ENTERPRISEPlan ENTERPRISE

Endpoint Protection

Protection des postes de travail et navigateurs contre les interactions non-autorisees avec les outils IA.

Fonctionnalites Cles

Browser Extension

Extension Chrome/Edge/Firefox pour controler l'acces aux outils IA.

MDM Integration

Deploiement centralise via Intune, JAMF, ou autre MDM.

DNS Filtering

Blocage au niveau DNS des domaines IA non-approuves.

Policy Engine

Regles granulaires par utilisateur, groupe, ou departement.

Extension Navigateur

L'extension Adlibo protege les utilisateurs contre l'utilisation non-autorisee d'outils IA et previent les fuites de donnees.

Chrome
Disponible
Edge
Disponible
Firefox
Beta

Fonctionnalites

Blocage des sites IA non-approuves (ChatGPT, Claude, Gemini, etc.)
Detection du copy/paste de donnees sensibles
Avertissement avant soumission de donnees confidentielles
Logging des interactions pour audit
Mode "Approved Only" ou "Block List"
Integration DLP temps reel

Configuration des Politiques

json
// POST /api/saas/endpoint/policies
{
  "name": "Default AI Policy",
  "scope": {
    "type": "organization",  // organization, group, user
    "targets": ["org_abc123"]
  },
  "rules": {
    "aiServices": {
      "mode": "allowlist",  // allowlist, blocklist
      "allowed": [
        {
          "domain": "chat.openai.com",
          "name": "ChatGPT Enterprise",
          "conditions": {
            "requireDlp": true,
            "maxInputLength": 5000
          }
        },
        {
          "domain": "claude.ai",
          "name": "Claude for Work",
          "conditions": {
            "requireDlp": true,
            "allowedDomains": ["PERSONAL", "CORPORATE"]
          }
        }
      ],
      "blocked": [
        { "domain": "*.openai.com", "except": ["chat.openai.com"] },
        { "domain": "bard.google.com" },
        { "domain": "perplexity.ai" }
      ]
    },
    "dataProtection": {
      "blockCopyPaste": {
        "enabled": true,
        "patterns": ["CREDIT_CARD", "SSN", "API_KEY", "PASSWORD"]
      },
      "warnBeforeSubmit": {
        "enabled": true,
        "threshold": 50  // Risk score threshold
      },
      "preventScreenshot": false
    },
    "logging": {
      "logAllInteractions": true,
      "logBlockedAttempts": true,
      "retentionDays": 90
    }
  },
  "enforcement": "block",  // block, warn, log
  "enabled": true
}

Deploiement MDM

Microsoft Intune

powershell
# PowerShell - Deploiement via Intune
$extensionId = "adlibo-endpoint-protection"
$policyId = "pol_abc123"

# Configuration Chrome
$chromeConfig = @{
  "ExtensionSettings" = @{
    $extensionId = @{
      "installation_mode" = "force_installed"
      "update_url" = "https://www.adlibo.com/extension/chrome/updates.xml"
    }
  }
}

# Configuration Edge
$edgeConfig = @{
  "ExtensionSettings" = @{
    $extensionId = @{
      "installation_mode" = "force_installed"
      "update_url" = "https://www.adlibo.com/extension/edge/updates.xml"
    }
  }
}

JAMF (macOS)

xml
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN">
<plist version="1.0">
<dict>
  <key>PayloadContent</key>
  <array>
    <dict>
      <key>ExtensionInstallForcelist</key>
      <array>
        <string>adlibo-endpoint;https://www.adlibo.com/extension/chrome/updates.xml</string>
      </array>
      <key>PayloadType</key>
      <string>com.google.Chrome</string>
    </dict>
  </array>
</dict>
</plist>

Group Policy (GPO)

text
# Registry keys pour Chrome
HKLM\SOFTWARE\Policies\Google\Chrome\ExtensionInstallForcelist
Value: "adlibo-endpoint;https://www.adlibo.com/extension/chrome/updates.xml"

# Registry keys pour Edge
HKLM\SOFTWARE\Policies\Microsoft\Edge\ExtensionInstallForcelist
Value: "adlibo-endpoint;https://www.adlibo.com/extension/edge/updates.xml"

DNS Filtering

Bloquez l'acces aux services IA au niveau DNS pour tous les appareils du reseau, y compris les appareils non-geres.

json
// POST /api/saas/endpoint/dns-config
{
  "enabled": true,
  "mode": "blocklist",
  "blockedDomains": [
    // OpenAI
    "chat.openai.com",
    "api.openai.com",
    "platform.openai.com",

    // Anthropic
    "claude.ai",
    "api.anthropic.com",

    // Google
    "bard.google.com",
    "gemini.google.com",

    // Other AI services
    "perplexity.ai",
    "you.com",
    "poe.com",
    "character.ai",
    "midjourney.com",
    "stability.ai"
  ],
  "allowedDomains": [
    // Exceptions pour services approuves
    "chat.openai.com"  // Si ChatGPT Enterprise approuve
  ],
  "blockPage": {
    "enabled": true,
    "message": "Cet outil IA n'est pas approuve. Contactez IT pour plus d'informations.",
    "contactEmail": "it@company.com"
  },
  "integration": {
    "type": "dns_forwarder",  // dns_forwarder, proxy, firewall
    "forwarders": ["10.0.0.53", "10.0.0.54"]
  }
}

Note importante

Le DNS filtering ne detecte pas l'utilisation d'API directement integrees dans des applications. Combinez avec l'extension navigateur et le DLP pour une protection complete.

Dashboard de Monitoring

Suivez l'utilisation des outils IA et les tentatives bloquees depuis le dashboard Enterprise.

342
Extensions Active
1,247
AI Interactions Today
89
Blocked Attempts
23
DLP Warnings
json
// GET /api/saas/endpoint/stats
{
  "period": "24h",
  "endpoints": {
    "total": 342,
    "active": 298,
    "offline": 44
  },
  "interactions": {
    "total": 1247,
    "byService": {
      "chat.openai.com": 845,
      "claude.ai": 312,
      "gemini.google.com": 90
    }
  },
  "blocked": {
    "total": 89,
    "byReason": {
      "unapproved_service": 52,
      "dlp_violation": 23,
      "policy_violation": 14
    }
  },
  "topUsers": [
    { "userId": "usr_123", "interactions": 145, "blocked": 3 },
    { "userId": "usr_456", "interactions": 98, "blocked": 0 }
  ]
}

Catalogue des Services IA (70+ services)

Liste complete des services IA detectes par Adlibo Endpoint Shield avec leur statut de conformite, localisation des donnees et niveau de risque. Mise a jour en continu.

TousLLM ChatCode AssistantImage GenVideo GenAudio/VoiceSearchWritingEnterprise
ServiceDomainesCategorieData ResidencyGDPRStatut
ChatGPT Enterprisechat.openai.com, chatgpt.comLLM ChatUS/EUApproved
ChatGPT Pluschat.openai.com, chatgpt.comLLM ChatUSReview
ChatGPT Freechat.openai.com, chatgpt.comLLM ChatUSBlocked
Claude for Workclaude.ai, api.anthropic.comLLM ChatUSApproved
Claude Proclaude.aiLLM ChatUSReview
Claude Freeclaude.aiLLM ChatUSBlocked
Google Gemini Advancedgemini.google.com, aistudio.google.comLLM ChatUS/EUReview
Google Gemini Freegemini.google.com, bard.google.comLLM ChatUSBlocked
Microsoft Copilot Enterprisecopilot.microsoft.com, copilot.cloud.microsoftLLM ChatUS/EUApproved
Microsoft Copilot Freecopilot.microsoft.com, bing.com/chatLLM ChatUSBlocked
Meta AImeta.ai, ai.meta.comLLM ChatUSBlocked
Mistral Le Chatchat.mistral.ai, mistral.aiLLM ChatFR/EUReview
Coherecohere.com, dashboard.cohere.comLLM ChatUS/CAReview
Perplexity Properplexity.aiSearchUSReview
Perplexity Freeperplexity.aiSearchUSBlocked
You.comyou.comSearchUSBlocked
Poepoe.comLLM ChatUSBlocked
Character.AIcharacter.ai, beta.character.aiLLM ChatUSBlocked
Pipi.ai, heypi.comLLM ChatUSBlocked
Groqgroq.com, console.groq.comLLM ChatUSReview
Together AItogether.ai, api.together.xyzLLM ChatUSReview
Replicatereplicate.comLLM ChatUSReview
Hugging Face Chathuggingface.co/chatLLM ChatUSReview
DeepSeekdeepseek.com, chat.deepseek.comLLM ChatCNBlocked
Qwen (Alibaba)qwenlm.ai, tongyi.aliyun.comLLM ChatCNBlocked
Baidu Ernieyiyan.baidu.comLLM ChatCNBlocked
Moonshot (Kimi)kimi.moonshot.cn, moonshot.cnLLM ChatCNBlocked
Zhipu AIchatglm.cn, open.bigmodel.cnLLM ChatCNBlocked
GitHub Copilot Businesscopilot.github.com, github.com/features/copilotCode AssistantUSApproved
GitHub Copilot Individualcopilot.github.comCode AssistantUSReview
Amazon CodeWhispereraws.amazon.com/codewhispererCode AssistantUSApproved
Cursorcursor.sh, cursor.comCode AssistantUSReview
Codeiumcodeium.comCode AssistantUSReview
Tabninetabnine.comCode AssistantUS/ILReview
Sourcegraph Codysourcegraph.comCode AssistantUSReview
Replit AIreplit.comCode AssistantUSBlocked
Windsurfwindsurf.ai, codeium.com/windsurfCode AssistantUSReview
DALL-E 3 (API)api.openai.comImage GenUSReview
Midjourneymidjourney.com, discord.com/midjourneyImage GenUSBlocked
Stable Diffusion (Stability)stability.ai, dreamstudio.aiImage GenUKReview
Leonardo.AIleonardo.ai, app.leonardo.aiImage GenAUBlocked
Adobe Fireflyfirefly.adobe.comImage GenUSApproved
Canva AIcanva.comImage GenAUReview
Ideogramideogram.aiImage GenUSBlocked
Flux (Black Forest)blackforestlabs.aiImage GenDEReview
Craiyoncraiyon.comImage GenUSBlocked
Runwayrunwayml.com, app.runwayml.comVideo GenUSBlocked
Pika Labspika.artVideo GenUSBlocked
Sora (OpenAI)openai.com/soraVideo GenUSBlocked
Synthesiasynthesia.ioVideo GenUK/EUReview
HeyGenheygen.comVideo GenUSBlocked
D-IDd-id.comVideo GenILReview
Luma AIlumalabs.aiVideo GenUSBlocked
ElevenLabselevenlabs.ioAudio/VoiceUSBlocked
Murf.AImurf.aiAudio/VoiceUSReview
Descriptdescript.comAudio/VoiceUSReview
Otter.aiotter.aiAudio/VoiceUSReview
Assembly AIassemblyai.comAudio/VoiceUSReview
Speechifyspeechify.comAudio/VoiceUSBlocked
Play.htplay.htAudio/VoiceUSBlocked
Suno AIsuno.ai, app.suno.aiAudio/VoiceUSBlocked
Udioudio.comAudio/VoiceUSBlocked
Jasperjasper.aiWritingUSReview
Copy.aicopy.aiWritingUSBlocked
Writesonicwritesonic.comWritingUSBlocked
Grammarly AIgrammarly.comWritingUSReview
QuillBotquillbot.comWritingUSBlocked
Notion AInotion.soWritingUSReview
Mem AImem.aiWritingUSBlocked
AWS Bedrockaws.amazon.com/bedrockEnterpriseMultiApproved
Azure OpenAIazure.microsoft.com, oai.azure.comEnterpriseMultiApproved
Google Vertex AIcloud.google.com/vertex-aiEnterpriseMultiApproved
IBM Watsonibm.com/watsonEnterpriseMultiApproved
Salesforce Einsteineinstein.ai, salesforce.com/einsteinEnterpriseUS/EUApproved

Legende des statuts

ApprovedService valide pour usage professionnel
ReviewEn cours d'evaluation
BlockedNon conforme, acces bloque

API Reference

Endpoints disponibles pour l'intégration Endpoint Shield. Authentification via device token ou API key.

POST
/api/v1/endpoint/register

Enregistrement d'un nouvel appareil

POST
/api/v1/endpoint/enroll

Enrollment via lien d'inscription

POST
/api/v1/endpoint/bind-user

Association utilisateur ↔ appareil

POST
/api/v1/endpoint/heartbeat

Heartbeat + envoi statistiques

GET
/api/v1/endpoint/config

Récupération politiques DLP et config

POST
/api/v1/endpoint/alert

Signalement alerte DLP

POST
/api/v1/endpoint/log

Envoi logs d'activité

POST
/api/v1/endpoint/license/validate

Validation clé de licence

Dashboard APIs (requérant session auth)

GET /api/dashboard/endpoint — Stats, appareils, licences

GET/POST/PATCH /api/dashboard/endpoint/policies — Gestion des politiques DLP

GET/POST /api/dashboard/endpoint/enrollment — Liens d'enrollment

GET/POST /api/dashboard/endpoint/settings — Paramètres organisation

Documentation Associee

Besoin d'aide avec le deploiement Endpoint ?

Notre equipe peut vous accompagner dans le deploiement et la configuration des politiques.