Proxaradocs
Guides/Start here

Choosing Connect or Endpoint

Proxara Connect governs what AI reads out of the firm's systems and installs nothing. Endpoint Protection governs what a person types into any AI tool on a managed machine. Which to start with, and when a firm runs both.

Updated July 2026

Proxara ships two products on one policy engine. They protect different moments, and the difference states in a line: Proxara Connect governs what AI reads out of the firm's systems. Endpoint Protection governs what a person types into an AI tool.

Proxara Connect

An employee asks Claude for something held in the firm's mail, calendar, Teams, files, or tasks. Claude reaches the firm's connector. Proxara retrieves only what that person can already open, replaces protected client references with stand-ins before anything reaches the model, and shows the real records in a view inside the conversation.

Nothing installs. No device management, no certificates, no change to anyone's laptop. The Microsoft side is one administrator consent, granted once.

Endpoint Protection

A native agent runs on managed macOS and Windows machines. It reads AI traffic through the operating system's proxy path, opens a connection only on positive evidence that the destination is an AI service, and seals sensitive values into reversible tokens before a prompt leaves.

That reaches what no connector can: text typed straight into a browser, files dragged into a chat, desktop AI apps, and coding tools.

What each one covers

Proxara ConnectEndpoint Protection
Work the firm's systems holdGovernedNot in scope
Text typed into a chatNot in scopeGoverned
Files uploaded by handNot in scopeGoverned
Installed on a deviceNothingOne signed package
To startOne administrator consentA managed rollout

The boundary runs both ways. A connector cannot see what someone types. An agent on a laptop cannot govern a connector running inside an AI vendor's own cloud.

Where firms usually start

Connect is the shorter path, because there is nothing to deploy and nothing to book with IT. A firm can be running on its own tenant without opening a device project.

Endpoint follows when the firm wants the same policy applied to everything else on the machine. Firms that already run device management sometimes take them in the other order, which works equally well.

Running both

Both products share one policy, one identity picture, and one signed record. Adding the second changes nothing underneath: no migration, no re-enrollment, and no second console.

Where to go next

To do thisRead
Set up the no-install pathConnect quickstart
Set up the device pathEndpoint quickstart
See both end to endHow Proxara works