25, then €11 per employee per month

  • Everything in Comply
  • Warn, coach, block or mask, on-device
  • Policy engine: allow, warn, block, coach
  • Tokenisation with keys on your side

Sovereign

250+ seats

For 250+ and regulated, in-region.

Custom

Annual contract, scoped with you

  • Everything in Enforce
  • In-region or on-premise deployment
  • Your own infrastructure for detection
  • HIPAA and NIST AI RMF coverage

Rates by team size, billed yearly

Team sizeComplyEnforce
Up to 25€125 /month flat€375 /month flat
26 to 100€4.50 /employee/month€11 /employee/month
101 to 250€3.50 /employee/month€8.50 /employee/month
250+SovereignSovereign

List prices, billed yearly. Monthly billing is available at a higher rate.

Prices are net of VAT and in EUR.

QUESTIONS

What people ask first.

Only if you ask it to. Discover and Comply observe and record; nothing is intercepted. On Enforce, an admin turns on policies that warn, coach towards approved tools, block, or mask sensitive data, decided on the device. Enforcement ships off by default and fails open, so a broken rule never takes a tool down.

By default, no. Zero-retention records metadata only: the tool, the account type, the kinds of data and counts. Content collection is a separate, explicit admin opt-in, with redaction on by default even then.

No. AI detection runs on an open-weights model StructLine hosts itself, or that you host in a Sovereign deployment. No third-party AI provider is involved at any stage.

No. An admin adds the corporate domains, picks a privacy mode, invites the team and enrols a device with a single-use token. Most teams are live in an afternoon. For larger rollouts we run the pilot and go-live with you.

The EU AI Act, the EU GDPR and the UK GDPR. The register, the exposure report and the audit trail are mapped to all three, alongside ISO 27001, SOC 2, ISO 42001 and PCI-DSS controls.

Yes. Right after enrolling, the extension shows each person what the organisation can see: the kinds of data and counts, never the values.

Per employee on total headcount, billed yearly by default with monthly available. The per-employee rate steps down as you grow, and Discover is free.

SEE IT ON YOUR OWN AI USAGE

Book a StructLine demo.

In twenty minutes we show you the shadow-AI picture for a team like yours and the register it builds, mapped to the EU AI Act and GDPR. Nothing your staff type has to leave their machines.

WHAT COMES WITH IT

  • Rollout led by a PrincipalScope, pilot and go-live owned by one senior engineer, working with your compliance, legal and IT leads.
  • Integration with your systemsSharePoint, ERPs, document stores, identity. We build the connections the product does not ship with.
  • Support after go-liveConfiguration, policy tuning and new use cases handled by people who know your setup, in your time zone.