Back to Blog
Tai Tran 4 min read

Enterprise Security with Privacy by Design: Introducing Privacy Mode

Enterprise Security with Privacy by Design: Introducing Privacy Mode

Now in Preview

Security teams need visibility into AI agents. Employees need confidence that security tooling is not quietly becoming workplace surveillance. Those requirements should reinforce each other, not compete.

That belief has shaped Certiv from the beginning. Scout observes AI agents and agentic activity, not everything a person does on their workstation. It does not monitor browser history, record keystrokes, or indiscriminately inspect documents. If an AI agent is not involved, Certiv is not looking.

Privacy Mode takes that principle one step further: even within agent activity, routine, policy-compliant work stays private by default.

The Certiv session detail view with Privacy Mode enabled: logs are hidden behind a prompt that asks for a reason before the session can be opened

A smoke alarm, not a camera

A smoke alarm is trusted because its purpose is narrow and clear. It is always present, but it does not record ordinary life. It watches for a specific signal and alerts when that signal appears.

Security software on an employee’s workstation should work the same way.

This matters especially for AI. Employees are already asking whether their prompts are being read, whether new tools will automate their jobs, and whether systems introduced for security will eventually be used to monitor performance.

Privacy Mode gives organizations a clearer answer: Certiv is there to identify and stop meaningful agent risk, not to invite casual review of ordinary work.

See the risk, not every routine session

Privacy Mode changes the default from broad visibility to purposeful access.

When an agent session triggers a policy violation, the security team receives full visibility into that session automatically. There is no extra step and no delay. The violation is the signal that warrants investigation.

When a session has no policy violations, it remains private by default. An authorized governance team member can still access it when there is a legitimate need, but doing so requires an explicit justification. Certiv records who accessed the session and why.

In practice, that means:

  • Sessions with policy violations are immediately visible to security teams.
  • Compliant sessions are not open to routine browsing.
  • Exceptional access remains possible, but it is deliberate and auditable.
  • Employees can use sanctioned AI agents without assuming that every prompt or workflow is being reviewed.

Privacy Mode does not remove visibility. It makes visibility proportional to risk.

Privacy is part of adoption

Deploying AI safely involves more than solving technical problems.

Certiv reduces technical friction by operating at the endpoint, without requiring network proxies, application SDKs, or per-agent configuration. But AI programs also face organizational friction: privacy reviews, works council concerns, and employees who avoid sanctioned tools because they feel watched.

Those concerns have direct security consequences. If people do not trust approved AI tools, they find alternatives. Usage moves into the shadows, where governance and enforcement are weaker.

Over-surveillance also chills experimentation. When employees believe every prompt may be read, they use AI less, take fewer productive risks, and limit themselves to low-value tasks. Governance should help an organization get more value from AI safely, not make people afraid to use it.

With Privacy Mode, security leaders can make a credible, enforceable commitment: we observe agents, not people; and within agent activity, we surface policy violations, not routine work.

Because access to compliant sessions requires a recorded justification, that commitment is more than cultural. It is auditable. Organizations can demonstrate to employees, privacy teams, and works councils that oversight is accountable and proportionate.

Runtime protection stays on

Privacy Mode works with Certiv’s Policy Engine.

Scout observes agent activity at the endpoint. The Policy Engine evaluates that activity against organizational policy before actions execute. Privacy Mode then uses those verdicts to determine session visibility:

  • Policy violation: the session is visible to the security team.
  • No policy violation: the session remains private unless an authorized user records a reason to access it.

Nothing about runtime enforcement changes. Block, Pause, and Steer interventions continue to operate in real time. Privacy Mode governs who can review a session after the fact; it does not weaken the protections applied while the agent is working.

Available now in Preview

Privacy Mode entered Preview in July and is available to Certiv customers today. If you are running a proof of value with us, ask your Certiv team to enable it. If you are not yet a customer, book a demo to see how it works.

Preview is also a chance to learn. We want to know whether Privacy Mode changes the conversation with your employees, privacy office, and works council. That feedback will help shape what comes next.

Certiv began with a narrow promise: observe agents, not people. Privacy Mode makes that promise stronger by ensuring that routine agent work remains routine while security teams see what matters when it matters.