The two products end to end: the hosted connector that joins the firm's AI to Microsoft 365, and the device agent, sharing one policy and one signed record.
Updated July 2026
Proxara is two products on one foundation. Proxara Connect joins the firm's AI assistant to the firm's own systems through a protected path, with nothing installed on any device. Endpoint Protection puts a checkpoint on managed devices for everything typed and uploaded outside that path. A firm runs either, or both together, on one policy, one identity graph, and one signed record.
This page is how each one works; Choosing Connect or Endpoint covers which one a firm starts with.
The firm's Claude administrator adds one web address, the firm's own connector, and nothing installs on any device. Claude registers itself against that address the first time it connects, so there is no client ID, secret, or token for anyone to copy or store. Each employee then signs in with their own Microsoft account, and access is refused unless that person is a current employee in the firm's own records. That check runs again on every request, not only at sign-in.
An employee asks Claude to prepare for a client meeting. Claude calls the connector, and inside the firm's dedicated environment Proxara draws on the mail, chats, files, and tasks the firm already holds, retrieving only what that employee is already permitted to open.
Proxara's policy engine reads that material with the firm's own rules and enterprise context, then replaces every protected reference with a consistent stand-in such as [Person_0CE2473EA47B] before anything reaches the model. That evaluation runs inside the firm's environment, not on the employee's device. If a real name or address from a message would still be visible after the swap, the request stops rather than going out.
The model reasons over stand-ins. The employee reads the real records in a Proxara view inside the conversation, opened once, for that employee, for that one piece of work. What was retrieved is held only long enough to serve the answer and that view, then it expires.
Retrieving and acting are two separate consents, so a read approval never quietly becomes a write approval. Where the firm has granted the second, the model proposes the work against stand-ins and Proxara resolves the real target, checks the employee's own permission and the firm's rules, commits it inside the firm's environment, and reads back what changed.
Claude is the assistant Connect works with today. What Proxara Connect is tells this side end to end, and the Connect quickstart is the setup.
The device proxy is a native background service on macOS and Windows. It captures traffic through the operating system's proxy path and decrypts a connection only on positive evidence that the destination is an AI service, so browsers, desktop AI apps that honour the system proxy, coding tools, and API calls flow through one inspection point. It never blocks a site. When it cannot inspect traffic, it passes it through rather than breaking the connection, and the gap is reported instead of hidden.
As a prompt passes through, a classifier running on AWS Bedrock inside the firm's environment reads it in context and seals sensitive values into reversible tokens before the prompt reaches the model. The model sees only tokens such as [Client_A], so it can still answer usefully, and the employee gets the real values back. The posture is best effort with a coverage record: it records what it caught rather than promising that every value is always removed, and it never blocks.
The device proxy covers what it inspects and what it never touches, and the Endpoint quickstart is the fleet rollout.
[Person_1], account [ID_1], ahead of Thursday.Each product covers what the other cannot. Connect governs the connected path into the firm's systems, but anything a person types or uploads directly into an AI tool is already visible to that tool. The device agent is what covers typed text, uploads, and the AI traffic that never touches the connector.
Adding one to the other changes nothing underneath: same environment, same identities, same policy, same record, no migration.
Every governed interaction, connected or device-side, joins one signed, hash chained record. It is verifiable offline, so a later edit is detectable. Risk is reported as a band rather than a numeric score on a person.
The Connect half of that record is deliberately content-free. It carries counts, categories, states, and fingerprints rather than names, stand-ins, or the words of any message.
The console is where a compliance officer reviews activity and produces evidence. It is the regulatory artifact and the auditor's gateway, not a daily review queue. Proxara works quietly and surfaces something only when it would concern a leader, on a threshold the firm sets.
For evaluations, pilots, and paid deployments, Proxara provisions a dedicated, single-tenant AWS environment for each firm. What Connect holds for a firm stays inside that environment, encrypted at rest, and no central Proxara service holds the firm's Microsoft tokens. The free trial and sandbox run on Proxara-operated infrastructure with per-tenant isolation and deletion at the end. For the full security and compliance picture, see the Trust Center.