Proxaradocs
Trust Center/Reference

Employee Monitoring Disclosure Template

Customizable templates for customers to notify employees: the monitoring disclosure for the Endpoint Protection device agent, and the lighter notice for Proxara Connect. State-specific language included.

Updated July 2026

Employee Monitoring Disclosure Template

Last updated: July 2026

Purpose: This page holds two templates for Proxara customers to customize and provide to their employees. The first, and the bulk of this page, is the monitoring disclosure for the Endpoint Protection device agent, whose deployment monitors AI interactions on managed devices. The second, at the end, is the lighter notice for Proxara Connect, which is not a monitoring deployment: it runs when an employee asks the firm's AI assistant for something, and the notice describes what happens to work content when they do. Customers must adapt these templates to reflect their specific policies, applicable state laws, and organizational requirements.

Proxara's Role: Proxara provides these templates as a starting point. Proxara does not provide legal advice. Customers should review any disclosure with their legal counsel before distribution to employees.


Template 1: Endpoint Protection Monitoring Disclosure


[Your Company Name]

Notice of AI Interaction Monitoring

Effective Date: _____________________

Dear Team,

This notice informs you that your organization uses Proxara, an AI governance and compliance tool, to monitor and protect interactions between employees and external AI tools used in the course of business.


What Is Monitored

When you use external AI assistants or AI features in connected business applications on company-managed devices, the following may occur.

Proxara inspects interactions with external AI assistants and AI features, including ChatGPT, Claude, Google Gemini, Perplexity, DeepSeek, Grok, Azure OpenAI, Amazon Bedrock, and Google Vertex AI, along with the AI features in the firm's connected business applications. It also observes Model Context Protocol (MCP) activity from AI clients. This applies whether you use these tools through a web browser, a native desktop application, or a command-line interface.

Specifically:

  • Prompts and responses you exchange with covered AI tools may be captured and reviewed by the compliance team for regulatory compliance purposes.
  • Files and attachments you upload to covered AI tools (spreadsheets, PDFs, documents, images) are captured and analyzed for sensitive content. The system extracts text from these files and evaluates whether they contain client data, financial records, or other regulated information.
  • Sensitive data (such as client names, account numbers, Social Security numbers, medical record numbers, and other identifiers) may be automatically redacted before your prompts reach the external AI service. The original values are then restored on your own screen when the AI responds. This process protects both you and the firm's clients.
  • MCP tool activity. Some AI clients (such as Claude Desktop, Cursor, or in-house agents) take actions through the Model Context Protocol. When MCP observability is deployed, tool activity is observed and recorded in a signed audit log. The compliance team can review MCP server usage at a governance level and may block or quarantine a server that poses a risk.
  • Flagged interactions that contain potentially sensitive or regulated information are surfaced for review by authorized compliance personnel. Depending on your organization's configuration, flagged event summaries may be routed to compliance officers via Slack, Microsoft Teams, or email.

What Is Not Monitored

  • The device agent does not intercept Microsoft 365, Microsoft Copilot, Teams, or Outlook network traffic; it passes through unmodified. The monitoring applies only to the external AI assistants and AI features listed above. (If your organization also uses Proxara Connect, the firm's AI assistant can retrieve your work content from Microsoft 365 when you ask it to; that is a separate, employee-invoked service described in the Proxara Connect notice below, not part of this monitoring.)
  • Sign-in pages and traffic to banking, healthcare, and government services are never intercepted. Those categories are excluded in the security certificate itself and refused by the software before any check runs.
  • Personal browsing activity is not captured. The tool only intercepts traffic to the covered AI services.
  • Personal communications (email, messaging apps, phone calls) are not captured.
  • Interactions with AI tools on personal devices outside the company network are not captured (unless you are accessing company resources).
  • The content of general, non-AI web browsing is not captured.
  • Non-AI application traffic is never intercepted or inspected.
  • Direct, human-driven use of internal tools (Slack, Notion, Drive, and similar) is not affected by MCP observability. The observability layer only records calls that an AI client makes to those tools through the Model Context Protocol. When you use those tools yourself, nothing about the experience changes and nothing additional is recorded.

Why We Monitor

Your organization operates in a regulated industry and is required to maintain oversight of how sensitive information is handled. AI tools can inadvertently transmit regulated data (client names, financial details, health information, privileged communications, or other sensitive data) to third-party services. This monitoring program helps the firm:

  • Protect client confidentiality and meet regulatory obligations.
  • Detect and prevent inadvertent data exposure.
  • Maintain auditable records as required by applicable regulations.
  • Support employees by automatically redacting sensitive data before it leaves the firm's environment.

How Data Is Used

  • All intercepted interactions are held within the firm's dedicated, isolated cloud environment for a short, configurable retention window (seven days by default) and then automatically deleted. Non-flagged interactions are retained during that window and purged; they are not surfaced to the compliance team.
  • Flagged interactions (those containing potentially sensitive data) are surfaced for compliance review. Once reviewed, they may be sent to the firm's compliance archive.
  • Review by the compliance team is focused on detecting sensitive data exposure, not on evaluating employee performance or productivity.
  • Intelligence insights derived from monitoring are reported at the firm level only and are never presented as assessments of a named individual.

Who Has Access

  • Only authorized members of the compliance team have access to review flagged interactions.
  • Access is controlled through role-based permissions, and all reviewer actions are logged in a tamper-evident audit record.

Data Protection

  • All data processing occurs within a dedicated, isolated cloud environment provisioned for your organization. No shared multi-tenant environment holds your firm's data.
  • Data is encrypted in transit and at rest.
  • For this device-level monitoring, the link between redacted tokens and the original values is held in an encrypted vault on your device. Retiring a token destroys its key, making the original permanently unrecoverable.
  • When device-level protection is deployed, the organization's security certificate is installed on your device. This certificate is restricted to covered AI provider domains only and is removed when the software is uninstalled.
  • If the system's certificate is not trusted by your device, the agent passes your traffic straight through to the real destination and interception is suspended. You will never see a certificate error caused by Proxara.
  • No monitoring data is shared with third parties outside of the compliance function and the firm's authorized sub-processors.

Your Rights

  • You may request information about what monitoring data pertains to you by contacting your compliance team.
  • You will not face retaliation for asking questions about this monitoring program.

State-Specific Notices

Customers must include applicable state-specific language below. The following are required notices based on employee locations.

#### Connecticut

Connecticut law (Conn. Gen. Stat. § 31-48d) requires employers to provide prior written notice of electronic monitoring. This notice satisfies that requirement. Your organization engages in electronic monitoring of employee interactions with external AI tools as described above.

#### Delaware

Delaware law (19 Del. C. § 705) requires employers to provide prior notice of electronic monitoring. This notice satisfies that requirement.

#### New York

New York law (N.Y. Civ. Rights Law § 52-c) requires employers who monitor employee electronic communications to provide prior written notice. This notice satisfies that requirement. A copy of this notice has been or will be posted in a prominent location.

#### California

California employees have privacy rights under the California Constitution and the CCPA/CPRA. Monitoring is limited to interactions with external AI tools for legitimate business purposes (regulatory compliance). Employees may exercise their CCPA/CPRA rights by contacting your organization's designated privacy contact.


Acknowledgment

I acknowledge that I have received and read this notice regarding the organization's AI interaction monitoring program.

Employee Name: _______________________________

Employee Signature: _______________________________

Date: _______________________________


Contact

If you have questions about this monitoring program, contact your compliance team or HR department. For general questions about Proxara's data practices, contact support@proxara.ai.


Template 2: Proxara Connect Notice

When to use this template: when the organization deploys Proxara Connect (the firm's AI assistant connected to Microsoft 365 through Proxara), with or without the device agent. This is a notice about what happens to work content when an employee uses the connected assistant; it is not a monitoring disclosure, because the service runs only when the employee invokes it.

## [Your Company Name]
### Notice: Using [Claude / the firm's AI assistant] with the Firm's Systems
Effective Date: _____________________
Our firm has connected [Claude / our AI assistant] to our Microsoft 365 systems through Proxara, a protective layer that runs in the firm's own environment. This notice explains what happens when you use it.
It runs when you ask. Nothing is installed on your device, and nothing happens until you ask the assistant for something held in the firm's systems, for example a meeting brief or a summary of a client thread.
It sees what you can see. You connect with your own Microsoft account, and every request runs under your own permissions. The assistant can never reach a mailbox, folder, or site through Proxara that you cannot already open yourself.
Client information is protected before it leaves. Before your request reaches the AI service, Proxara replaces client names and other protected details with neutral stand-ins inside the firm's environment. You see the real names and records in the Proxara view inside the conversation; the AI service works with the stand-ins. For certain categories the firm designates, the substance stays inside the firm's environment entirely.
Actions are confirmed by you. If you ask the assistant to draft a reply or create a task, the real final version is shown to you for confirmation before anything happens.
Your requests are on the firm's record. Each request and its outcome is recorded with your identity, in the same way the firm's other systems of record work. The record shows what was asked, what sources were used, and what was protected; it is reviewed for supervision of client-information handling, not to evaluate your performance or productivity.
If you have questions about this notice, contact [compliance contact].
Employee Name: _______________________________
Employee Signature (where the organization requires acknowledgment): _______________________________
Date: _______________________________