Skip to content
Bastyx
Book a Demo
High-risk actions

The AI flags it. A passkey approves it.

Bastyx reads outgoing email and prompts to AI chatbots such as ChatGPT before they leave, and flags anything that looks like customer data, credentials, source code or other information your company can’t afford to lose. Your policy decides what happens next: a warning, a block, or a passkey from the person sending it.

A prompt to ChatGPT from Alex Morgan, checked by Bastyx before it’s sent. The model found customer data (214 names and emails, high risk), revenue for each account (elevated) and an external AI destination. Overall risk is high. The rule ai-chat-customer-data requires a passkey to send, so Alex can edit the prompt or send it with a passkey, and the decision is recorded without the prompt itself.

What it is

What is high-risk action verification?

High-risk action verification is a check that runs before an email is sent or a prompt is submitted to an AI chatbot such as ChatGPT. A language model reads the content and rates the risk that it exposes important company data. When the rating crosses the level your policy sets, the person has to confirm with a passkey, security key or fingerprint before it goes through, and the decision is recorded.

The AI never approves or sends anything on its own. It can only raise the bar to a passkey: phishing-resistant authentication from the person’s own device.

Built on authentication

It still comes down to authentication.

An AI model is good at noticing that a message looks like a customer export. It isn’t a security boundary: it can miss things, flag harmless ones and be steered by text written to fool it. So in Bastyx the model never has the final say. It can only raise the bar to a check that can’t be faked.

The AI notices

  • Reads the email or prompt before it leaves
  • Rates the risk and names what it found
  • Explains why, in one line a person can read

Your policy decides

  • Sets which risk levels and categories need what
  • Differs by channel, recipient, AI tool and team
  • Keeps rules that apply whatever the AI says

A passkey confirms

  • Needs the person, present, on their own device
  • Can’t be clicked by malware, a stolen session or an agent
  • Records exactly who released the message

Why a passkey, not an “Are you sure?” button

A confirmation button proves only that something clicked it. An attacker with a stolen session cookie can click it, so can malware, and so can an AI agent working in the browser. A passkey is a FIDO2 signature that needs the person to be present on their own device, with a touch or a fingerprint, and it can’t be produced on a look-alike domain. That turns “someone approved this” into “Alex approved this, on Alex’s laptop, at 14:32”.

The same holds in reverse. A risk check on an account an attacker already controls only slows them down, which is why every Bastyx sign-in is passwordless and phishing-resistant from the start. How FIDO2 resists phishing and AI-driven attacks.

Your policy

You decide when a passkey is needed.

Choose what counts as sensitive, how each channel responds, and who it applies to. Rules are readable and reviewed like any other access policy.

  • Customer and personal data

    Customer lists, contact details, support exports and anything that identifies a person.

  • Credentials and secrets

    API keys, passwords, private keys, tokens and connection strings pasted into a message.

  • Source code

    Proprietary code, configuration and infrastructure details copied into a chatbot.

  • Financials and pricing

    Revenue, forecasts, unreleased pricing and deal terms.

  • Legal, HR and deals

    Contracts, personnel matters, board material and acquisitions.

  • Your own categories

    Describe what matters in plain language, such as “anything about Project Atlas”, and the model looks for it.

Four responses

Allow and record
The message goes through. The verdict is logged for review.
Warn
The person sees what was flagged and why, then decides whether to edit or send.
Require a passkey
The message waits until the person confirms with a passkey, security key or fingerprint on their own device.
Block
The message isn’t sent. The person sees why, and the security team is notified.

An example policy

  • Customer and personal data

    Email to external recipients
    Require a passkey
    Prompts to AI chatbots
    Require a passkey
  • Credentials and secrets

    Email to external recipients
    Block
    Prompts to AI chatbots
    Block
  • Source code

    Email to external recipients
    Warn
    Prompts to AI chatbots
    Require a passkey
  • Financials and pricing

    Email to external recipients
    Require a passkey
    Prompts to AI chatbots
    Require a passkey
  • Anything about Project Atlas

    Email to external recipients
    Require a passkey
    Prompts to AI chatbots
    Block
  • Low risk

    Email to external recipients
    Allow and record
    Prompts to AI chatbots
    Allow and record

How it works

Checked before it leaves. Released by a person.

An email from Alex Morgan to an external address at northwind-partners.com, checked by Bastyx in Outlook. The model found customer data in an attached spreadsheet of 1,208 rows (high risk), an unreleased discount schedule (elevated) and a first-contact external recipient. Overall risk is high. The rule external-email-sensitive requires a passkey to send.
  1. 1

    Someone sends an email or submits a prompt

    In company email, or to an AI chatbot in a browser on a device enrolled in Bastyx.

  2. 2

    The model rates it before it leaves

    It returns a risk level, the categories it found and a one-line reason a person can read.

  3. 3

    Your policy decides the response

    Rules match on the risk level, category, channel, recipient and team. Rules you mark as always apply regardless of the model’s rating.

  4. 4

    A passkey confirms it, when the policy says so

    The person sees what was flagged, can edit it, or confirms with a touch or a fingerprint. Nothing is sent until they do.

  5. 5

    The decision is recorded

    Who, when, which channel, what was flagged and what they decided, in the same audit log as every sign-in. Not the content itself.

Data handling

Read to protect it. Not kept.

Content
Evaluated when it’s sent, then discarded. Emails and prompts aren’t stored.
Audit log
Who, when, the channel, the categories found and the decision.
Training
Your content is never used to train models.
On-premises
On Enterprise, the model runs in your own data center or cloud account, next to the control plane.

Supported email clients, AI tools and browsers are listed on the compatibility page.

FAQ

High-risk action questions

What is high-risk action verification?

High-risk action verification is a check that runs before an email is sent or a prompt is submitted to an AI chatbot such as ChatGPT. A language model reads the content and rates the risk that it exposes important company data. When the rating crosses the level your policy sets, the person has to confirm with a passkey, security key or fingerprint before it goes through, and the decision is recorded.

Does the AI decide what gets sent?

No. The model only rates the risk and explains what it found. Your policy decides the response, and when it requires confirmation, only a passkey from the person’s own device can release the message. The AI can raise the bar; it can never approve anything on its own.

Why require a passkey instead of an “Are you sure?” button?

A button can be clicked by anyone or anything holding the session: an attacker with a stolen session cookie, malware, or an AI agent working in the browser. A passkey signature needs the person to be present on their own device, can’t be produced on a phishing site, and proves exactly who approved the message.

What happens when the AI gets it wrong?

A false alarm costs one passkey touch, and the person can see why it was flagged. A miss is why the check is one layer on top of phishing-resistant sign-in, least-privilege access and an audit log, not a replacement for them. Rules you mark as always apply regardless of the model’s rating.

Can a prompt injection or a cleverly worded message fool the model?

It might lower a rating. It can’t approve or send anything, because the model has no permission to. Deterministic rules, such as always requiring a passkey for attachments sent to external domains, apply whatever the model says.

Does Bastyx block people from using ChatGPT?

No. People keep using the AI tools you allow. Only prompts that match your policy are warned, held for a passkey or blocked. You can also list approved tools and apply stricter rules to the rest.

Does Bastyx store our emails or AI prompts?

No. Content is evaluated when it’s sent and then discarded. The audit log keeps the verdict: who, when, the channel, the categories found and the decision. On the Enterprise plan the model can run in your own environment.

Which email and AI tools does it work with?

Gmail in Google Workspace and Outlook in Microsoft 365 for email, and ChatGPT, Claude, Gemini and Microsoft Copilot in Chrome, Edge and Firefox through the Bastyx browser extension. See the compatibility page for current status.

How is this different from traditional DLP?

Traditional data loss prevention matches patterns, such as card numbers. A language model reads context, so it can recognize a pasted customer list or an unreleased roadmap that no pattern describes. And instead of a silent block, a flagged message ends in authentication: the person confirms with a passkey, and you know who did.

What about personal devices and personal accounts?

Checks run in company email and in browsers on devices enrolled in Bastyx. Personal devices and accounts are outside what Bastyx can see, which is why access policies keep company apps and data on enrolled devices in the first place.

See a risky prompt stop for a passkey.

A 20-minute live demo: a flagged ChatGPT prompt, a flagged email, the policy behind them and the audit log. We reply the same business day.

ChatGPT is a trademark of OpenAI. Claude is a trademark of Anthropic. Gemini and Gmail are trademarks of Google LLC. Microsoft Copilot, Outlook and Microsoft 365 are trademarks of Microsoft Corporation. They’re used here only to describe compatibility; Bastyx isn’t sponsored or endorsed by these companies.