CattleGrid

Why CattleGrid?

Prevent sensitive data leakage and stay compliant.

Why choose CattleGrid

Your people want to use these tools, and they should — the gains are real. CattleGrid exists so that adopting AI properly doesn't have to mean adopting the risk that usually comes with it. It inspects the content of every outbound request against your configured inspection rules, matching regex patterns (UK National Insurance numbers, credit card numbers, postcodes) or keyword blocklists (internal project names, customer identifiers). See everything the platform does, or how Anonymise keeps data usable without exposing it.

What CattleGrid Does

CattleGrid sits between your applications and AI providers. Every AI API request passes through it. Before anything reaches Anthropic, OpenAI, Mistral, or Google, CattleGrid inspects the content, enforces your rules, and either blocks the request, redacts the sensitive data, or lets it through – logged and audited. It retains none of your data. Inspect, redact, block, discard. That is the complete sequence. See how it works technically.

What it never does

Streaming responses are piped straight back to your application with zero buffering and zero modification — the gateway does not sit in the way of what the AI generates. Request content is never stored on that path: it exists only during processing and is discarded when the request completes. There is no database of your prompts and no log of what your staff typed. Where you switch on conversation history, persistent memory or compliance review, that is your decision, your retention policy, and visible to you as such.

The only records retained are: usage metadata ( counts, latencies, status codes), violation summaries (rule triggered and action taken – not the content that triggered it), and configuration audit events.

On the gateway path this is not a policy position. It is an architectural constraint enforced at every layer.

What CattleGrid does for the person responsible for AI governance in a regulated SME.

MD / Senior Partner / CEO

What's the financial exposure if something goes wrong, and what does the board need to know?

Your people are already using AI. The only open question is whether anyone is governing it.

71% of UK employees are using AI tools their employer hasn't approved, and 51% do so weekly (Microsoft/Censuswide UK Shadow AI Survey, October 2025). That is not a future risk on a roadmap. It is a present condition inside your organisation, uncosted on any risk register you've likely seen.

£498,000. That is what the IBM Cost of Data Breach Report 2025 says a breach costs on top of the baseline when shadow AI is involved — on top of an average UK breach cost already at £3.29 million.

Governing this doesn't mean banning it. It means being able to back your people using the best tools available, and still sleep well — putting a control in place before the exposure crystallises rather than after.

DPO / Compliance Officer

Does your current AI usage create a data processor relationship you haven't documented?

Every time someone in your organisation pastes client or employee data into a public AI tool, that data reaches a third-party processor — whether or not anyone wrote that relationship down.

71% of UK employees are already using AI tools their employer hasn't approved, and 51% do so weekly (Microsoft/Censuswide UK Shadow AI Survey, October 2025). 83% of UK organisations have no controls in place over what leaves through them (BlackFog/Sapio Research, November 2025). If your RoPA and DPIAs were written before that usage started, they don't describe what's actually happening today — and an ICO enquiry or a client's own due-diligence questionnaire will ask you to reconcile the two.

CattleGrid's audit trail is cryptographically verifiable — tamper-evident by design, not by policy. It records what left, what was blocked or redacted, and when, automatically and continuously.

You wrote the policy. This is what makes it enforceable everywhere, not just where people remember to follow it.

CIO / IT Manager

What does this actually involve to set up, and how do you explain it upstairs?

Every AI governance project reaches an IT manager who has to answer both questions credibly, on the same afternoon.

71% of UK employees are already using AI tools their employer hasn't sanctioned, and 51% do so weekly, according to a Microsoft-commissioned survey of over 2,000 UK employees (Censuswide, October 2025). Separately, 83% of UK organisations have no controls in place over what leaves through those tools (BlackFog/Sapio Research, November 2025). None of that shows up in a board pack until something goes wrong — and when it does, the question of who was supposed to have visibility lands on IT.

CattleGrid's rule layer runs in-process with no external calls, targeting under 8 ms of added overhead. Governance doesn't become the reason things get slower, which is usually the first objection you'll need an answer for.

Deployment is a URL change. Nothing else in your application stack moves.

CISO / Head of InfoSec

Does your current AI usage create a data processor relationship you haven't documented?

Every time someone in your organisation pastes client or employee data into a public AI tool, that data reaches a third-party processor — whether or not anyone wrote that relationship down.

71% of UK employees are already using AI tools their employer hasn't approved, and 51% do so weekly (Microsoft/Censuswide UK Shadow AI Survey, October 2025). 83% of UK organisations have no controls in place over what leaves through them (BlackFog/Sapio Research, November 2025). If your RoPA and DPIAs were written before that usage started, they don't describe what's actually happening today — and an ICO enquiry or a client's own due-diligence questionnaire will ask you to reconcile the two.

CattleGrid's audit trail is cryptographically verifiable — tamper-evident by design, not by policy. It records what left, what was blocked or redacted, and when, automatically and continuously.

You wrote the policy. This is what makes it enforceable everywhere, not just where people remember to follow it.

Departmental Lead
(IFA / Practice Manager / Head of Legal)

Your regulator already has a view on this. Do you have the specific control that answers to it?

This isn't a generic AI governance question. It's the question your regulator has already started asking, in language specific to your sector.

If you're in legal services, the SRA's Codes of Conduct engage duty of competence, client confidentiality, and — for COLPs — firm-level supervision the moment AI tools touch client work, and the SRA has issued its own guidance and warning notices on generative AI use. If you're in financial services, the FCA's position is explicit: AI governance sits within existing obligations under Consumer Duty, SMCR, and SYSC 8, not a future framework still to be written (FCA AI Update, April 2024). 75% of FCA-regulated firms are already using AI (Bank of England/FCA AI Survey, 2024).

Neither regulator is waiting for a formal AI-specific rulebook before asking the question. Both are asking it now, inside the rules they already enforce.

CattleGrid maps its controls to the specific obligation your sector's regulator names — not a generic compliance checklist.

Why did CattleGrid block my prompt?

You typed something into CattleGrid, picked a model from the dropdown (Claude, GPT, Gemini, whichever your organisation has enabled), and instead of the answer you expected, part of your message came back highlighted, replaced with a label like `[REDACTED: UK National Insurance Number]`. Or the whole thing didn't go through: a notice card told you the request was blocked, with a reference number.

Your first thought was probably not "how interesting, a data governance control." It was probably "am I in trouble" or "is someone watching what I type."

Neither. Here's the short version.

Every message you send in CattleGrid is checked against your organisation's rules before it's forwarded to the AI provider you selected: OpenAI, Anthropic, Google Gemini, or Mistral. If it finds something sensitive, such as client data, National Insurance numbers, bank details, or credentials, it blocks the request, redacts the sensitive part, or lets it through with a warning. This happens in the same second you hit send. The check itself is automatic — no person sits between you and the answer. What your organisation keeps afterwards is its own decision: some enable conversation history or compliance review, some don't, and your admin can tell you which applies here.

This isn't about not trusting you. It's the opposite — it's what lets your organisation hand you these tools in the first place, rather than blocking them outright like a lot of firms have. It's about not trusting the moment: the one where everyone is moving fast and a client's details end up somewhere they shouldn't. It happens to careful people constantly.

What actually happens behind that badge or notice card, and what it means for you day to day, is on the next page.