This tool does not fit us.
- 1 See
DeepSeek shows up. Nobody asked for it.
- 2 Decide
Not allowed, after the catalog assessment.
- 3 Help
Anyone opening it sees the decision and the alternative.
- 4 Substantiate
Use drops, the alternative wins.
Safe AI use for organisations
BeeSensible shows which AI tools your people actually use. You decide per tool what is allowed, and anyone who opens a tool sees that decision right away.
14 days free, no credit card. Rolled out across your organisation within the hour.
"Awareness fades when you're busy. That's why we use BeeSensible."Debby Elfrink, Operations director, Speck Pompen
Plus everything else that is running
The problem
Most teams cannot say which AI tools they use, or what goes into them.
KPMG and the University of Melbourne asked 48,000 working people in 47 countries how they use AI on the job. The answers describe everyday behaviour, not rare accidents: people work fast, paste context, and keep their AI use out of sight.
Source: KPMG & University of Melbourne, Trust, Attitudes and Use of AI: A Global Study, 2025.
How it works
Four steps, on repeat. See what actually happens, decide what fits, help people at the moment itself, and substantiate with what happens next.
Step 1 · See
Running policy on assumptions is guessing. BeeSensible shows which AI tools are actually used in your organisation, including the ones nobody ever requested. You see how that use develops and where sensitive data shows up.
That changes the conversation. No longer: may our people use AI? But: this is what our people actually use, what do we think of it?
What we do and do not seeStep 2 · Decide
Per tool you set what is allowed: allowed, limited use, no decision yet, or not allowed. Not blindly. Under every tool sits a risk assessment by BeeSensible, from a catalog of 865 assessed AI tools, with an indicative EU AI Act classification per tool.
The choice is and stays yours: allowed, limited use, not allowed, or no decision yet. BeeSensible never decides for your organisation.
How we assess toolsStep 3 · Help
A measure only works when people can act on it. So BeeSensible brings your decisions to the moment of work: anyone opening a tool with a decision on it sees that decision right away, with the approved alternative leading. Continuing is always possible; BeeSensible never blocks.
People also get the means to work responsibly: sensitive data such as a card number or a customer's name gets a marking while someone types, with the choice to replace, mask, or remove. And a document is cleaned up front with document anonymisation.
Grok is not allowed here
Your organisation does not allow this tool for work. Use an allowed alternative.
Use instead
Open ClaudeAlso allowed: ChatGPT ·Mistral Le Chat
Grok is allowed here, with limits
Your organisation allows this tool with limits. Only use it with anonymised data.
Use instead
Open ClaudeAlso allowed: ChatGPT ·Mistral Le Chat
No decision yet on Grok
Your organisation has not made a decision on this tool yet. Do not share personal data or confidential business information here.
Use instead
Open ClaudeAlso allowed: ChatGPT ·Mistral Le Chat
Only enter public information here
Step 4 · Substantiate
Policy on paper does not tell you what happens next. BeeSensible shows how your policy lands in practice: how much gets fixed before anything leaves, what happens with notices, and what share of AI use runs through approved tools.
Accountability translates that into frameworks like GDPR and NIS2: from data minimisation at the moment of input to a current register of AI services. Per measure you see what you substantiate with BeeSensible, and honestly what you do not yet. And whatever stands out here goes back to seeing: that is where the next round starts.
Data minimisation at input
Sensitive data marked and handled before sending
Register of AI services
Vendor, classification, and a decision per tool
Appropriate technical measures
Detection active on the supported applications, handling still below the norm
Personal data breach notification
BeeSensible provides the signal, not a reporting process to the regulator
Roll out BeeSensible and look at what is already happening. Deciding, helping, and substantiating follow from there.
Three situations
The same four steps, three different decisions. The choice stays yours.
DeepSeek shows up. Nobody asked for it.
Not allowed, after the catalog assessment.
Anyone opening it sees the decision and the alternative.
Use drops, the alternative wins.
The video team uses an AI video tool.
Limited: not for customer or personal data.
That condition appears on opening.
You see whether use shifts.
Five tools for the same task.
One assessed and approved as the preferred route.
Open another tool: one click to the preferred one.
The share via approved tools grows.
The catalog
Before you can decide anything about a tool, you need to know what it does with your data. Where the vendor sits, whether it trains on what you type, whether a processing agreement exists, whether incidents are known. Finding that out takes an afternoon per tool, and tomorrow there is a new name in a colleague's browser.
We did it for 865 tools, and we keep doing it. Whatever surfaces in organisations or comes out of our own research goes through the same assessment and joins the catalog with a full fact sheet. What is left is the question only you can answer: is this allowed here, and under what condition?
The GDPR asks for a record of processing, NIS2 for a view of your suppliers, and the EU AI Act for demonstrable AI literacy. Because every observed tool is recorded with its vendor, hosting region and training policy, and carries a decision from your organisation, you can answer at any moment.
Which tools are in use, and for what
Every observed tool is in the register, with vendor, country, hosting region, training policy and the kind of work it is used for.
Which of them fit your policy
One decision per tool: allowed, limited use, not allowed, or no decision yet. Nothing is silently approved; the decision is always yours.
What you do to uphold that policy
Anyone opening a tool you have decided something about sees it at that moment, right in the page. That the notice appeared is counted, without content and without a name, so you can show the mechanism actually reached people.
The overview does not establish that you comply with the law. It shows which measures you can substantiate with measurements, and which you cannot. The judgement stays with you.
See the catalogOperations director Debby Elfrink fully embraces AI. She sees the upside, wants her team to use it, and knows what can go wrong.
Everyone here knows you have to be careful with customer data. But that awareness fades when you're busy. Knowledge is no guarantee of behaviour. That is exactly why we use BeeSensible.
Annemieke Jongbloed advises SMEs on AI governance through Way Projects, a BeeSensible partner. She brings HR, change leadership and everyday AI use together.
Making agreements is step one. Giving employees the means to follow those agreements in practice is the next.
Your team simply carries on working while the list fills up. After that, you decide what is allowed.
Privacy by design
Built to protect your organisation without watching your people. Processing happens at European companies, nothing of it is kept, and the dashboard only counts.
Dear Eva Eriksson,
Someone types
In ChatGPT, email, or a document. BeeSensible recognises sensitive data in the text itself, at the moment it matters.
European servers
On our own servers at Scaleway in Amsterdam and Hetzner in Germany. European companies, with no US parent.
Counts, not content
The dashboard shows how much was marked, of which type, in which app, and what happened next. Never what someone typed, never per employee.
Why BeeSensible
Most employees have no intention of being careless with AI. They just face small decisions all day while doing their actual job, and a policy document has no answer at that moment. So most teams have already tried to manage the risk one of these ways. Each one breaks at the same point: someone is busy, pastes context, and hits send.
People know the rules after a workshop and forget them under deadline pressure. Knowledge is no guarantee of behaviour.
BeeSensible puts the warning in the draft itself, at the moment the risk appears: the extension of your training. That is why we work with training and advisory partners.
See our partnersClassic DLP and monitoring suites can watch for sensitive data, but they send your team's text to a vendor cloud to do it. The privacy tool becomes a privacy risk of its own.
With us the text sits on our own servers at European companies, and is wiped right after the check. No US parent to serve an order on, and nothing kept, so there is nothing to look back at later.
Block ChatGPT and people move to personal accounts and tools IT has never heard of. The risk does not disappear. It moves out of sight.
BeeSensible blocks nothing. It shows which tools are used, and shows your decision the moment someone opens one that is not approved.
Hoping it goes well, while 48% of workers admit putting sensitive company information into public AI tools (KPMG and University of Melbourne, 2025). One pasted client record can become a reportable incident.
BeeSensible shows the patterns of what almost left, without storing what people write.
The parts
Every part runs the same four steps. The first three can be bought on their own; Substantiate falls out once Realtime Privacy and AI Governance are both running.
Frequently asked questions
The browser extension for Chrome and Edge, and the desktop app for macOS (Apple Silicon) and Windows 10 or 11. The desktop app covers Outlook, ChatGPT, Claude, and Microsoft Copilot as separate programs, and anonymises documents. Each workstation takes a few minutes.
Yes, through Microsoft Intune. The extension installs on its own, people sign in with their work account, and the desktop app installs silently in the background. The full instructions are in the documentation. With a managed rollout your organisation is up and running inside an hour.
Totals per tool, per kind of data, and per app, and what was done with a marking. Never the text itself, and no per-employee view anywhere. Who did something is not recorded, so it cannot be looked up either. That makes BeeSensible something other than a monitoring system. Whether your works council needs a say is for your own organisation to decide; we supply the material for that conversation.
On our own servers: the application at Scaleway in Amsterdam, the models at Hetzner in Germany. These are European companies rather than a European region of an American cloud, so there is no US parent that can be ordered to hand data over; both are ISO 27001 certified. The text is checked in working memory and discarded straight after, never written to disk. No external AI service is involved.
Always. BeeSensible never blocks and never changes your text by itself. It does count, without content and without a name, how often something was sent despite a marking. That figure exists to test your policy, not to confront a person.
14 days free, with every module and no credit card. Your team simply carries on working while the list of AI tools fills up. Want to continue afterwards? Then you pick a plan; do nothing and the trial stops by itself.
Starter begins at 5 euros per user per month billed yearly and carries one module of your choice. Business is from 10 euros per user per month billed yearly and carries every module. From 100 users there is volume pricing and we put together a quote.
Classic DLP looks at files and traffic, and often sends your people's text to a vendor cloud that falls under US law. BeeSensible sits at the moment of typing in the browser, processes at European providers without keeping anything, never blocks, and never shows individuals. The two do not compete: they act at different moments in the same chain.
See within 14 days which AI tools are actually in use, while your team simply keeps working. After that, you decide what is allowed.
14 days free, no credit card. Rolled out across your organisation within the hour.
From our blog
Practical articles on where sensitive data leaks into AI tools, what the rules ask of you, and how to roll out AI without a ban.
Rens, BeeSensible
I am happy to give you a twenty-minute tour. Leave your details and I will find a moment that suits you. Calling or emailing works just as well.