Govern your organisation's AI use from one place: see who uses which AI tool, check sensitive data before it leaves, and look back when you need to.
ClickNext AI Security Gateway is an AI security gateway for organisations, built by ClickNext (ClickNext Co., Ltd.), a Thai software company in Bangkok. It sits between employees and AI services: it shows AI use on 13 platforms through a browser extension, checks prompts against DLP rules before they are sent, warns or blocks them by a central policy that administrators set, and records every event in an audit log you can review later.
When people use AI every day, customer data, internal documents or keys inside code can end up in a chat by accident. An AI Security Gateway is the central point that lets an organisation see and manage this, while teams keep the tools they like.
An AI gateway usually means a central point that requests to AI models pass through, to manage API keys, model choice and cost. An AI security gateway adds security work on top: checking data before it leaves, deciding by policy, and keeping a trail to review. ClickNext AI Security Gateway does both, for AI used in the browser, such as ChatGPT, Claude and Gemini, and for models called through an API by your team's tools.
Observe → Detect → Decide → Audit
How it works: the same four steps every time
Every AI request through a connected channel goes through these four steps. Employees work as usual; administrators know what happened and can look back.
01 · Observe
See AI use in one view
The ClickNext AI Security Monitor browser extension sends usage events from 13 AI platforms to a central dashboard, so IT sees who uses which AI tool and through which channel. Tools that call models through the Gateway API are recorded at the gateway in the same view. Only connected channels are visible.
02 · Detect
Check sensitive data before it is sent
Before a prompt is sent, the extension checks it on the employee's machine against the same DLP rules administrators set centrally: personal data, Thai national ID numbers, credit card numbers, keys and secrets, company-confidential information and prompt-injection attempts. ID and card numbers are checksum validated, so ordinary numbers such as order IDs pass.
03 · Decide
Policy decides
Each rule has its own level: warn or block. One rule set applies to every machine from the centre. Administrators change levels, add rules and allowlist text the organisation accepts, all from the dashboard, without configuring each machine.
04 · Audit
Look back with context
Usage and detection events are recorded in time order. Each entry shows the user, time, platform and check result. Administrators search past events and export reports as CSV according to their role, to support investigations, governance work and internal audits.
WarnThe prompt is still sent, work is not interrupted, and the event is logged for administrators.
BlockThe prompt is not sent. The user sees a notice showing which word or phrase caused the block, and the event is logged for the security team.
API traffic: the browser extension stops block-level prompts before they are sent. Requests through the Gateway API, such as coding work with an API key, are checked against the same rules and logged for administrators, but they are not cut off, because code routinely contains words like password or KEY=.
Capabilities
Everything below exists in the product today. Administrators use it from the web dashboard.
DLP
DLP for AI use
Checks prompts before they reach an AI platform, with these default rules:
Personal data such as email addresses (warn)
Thai national ID numbers that pass the checksum and credit card numbers that pass Luhn (block)
Real API keys, passwords and tokens (block)
Prompt injection and company-confidential information in a sensitive context (block)
Administrators can add their own keyword or regex rules.
Policy
Central policy
Set whether each rule warns or blocks, and allowlist cases the organisation accepts. The same rules apply to the browser extension and to requests through the gateway. The allowlist never unblocks real values such as secret keys or national ID numbers.
Audit Log
Audit log and reports
Records AI usage events and check results in time order, searchable by role and exportable as CSV. Key administrator actions, such as exporting a report or changing permissions, are logged too.
RBAC
Role- and team-based access
Open dashboard menus per role and per team (RBAC). Employees see only their own usage; administrators see the whole organisation.
SSO
Secure sign-in
The ClickNext team signs in with SSO through Microsoft, Google or ClickNext. Customer accounts sign in with email and password.
AI Gateway
An AI gateway for team tools
Administrators can issue each user a ClickNext API key that works with OpenAI-compatible and Anthropic Messages APIs, so it works with tools such as Claude Code, Cursor, OpenCode and common SDKs. Keys reach models from several providers, such as OpenAI, Anthropic, Google Gemini and DeepSeek, as each key allows. Provider keys are stored encrypted at the gateway.
Cost
AI cost control
Every request through the gateway is metered in tokens and priced at the provider's rates. Administrators see cost per person and per key, and set token or spending quotas per key that reset monthly or weekly.
Policy page
A policy employees can read
The DLP policy page (in Thai) explains what passes, what gets a warning and what is blocked. Employees can acknowledge it and report a block they think is wrong.
AI platforms the extension supports (13)
The ClickNext AI Security Monitor extension for Google Chrome checks prompts before they are sent on these platforms.
ChatGPTchatgpt.com
Claudeclaude.ai
Geminigemini.google.com
Copilotcopilot.microsoft.com
DeepSeekchat.deepseek.com
Perplexityperplexity.ai
Grokgrok.com
Mistralchat.mistral.ai
Poepoe.com
HuggingFace Chathuggingface.co/chat
NotebookLMnotebooklm.google.com
Google AI Studioaistudio.google.com
Meta AImeta.ai
Counted from the platforms the current extension version (2.19.9) supports. Other tools connected through the Gateway API, such as the ClickNext Agent app, appear in the same overview.
Who it is for
IT and information security teams who want to see AI use across the organisation and set rules in one place instead of machine by machine
Governance and internal audit who need a trail of AI use with context
Software teams who use AI tools through an API and want central keys with quotas and cost reports
Leadership who want teams to use AI fully while the organisation still sees usage, and the cost of AI calls through the gateway per person
Detecting personal data before it leaves, deciding by policy and keeping an audit log help support PDPA compliance (Thailand's Personal Data Protection Act).
Frequently asked questions
What is an AI Security Gateway?
An AI Security Gateway sits between users and AI services. It shows how AI is used, checks sensitive data before it leaves, decides by the organisation's policy and records events for later review. ClickNext AI Security Gateway covers both AI used in the browser, through a browser extension, and models called through an API.
Is ClickNext AI Security Gateway made by a Thai company?
Yes. It is built by ClickNext (ClickNext Co., Ltd., บริษัท คลิกเน็กซ์ จำกัด), a Thai software company with its office in Ratchathewi, Bangkok. The dashboard is in Thai, and the product introduction page is available in Thai, English and Indonesian.
How is this different from letting employees use ChatGPT or Claude directly?
Employees keep using the same tools. What changes is that prompts are checked before they are sent: a prompt with block-level data, such as a real key or a valid national ID number, is stopped before it leaves the machine, and IT sees an overview of AI use with a record to look back on, without having to ask each person.
What does it detect, and what gets blocked?
The default rules cover personal data, Thai national ID numbers, credit card numbers, keys and secrets, company-confidential information and prompt injection. Email addresses get a warning. National ID numbers that pass the checksum, card numbers that pass Luhn, real keys or secrets, prompt injection and company-confidential information in a sensitive context are blocked. A word like password with no real value after it is not blocked. Administrators can change levels and add rules.
What if a normal prompt is blocked by mistake?
Employees can report it on the DLP policy page at clicknexttest.biz/DLP.html. Administrators review it and can adjust the rule or allowlist that text. The allowlist never unblocks real values such as secret keys, national ID numbers or prompt injection.
Which AI platforms are supported?
The current browser extension supports 13 platforms: ChatGPT, Claude, Gemini, Copilot, DeepSeek, Perplexity, Grok, Mistral, Poe, HuggingFace Chat, NotebookLM, Google AI Studio and Meta AI. Tools or apps that call models through the Gateway API appear in the same overview.
Can we connect coding tools or internal apps through an API?
Yes. ClickNext API keys work with OpenAI-compatible and Anthropic Messages APIs, so they work with tools such as Claude Code, Cursor, OpenCode and common SDKs. Every request is checked against the DLP rules and logged, with tokens and cost counted per key. On the API channel the check result is logged for administrators, but the request is not cut off.
How does it help with the PDPA?
Detecting personal data before it leaves, deciding by policy and keeping an audit log help support PDPA compliance. The system is not a legal certification; the organisation still needs its own personal-data policies and processes.
Who can see what?
Access depends on role and team. Employees see only their own usage, administrators see the whole organisation, and key administrator actions, such as exporting a report or changing permissions, are logged. What the extension collects is described in the privacy policy at clicknexttest.biz/privacy.
How can we control AI costs?
Every request that calls a model through the gateway is metered in tokens and priced at the provider's rates. Administrators see cost per person and per key, and set token or spending quotas per key that reset monthly or weekly.
How do we roll it out?
Employees use the ClickNext AI Security Monitor extension in Google Chrome and administrators use the web dashboard. IT can point the extension at the organisation's gateway through Chrome policy (managed policy). For rollout details for your organisation, contact ClickNext through www.clicknext.com.
Start seeing and governing your organisation's AI use
Administrators sign in to see the overview and manage what their role allows. Employees can read the DLP policy without signing in.