ENTERPRISEPlan ENTERPRISE

Endpoint Protection

Protection des postes de travail et navigateurs contre les interactions non-autorisees avec les outils IA.

Fonctionnalites Cles

Browser Extension

Extension Chrome/Edge/Firefox pour controler l'acces aux outils IA.

MDM Intégration

Déploiement centralise via Intune, JAMF, ou autre MDM.

DNS Filtering

Blocage au niveau DNS des domaines IA non-approuves.

Policy Engine

Règles granulaires par utilisateur, groupe, ou departement.

Extension Navigateur

L'extension Adlibo protégé les utilisateurs contre l'utilisation non-autorisée d'outils IA et previent les fuites de données.

Chrome
Disponible
Edge
Disponible
Firefox
Beta

Fonctionnalites

Blocage des sites IA non-approuves (ChatGPT, Claude, Gemini, etc.)
Détection du copy/paste de données sensibles
Avertissement avant soumission de données confidentielles
Logging des interactions pour audit
Mode "Approved Only" ou "Block List"
Intégration DLP temps reel

Configuration des Politiques

json
// POST /api/saas/endpoint/policies
{
  "name": "Default AI Policy",
  "scope": {
    "type": "organization",  // organization, group, user
    "targets": ["org_abc123"]
  },
  "rules": {
    "aiServices": {
      "mode": "allowlist",  // allowlist, blocklist
      "allowed": [
        {
          "domain": "chat.openai.com",
          "name": "ChatGPT Enterprise",
          "conditions": {
            "requireDlp": true,
            "maxInputLength": 5000
          }
        },
        {
          "domain": "claude.ai",
          "name": "Claude for Work",
          "conditions": {
            "requireDlp": true,
            "allowedDomains": ["PERSONAL", "CORPORATE"]
          }
        }
      ],
      "blocked": [
        { "domain": "*.openai.com", "except": ["chat.openai.com"] },
        { "domain": "bard.google.com" },
        { "domain": "perplexity.ai" }
      ]
    },
    "dataProtection": {
      "blockCopyPaste": {
        "enabled": true,
        "patterns": ["CREDIT_CARD", "SSN", "API_KEY", "PASSWORD"]
      },
      "warnBeforeSubmit": {
        "enabled": true,
        "threshold": 50  // Risk score threshold
      },
      "preventScreenshot": false
    },
    "logging": {
      "logAllInteractions": true,
      "logBlockedAttempts": true,
      "retentionDays": 90
    }
  },
  "enforcement": "block",  // block, warn, log
  "enabled": true
}

Déploiement MDM

Microsoft Intune

powershell
# PowerShell - Déploiement via Intune
$extensionId = "adlibo-endpoint-protection"
$policyId = "pol_abc123"

# Configuration Chrome
$chromeConfig = @{
  "ExtensionSettings" = @{
    $extensionId = @{
      "installation_mode" = "force_installed"
      "update_url" = "https://www.adlibo.com/extension/chrome/updates.xml"
    }
  }
}

# Configuration Edge
$edgeConfig = @{
  "ExtensionSettings" = @{
    $extensionId = @{
      "installation_mode" = "force_installed"
      "update_url" = "https://www.adlibo.com/extension/edge/updates.xml"
    }
  }
}

JAMF (macOS)

xml
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN">
<plist version="1.0">
<dict>
  <key>PayloadContent</key>
  <array>
    <dict>
      <key>ExtensionInstallForcelist</key>
      <array>
        <string>adlibo-endpoint;https://www.adlibo.com/extension/chrome/updates.xml</string>
      </array>
      <key>PayloadType</key>
      <string>com.google.Chrome</string>
    </dict>
  </array>
</dict>
</plist>

Group Policy (GPO)

text
# Registry keys pour Chrome
HKLM\SOFTWARE\Policies\Google\Chrome\ExtensionInstallForcelist
Value: "adlibo-endpoint;https://www.adlibo.com/extension/chrome/updates.xml"

# Registry keys pour Edge
HKLM\SOFTWARE\Policies\Microsoft\Edge\ExtensionInstallForcelist
Value: "adlibo-endpoint;https://www.adlibo.com/extension/edge/updates.xml"

DNS Filtering

Bloquez l'acces aux services IA au niveau DNS pour tous les appareils du réseau, y compris les appareils non-geres.

json
// POST /api/saas/endpoint/dns-config
{
  "enabled": true,
  "mode": "blocklist",
  "blockedDomains": [
    // OpenAI
    "chat.openai.com",
    "api.openai.com",
    "platform.openai.com",

    // Anthropic
    "claude.ai",
    "api.anthropic.com",

    // Google
    "bard.google.com",
    "gemini.google.com",

    // Other AI services
    "perplexity.ai",
    "you.com",
    "poe.com",
    "character.ai",
    "midjourney.com",
    "stability.ai"
  ],
  "allowedDomains": [
    // Exceptions pour services approuves
    "chat.openai.com"  // Si ChatGPT Enterprise approuve
  ],
  "blockPage": {
    "enabled": true,
    "message": "Cet outil IA n'est pas approuve. Contactez IT pour plus d'informations.",
    "contactEmail": "it@company.com"
  },
  "intégration": {
    "type": "dns_forwarder",  // dns_forwarder, proxy, firewall
    "forwarders": ["10.0.0.53", "10.0.0.54"]
  }
}

Note importante

Le DNS filtering ne détecté pas l'utilisation d'API directement intégrées dans des applications. Combinez avec l'extension navigateur et le DLP pour une protection complete.

Dashboard de Monitoring

Suivez l'utilisation des outils IA et les tentatives bloquees depuis le dashboard Enterprise.

342
Extensions Active
1,247
AI Interactions Today
89
Blocked Attempts
23
DLP Warnings
json
// GET /api/saas/endpoint/stats
{
  "period": "24h",
  "endpoints": {
    "total": 342,
    "active": 298,
    "offline": 44
  },
  "interactions": {
    "total": 1247,
    "byService": {
      "chat.openai.com": 845,
      "claude.ai": 312,
      "gemini.google.com": 90
    }
  },
  "blocked": {
    "total": 89,
    "byReason": {
      "unapproved_service": 52,
      "dlp_violation": 23,
      "policy_violation": 14
    }
  },
  "topUsers": [
    { "userId": "usr_123", "interactions": 145, "blocked": 3 },
    { "userId": "usr_456", "interactions": 98, "blocked": 0 }
  ]
}

Catalogue des Services IA (70+ services)

Liste complete des services IA detectes par Adlibo Endpoint Shield avec leur statut de conformite, localisation des données et niveau de risque. Mise a jour en continu.

TousLLM ChatCode AssistantImage GenVideo GenAudio/VoiceSearchWritingEnterprise
ServiceDomainesCategorieData ResidencyGDPRStatut
ChatGPT Enterprisechat.openai.com, chatgpt.comLLM ChatUS/EUApproved
ChatGPT Pluschat.openai.com, chatgpt.comLLM ChatUSReview
ChatGPT Freechat.openai.com, chatgpt.comLLM ChatUSBlocked
Claude for Workclaude.ai, api.anthropic.comLLM ChatUSApproved
Claude Proclaude.aiLLM ChatUSReview
Claude Freeclaude.aiLLM ChatUSBlocked
Google Gemini Advancedgemini.google.com, aistudio.google.comLLM ChatUS/EUReview
Google Gemini Freegemini.google.com, bard.google.comLLM ChatUSBlocked
Microsoft Copilot Enterprisecopilot.microsoft.com, copilot.cloud.microsoftLLM ChatUS/EUApproved
Microsoft Copilot Freecopilot.microsoft.com, bing.com/chatLLM ChatUSBlocked
Meta AImeta.ai, ai.meta.comLLM ChatUSBlocked
Mistral Le Chatchat.mistral.ai, mistral.aiLLM ChatFR/EUReview
Coherecohere.com, dashboard.cohere.comLLM ChatUS/CAReview
Perplexity Properplexity.aiSearchUSReview
Perplexity Freeperplexity.aiSearchUSBlocked
You.comyou.comSearchUSBlocked
Poepoe.comLLM ChatUSBlocked
Character.AIcharacter.ai, beta.character.aiLLM ChatUSBlocked
Pipi.ai, heypi.comLLM ChatUSBlocked
Groqgroq.com, console.groq.comLLM ChatUSReview
Together AItogether.ai, api.together.xyzLLM ChatUSReview
Replicatereplicate.comLLM ChatUSReview
Hugging Face Chathuggingface.co/chatLLM ChatUSReview
DeepSeekdeepseek.com, chat.deepseek.comLLM ChatCNBlocked
Qwen (Alibaba)qwenlm.ai, tongyi.aliyun.comLLM ChatCNBlocked
Baidu Ernieyiyan.baidu.comLLM ChatCNBlocked
Moonshot (Kimi)kimi.moonshot.cn, moonshot.cnLLM ChatCNBlocked
Zhipu AIchatglm.cn, open.bigmodel.cnLLM ChatCNBlocked
GitHub Copilot Businesscopilot.github.com, github.com/features/copilotCode AssistantUSApproved
GitHub Copilot Individualcopilot.github.comCode AssistantUSReview
Amazon CodeWhispereraws.amazon.com/codewhispererCode AssistantUSApproved
Cursorcursor.sh, cursor.comCode AssistantUSReview
Codeiumcodeium.comCode AssistantUSReview
Tabninetabnine.comCode AssistantUS/ILReview
Sourcegraph Codysourcegraph.comCode AssistantUSReview
Replit AIreplit.comCode AssistantUSBlocked
Windsurfwindsurf.ai, codeium.com/windsurfCode AssistantUSReview
DALL-E 3 (API)api.openai.comImage GenUSReview
Midjourneymidjourney.com, discord.com/midjourneyImage GenUSBlocked
Stable Diffusion (Stability)stability.ai, dreamstudio.aiImage GenUKReview
Leonardo.AIleonardo.ai, app.leonardo.aiImage GenAUBlocked
Adobe Fireflyfirefly.adobe.comImage GenUSApproved
Canva AIcanva.comImage GenAUReview
Ideogramideogram.aiImage GenUSBlocked
Flux (Black Forest)blackforestlabs.aiImage GenDEReview
Craiyoncraiyon.comImage GenUSBlocked
Runwayrunwayml.com, app.runwayml.comVideo GenUSBlocked
Pika Labspika.artVideo GenUSBlocked
Sora (OpenAI)openai.com/soraVideo GenUSBlocked
Synthesiasynthesia.ioVideo GenUK/EUReview
HeyGenheygen.comVideo GenUSBlocked
D-IDd-id.comVideo GenILReview
Luma AIlumalabs.aiVideo GenUSBlocked
ElevenLabselevenlabs.ioAudio/VoiceUSBlocked
Murf.AImurf.aiAudio/VoiceUSReview
Descriptdescript.comAudio/VoiceUSReview
Otter.aiotter.aiAudio/VoiceUSReview
Assembly AIassemblyai.comAudio/VoiceUSReview
Speechifyspeechify.comAudio/VoiceUSBlocked
Play.htplay.htAudio/VoiceUSBlocked
Suno AIsuno.ai, app.suno.aiAudio/VoiceUSBlocked
Udioudio.comAudio/VoiceUSBlocked
Jasperjasper.aiWritingUSReview
Copy.aicopy.aiWritingUSBlocked
Writesonicwritesonic.comWritingUSBlocked
Grammarly AIgrammarly.comWritingUSReview
QuillBotquillbot.comWritingUSBlocked
Notion AInotion.soWritingUSReview
Mem AImem.aiWritingUSBlocked
AWS Bedrockaws.amazon.com/bedrockEnterpriseMultiApproved
Azure OpenAIazure.microsoft.com, oai.azure.comEnterpriseMultiApproved
Google Vertex AIcloud.google.com/vertex-aiEnterpriseMultiApproved
IBM Watsonibm.com/watsonEnterpriseMultiApproved
Salesforce Einsteineinstein.ai, salesforce.com/einsteinEnterpriseUS/EUApproved

Legende des statuts

ApprovedService valide pour usage professionnel
ReviewEn cours d'évaluation
BlockedNon conforme, acces bloqué

API Référence

Endpoints disponibles pour l'intégration Endpoint Shield. Authentification via device token ou API key.

POST
/api/v1/endpoint/register

Enregistrement d'un nouvel appareil

POST
/api/v1/endpoint/enroll

Enrollment via lien d'inscription

POST
/api/v1/endpoint/bind-user

Association utilisateur ↔ appareil

POST
/api/v1/endpoint/heartbeat

Heartbeat + envoi statistiques

GET
/api/v1/endpoint/config

Récupération politiques DLP et config

POST
/api/v1/endpoint/alert

Signalement alerte DLP

POST
/api/v1/endpoint/log

Envoi logs d'activité

POST
/api/v1/endpoint/license/validate

Validation clé de licence

Dashboard APIs (requérant session auth)

GET /api/dashboard/endpoint — Stats, appareils, licences

GET/POST/PATCH /api/dashboard/endpoint/policies — Gestion des politiques DLP

GET/POST /api/dashboard/endpoint/enrollment — Liens d'enrollment

GET/POST /api/dashboard/endpoint/settings — Paramètres organisation

Documentation Associee

Besoin d'aide avec le déploiement Endpoint ?

Notre équipe peut vous accompagner dans le déploiement et la configuration des politiques.