Article 35 risk assessment for the Endpoint Protection device service: processing activities, necessity, proportionality, risk scenarios, and mitigation measures.
Updated July 2026
Last updated: July 2026
Controller / Processor: Proxara, Inc.
Assessment Date: June 2026
Assessor: Jex Pearce, Founder
Review Cycle: Annual, or upon material change to processing activities
This Data Protection Impact Assessment ("DPIA") is prepared in accordance with Article 35 of the UK GDPR and EU GDPR. It assesses one processing activity: the Endpoint Protection device service (network-layer interception, redaction, and MCP observability on managed devices) as deployed within customer environments, and describes the measures implemented to mitigate its risks. The separate Proxara Connect processing activity (server-side retrieval from Microsoft 365 under delegated permissions) has its own assessment: the Proxara Connect DPIA. Statements in this document about where data is and is not stored describe the device service only.
Endpoint Protection is Proxara's device-level data-protection and observability product. A signed agent, deployed through the firm's MDM, redacts sensitive data from AI requests at the network layer before they leave the firm and records a cryptographically signed audit trail for compliance. (Proxara's hosted connector product, Proxara Connect, is assessed separately in the Proxara Connect DPIA.)
The system operates through two integrated components:
Both components share the same classification API, the same identity vault, and the same cryptographically chained audit log.
The system operates through three primary functions:
Real-time semantic redaction. The service intercepts employee prompts before they reach external AI tools. The classification engine identifies sensitive identifiers (client names, account numbers, Social Security numbers, medical record numbers, and similar data) and replaces them with context-preserving semantic tokens (for example, "[Client_A]", "[Account_Num_1]"). The redacted prompt is forwarded to the external AI. When the AI responds, the service restores the original values from a device-side vault so the employee sees natural text. The external AI provider receives the redacted version in place of the detected sensitive values.
Compliance monitoring. The service captures the interaction (prompt text, AI response, and any uploaded files) and sends it to the classification engine. The classifier analyzes each interaction for compliance risk based on the customer's industry profile and organizational policies. Interactions that may contain sensitive data or regulatory risk are flagged for compliance officer review.
MCP governance. When employees use MCP-capable AI clients, the service observes tool activity, tags each event against the compliance control library, and surfaces governance decisions (block or quarantine per server) to the compliance team. MCP requests the device proxy can inspect are redacted with the same engine as other AI traffic before they reach a downstream server.
Proxara inspects interactions with external AI assistants and AI features, including ChatGPT, Claude, Google Gemini, Perplexity, DeepSeek, Grok, Azure OpenAI, Amazon Bedrock, and Google Vertex AI, along with the AI features in the firm's connected business applications. It also observes Model Context Protocol (MCP) activity from AI clients.
The device agent does not intercept Microsoft 365, Microsoft Copilot, Teams, or Outlook network traffic; it passes through unmodified. (Proxara Connect's server-side retrieval of Microsoft 365 content is a separate processing activity, assessed in its own DPIA.) Sign-in pages and traffic to banking, healthcare, and government services are never intercepted.
Proxara provisions and manages a dedicated, isolated cloud environment on behalf of each customer (Amazon Web Services). There is no shared multi-tenant environment. Each customer deployment is a single-tenant instance running in a dedicated AWS account.
Proxara-Managed (default). Proxara provisions, deploys, and operates the customer's dedicated AWS environment. The customer receives read-only access to the environment and retains full ownership of all data. On termination, the customer may take ownership of the dedicated AWS account or Proxara will delete all data and certify destruction.
Customer-Managed (alternative). Proxara provides deployment templates and software. The customer deploys and operates the service in their own AWS account. Proxara does not access customer data.
The agent reaches employee laptops through the firm's MDM (Jamf, Intune, Kandji, and compatible platforms); employees install nothing themselves.
This DPIA addresses the Proxara-Managed deployment model, where Proxara acts as a data processor.
| Data Category | Source | Retention |
|---|---|---|
| Employee identifiers (name, employee ID, device ID) | Customer-provided during deployment | Duration of service |
| Prompt text submitted to external AI tools | Captured by the service | All intercepted interactions are stored briefly. Default retention is 7 days (configurable; 0 = retain until manually purged). Purged automatically at the end of the retention window. |
| AI response text | Captured by the service | Same as prompt text |
| Uploaded file content (spreadsheets, PDFs, CSVs, documents) | Captured by the device proxy when an employee uploads files to AI tools | Retained during the same window as the associated interaction. Original file bytes are never stored; only redacted text and a hash of the redacted bytes. |
| Identity vault tokens (original value to semantic token mapping) | Generated on-device by the classification engine | Held in an on-device encrypted vault; the device service does not store these mappings in the customer's cloud environment. Retiring a token destroys the AES-256-GCM key, making the original unrecoverable. |
| Device enrollment data (device ID, platform, hostname, agent version) | Collected during device service registration | Duration of service |
| Classification results (severity, risk category, data types) | Generated by classification engine | Retained as part of the interaction record and supervision audit log |
| Supervision audit log (reviewer actions, status changes, notes) | Generated by compliance workflow | Retained as the permanent supervision record. Contains metadata only; no original prompt or response content. Never purged. |
| Session metadata (provider name, page URL, timestamp) | Captured by the service | Retained with audit records |
| MCP tool-call records (tool name, server identifier, hashed arguments, classification, resolved egress mode) | Observed by the MCP component | Raw payloads are never stored; only hashes and signatures. Retained per customer-configured retention window. Cryptographically signed and hash-chained per tenant. |
| Per-server governance records (egress mode, taxonomy, compliance officer identity, optional DPA reference) | Set by the customer's compliance officer | Retained with version history; never physically deleted. |
Proxara does not intentionally process special category data (Article 9). However, depending on the customer's industry, employee prompts may contain:
The purpose of Proxara's processing is to prevent this data from reaching external AI tools. The redaction engine intercepts and replaces such data before it leaves the firm's environment.
| Recipient | Data Received | Legal Basis |
|---|---|---|
| AWS (Amazon Web Services) | All data processed within the customer's dedicated, isolated AWS environment. Amazon Bedrock processes prompt text for classification (Claude Haiku 4.5); Bedrock does not store model inputs or outputs. Amazon Textract processes file bytes for text extraction. | Sub-processor agreement (AWS Customer Agreement) |
| Google LLC (Google Workspace) | Outbound transactional and notification email: recipient addresses and email content. | Sub-processor agreement |
| Customer's compliance archive provider (e.g., Smarsh, Global Relay) | Where the firm enables the integration, interaction records the firm chooses to forward for regulatory archival | Customer's agreement with archive provider |
| Customer's communication platforms (Slack, Teams, email) | Notification summaries (severity, employee name, provider, brief excerpt) routed to customer-configured channels. Off by default; customer-controlled. | Customer-controlled; Proxara does not select or operate these platforms |
| Exa | Used only when Proxara researches an unrecognized MCP server's capabilities. Receives server or software metadata and a generated query; never employee content or personal data. | Sub-processor agreement |
| Sigstore Rekor (public transparency log, on by default) | Audit anchoring transmits only 32-byte Merkle batch root hashes. No personal data is sent. | Public service operated under the Linux Foundation. Anchoring runs by default and continues locally if the log is unreachable. |
Proxara does not sell, share, or disclose personal data to any other third party.
The customer (data controller) determines the lawful basis for monitoring employee AI interactions. Typical bases include:
Proxara processes personal data solely on the customer's documented instructions and for the purpose of providing the service as described in the Data Processing Addendum.
Employees at regulated firms are using external AI tools regardless of whether their firm has a formal AI policy. Industry surveys indicate over 70% of employees at advisory firms use AI tools, and the majority use personal devices or accounts outside employer visibility.
Without a technical supervision layer, firms face a binary choice: ban AI (unenforceable and commercially disadvantageous) or permit AI with no compliance oversight (regulatory risk).
Proxara resolves this by enabling supervised AI use: employees can use AI tools productively while the firm maintains the compliance oversight its regulators require.
Data minimization is core to the architecture:
The processing scope is narrowly targeted:
Less intrusive alternatives were considered:
| Alternative | Why Insufficient |
|---|---|
| Policy-only approach (no technical controls) | Unenforceable; does not provide regulators with evidence of active supervision |
| Post-hoc log review (no real-time interception) | Does not prevent sensitive data from reaching external AI tools; by the time a log is reviewed, the data has already been disclosed |
| Full network monitoring (DLP at network layer) | Disproportionate; captures all web traffic, not just AI interactions; higher privacy impact |
| Blanket AI ban | Commercially disadvantageous; studies show employees circumvent bans using personal devices |
Proxara is the least intrusive approach that satisfies the regulatory requirement for active supervision while preventing data leakage.
| Risk | Likelihood | Impact | Overall Risk | Mitigation Reference |
|---|---|---|---|---|
| R1: Unauthorized access to audit records. An attacker or unauthorized person gains access to stored prompts, responses, or file content containing personal data. | Low | High | Medium | M1, M2, M3, M4 |
| R2: Breach of identity vault. Token-to-original mappings stored on-device are exposed, enabling re-identification. | Very Low | High | Low | M5 |
| R3: Redaction failure. The classification engine fails to detect sensitive data in a prompt or file, allowing it to reach an external AI tool. | Medium | Medium | Medium | M6, M7 |
| R4: Excessive monitoring. Employees are subjected to disproportionate surveillance beyond what is necessary for compliance. | Low | Medium | Low | M8, M9 |
| R5: Data retained beyond necessary period. Audit records or file content retained longer than required. | Low | Medium | Low | M10 |
| R6: Sub-processor breach. AWS infrastructure or Bedrock service is compromised. | Very Low | High | Low | M11, M12 |
| R7: Employee awareness gap. Employees are not informed that their AI interactions are monitored. | Medium | Medium | Medium | M13 |
| R8: Inference from classification metadata. Even after purge of full text, retained metadata (severity, data types, risk category) could reveal information about the nature of an employee's work. | Very Low | Low | Very Low | M14 |
| R9: Device service root CA compromise. The per-tenant root CA private key is extracted from a device, enabling impersonation of AI provider domains for the firm's devices. | Very Low | High | Low | M15 |
| R10: Local vault data exposure. Identity vault data stored on the employee's device is accessed by an unauthorized party. | Very Low | Medium | Very Low | M16 |
| R11: Sensitive data reaches a downstream MCP server. MCP requests the device proxy can inspect are redacted before they reach a downstream server, but a server reached over a path the proxy cannot inspect could receive sensitive data. | Low | Medium | Low | M17 |
| R12: Tampering with the audit chain. A bad actor with local access attempts to alter, reorder, or delete events from the audit log to conceal an action. | Very Low | High | Low | M18 |
| R13: Tool-call supply-chain compromise. A poisoned or rug-pulled MCP server attempts to exfiltrate data via a malicious tool description, hidden instruction in a tool result, or a multi-step "leak then send" pattern. | Medium | High | Medium | M19 |
Each customer deployment runs within a dedicated, isolated AWS account and VPC provisioned and managed by Proxara on the customer's behalf. There is no shared multi-tenant infrastructure. Customer data does not commingle with other customers' data. Network security groups restrict inbound and outbound traffic to required ports and services. The classification API and database run in private subnets with no direct inbound internet access. The customer receives read-only access to the environment and retains full ownership of all data.
The customer owns the KMS keys. Proxara holds use-only rights and the customer can revoke access at any time.
All compliance reviewer actions (status changes, notes, feedback, escalations) are recorded in a dedicated append-only audit log. Entries are never updated or deleted. Each entry contains the event identifier, the action taken, the actor's identity, a UTC timestamp, and action-specific details. This provides the tamper-evident evidence trail required by regulators and ensures accountability for all access to personal data within the system.
Identity vault tokens (the association between a semantic tag and an original value) are held in an on-device encrypted vault. Each original value is sealed under its own AES-256-GCM key derived via HKDF. The device service's mappings are not transmitted to or stored within the customer's cloud environment (the separately assessed Proxara Connect service maintains its own server-side vault there). Retiring a token destroys its key irreversibly; the original becomes unrecoverable even if a backup of the vault is later obtained. On uninstall, the entire vault is deleted.
Proxara uses Claude Haiku 4.5 (via AWS Bedrock) for semantic classification. Semantic analysis understands context, distinguishing, for example, between a client's Social Security number and an employee's own personal information in a resume. The classification engine applies industry-specific rules (financial services, healthcare, legal, accounting) calibrated to the customer's regulatory environment.
When employees upload files to external AI tools, the system applies a multi-pass classification:
The device proxy's TLS interception is restricted to AI provider domains by X.509 Name Constraints in the root CA certificate and by domain matching in the proxy. The service does not access or monitor other websites, browsing history, keystrokes, or ambient data. The device agent does not intercept Microsoft 365, Microsoft Copilot, Teams, or Outlook network traffic. Non-AI traffic passes through the device's network stack untouched and is never decrypted or inspected.
All intercepted interactions are stored for a short, configurable retention window (default 7 days). At the end of this window, interaction records, prompt and response text, and file content are purged automatically. After purge, the supervision audit log retains metadata only (no content). The audit log is the permanent record of compliance activity. Cryptographic audit proofs are archived to S3 COMPLIANCE Object Lock for 7 years (meeting SEC Rule 17a-4(f), FINRA 4511, and NYDFS 500.6 minimums).
Where the firm has enabled an archive integration, interaction records can be forwarded to the firm's designated archive provider (Smarsh, Global Relay, or equivalent) for long-term regulatory retention before the purge window expires. That archive, not Proxara, is the firm's system of record.
Proxara's primary sub-processor is Amazon Web Services, which hosts the customer's dedicated environment and provides AI classification (Amazon Bedrock, running Claude Haiku 4.5) and document text extraction (Amazon Textract). Outbound notification email is sent through Google Workspace (smtp.gmail.com). Audit anchoring uses Sigstore Rekor by default (cryptographic hashes only; no personal data). Exa is used solely for researching unrecognized MCP server capabilities (server metadata only; no employee content). Customer-connected integrations (Slack, Microsoft Teams for notifications, Google Calendar for context) are off by default and controlled by the customer. The full sub-processor list is published separately and updated with 30 days' notice.
AWS maintains SOC 1/2/3, ISO 27001, PCI DSS, FedRAMP, and HIPAA certifications. AWS Bedrock does not store model inputs or outputs; data is processed in real time and discarded.
Customer data is processed within the customer's selected AWS region (default: US regions). Where data is transferred from the UK or EEA to a country without an adequacy decision, the Data Processing Addendum incorporates Standard Contractual Clauses (Module Two: Controller to Processor) and, for UK transfers, the UK International Data Transfer Addendum.
Proxara provides a customizable Employee Monitoring Disclosure Template that customers deploy to inform employees about monitoring. The device proxy surfaces a built-in notice on first use of any AI tool, which customers can customize with their firm name and compliance contact information. The notice explains what is monitored, why, what data is collected, and how employees can raise concerns.
After full text and file content are purged, the retained metadata consists of classification results (severity, risk category, data types detected) and audit trail entries. This metadata is designed to answer "was supervision active?" without retaining enough detail to reconstruct the original interaction. Risk category labels are generic ("data_sensitivity", "advice_risk") rather than content-specific. The underlying numeric risk scores are stripped server-side and never sent to the console.
The device service's root CA is per tenant: minted server-side at enrollment and delivered to each device over the authenticated enrollment envelope, so extraction of the key on one device is extraction of the firm's CA, and the risk is assessed on that honest basis. Two bounds apply. The CA certificate carries X.509 Name Constraints excluding sign-in, banking, healthcare, government, and security-tooling domains; verifiers that enforce constraints (Firefox and other NSS-based software) reject violations cryptographically, while macOS does not reliably enforce them on user-added roots, so the operating control there is the agent's runtime gate, which refuses the excluded categories before any connection is opened. The CA private key is stored in a system-protected directory readable only by the system account (file mode 0600, re-asserted on load). On uninstall, the CA is removed from the OS trust stores and all key material is deleted. The device service also verifies code signatures on update packages (macOS: Developer ID; Windows: Authenticode) to prevent supply-chain compromise.
If the agent's CA is not OS-trusted, the agent passes traffic straight through to the real origin and alerts the firm. Sites keep working; no Proxara certificate is ever presented without trust.
The identity vault is stored in a system-protected directory on the employee's device. Hourly cleanup removes expired tokens. On uninstall, the entire data directory is deleted. The device vault's data does not leave the employee's device and is not transmitted to the customer's cloud environment or to Proxara.
Proxara observes MCP activity from AI clients and redacts inspectable MCP requests with the same engine as other AI traffic before they reach a downstream server. Each observed tool call produces a signed audit event; raw payloads are never stored, only hashes and signatures. The compliance officer can classify each MCP server and can block or quarantine one through the governance console; block and quarantine decisions propagate to enrolled devices. Original values never enter the audit log, so a regulator can confirm whether a person's data was involved without the personal data being retained.
Every event is encoded in canonical form (RFC 8785 JCS for JSON records), signed with Ed25519, and linked into a per-tenant hash chain (each event references the SHA-256 of the previous event). Five-minute batches are Merkle-rooted, the root is signed, and each batch root is anchored by default to Sigstore Rekor, a public transparency log (hashes only; local recording continues if the log is unreachable). The offline proxara-audit-verify CLI confirms signatures, chain continuity, Merkle inclusion proofs, and the public-log timestamp, independently of any Proxara service. Tampering at any link breaks the chain and is detected by verification.
Three layers prevent a compromised downstream server from exfiltrating data: (a) tool descriptions, results, resource bodies, prompt messages, and task payloads pass through a semantic prompt-injection scanner with severity-graded actions (allow, annotate, sanitize, block); (b) a tool-call graph analysis catches multi-step patterns including read-then-exfil, enumerate-then-escalate, and leak-then-send, and surfaces them as policy signals; (c) tool descriptions are hashed on first sight and rechecked on every call so a mid-session mutation triggers a block. The component's STDIO subprocess pool validates arguments on registration to refuse any program string with shell metacharacters, user input interpolation, or unresolved variable expansion.
Customers configure the scope of monitoring (which AI providers, which employees, sensitivity thresholds) and are responsible for determining the lawful basis for processing, providing employee notice, and obtaining any required consent. Proxara provides documentation, disclosure templates, and technical controls to support customers' compliance decisions.
Employees are informed of monitoring through the Employee Monitoring Disclosure and the in-product notice the device proxy surfaces on first use of any AI tool. Employees exercise agency through the confirmation overlay, where they can review, accept, modify, or reject suggested redactions for each interaction. Employees may also raise data protection concerns through their employer's designated channels.
Customers with a designated Data Protection Officer are encouraged to review this DPIA and the Data Processing Addendum as part of their vendor assessment process.
| Framework | Status |
|---|---|
| HIPAA | Business Associate Agreement available for healthcare deployments |
| GDPR / UK GDPR | Data Processing Addendum with Standard Contractual Clauses available |
| CCPA/CPRA | Service Provider obligations documented in DPA |
| AWS Compliance | AWS Bedrock is SOC 2 compliant, HIPAA eligible, and GDPR-compliant. AWS maintains ISO 27001, SOC 1/2/3, PCI DSS, and FedRAMP certifications. |
Proxara's security program includes internal adversarial security reviews, least-privilege IAM, private-subnet data stores, KMS-encrypted storage, MFA-gated administration, and nightly automated audit-chain verification. Independent third-party penetration testing is planned.
This assessment identifies thirteen risks to data subjects arising from Proxara's processing activities. All identified risks are mitigated to Low or Very Low through the measures described in Section 4, with the exception of R3 (redaction accuracy) and R13 (MCP supply-chain), which carry residual Medium risk explained below.
Residual risks:
Overall assessment: The processing described in this DPIA is necessary and proportionate to the legitimate interests pursued. The residual risks are acceptable given the mitigation measures in place and the regulatory obligations that the processing is designed to satisfy. Processing may proceed.
Next review date: June 2027, or upon material change to processing activities.
For questions about this DPIA:
Proxara, Inc.
28 Geary St. Suite 650 PMB 5328, San Francisco, CA 94108
Email: support@proxara.ai
Security inquiries: security@proxara.ai