ClickNextAI Security Gateway Sign in

Home / AI Security Gateway

AI Security Gateway · Built by a Thai company

ClickNext AI Security Gateway

Govern your organisation's AI use from one place: see who uses which AI tool, check sensitive data before it leaves, and look back when you need to.

ClickNext AI Security Gateway is an AI security gateway for organisations, built by ClickNext (ClickNext Co., Ltd.), a Thai software company in Bangkok. It sits between employees and AI services: it shows AI use on 13 platforms through a browser extension, checks prompts against DLP rules before they are sent, warns or blocks them by a central policy that administrators set, and records every event in an audit log you can review later.

Developer
ClickNext (ClickNext Co., Ltd.), Bangkok, Thailand
Coverage
13 AI platforms through a browser extension, plus tools connected through the Gateway API
Outcome per DLP rule
Warn or block, as administrators set, with an allowlist
Sign-in
SSO with Microsoft, Google or ClickNext for the ClickNext team; email and password for customer accounts

Updated

What an AI Security Gateway does

When people use AI every day, customer data, internal documents or keys inside code can end up in a chat by accident. An AI Security Gateway is the central point that lets an organisation see and manage this, while teams keep the tools they like.

An AI gateway usually means a central point that requests to AI models pass through, to manage API keys, model choice and cost. An AI security gateway adds security work on top: checking data before it leaves, deciding by policy, and keeping a trail to review. ClickNext AI Security Gateway does both, for AI used in the browser, such as ChatGPT, Claude and Gemini, and for models called through an API by your team's tools.

Observe → Detect → Decide → Audit

How it works: the same four steps every time

Every AI request through a connected channel goes through these four steps. Employees work as usual; administrators know what happened and can look back.

  1. 01 · Observe

    See AI use in one view

    The ClickNext AI Security Monitor browser extension sends usage events from 13 AI platforms to a central dashboard, so IT sees who uses which AI tool and through which channel. Tools that call models through the Gateway API are recorded at the gateway in the same view. Only connected channels are visible.

  2. 02 · Detect

    Check sensitive data before it is sent

    Before a prompt is sent, the extension checks it on the employee's machine against the same DLP rules administrators set centrally: personal data, Thai national ID numbers, credit card numbers, keys and secrets, company-confidential information and prompt-injection attempts. ID and card numbers are checksum validated, so ordinary numbers such as order IDs pass.

  3. 03 · Decide

    Policy decides

    Each rule has its own level: warn or block. One rule set applies to every machine from the centre. Administrators change levels, add rules and allowlist text the organisation accepts, all from the dashboard, without configuring each machine.

  4. 04 · Audit

    Look back with context

    Usage and detection events are recorded in time order. Each entry shows the user, time, platform and check result. Administrators search past events and export reports as CSV according to their role, to support investigations, governance work and internal audits.

WarnThe prompt is still sent, work is not interrupted, and the event is logged for administrators.

BlockThe prompt is not sent. The user sees a notice showing which word or phrase caused the block, and the event is logged for the security team.

API traffic: the browser extension stops block-level prompts before they are sent. Requests through the Gateway API, such as coding work with an API key, are checked against the same rules and logged for administrators, but they are not cut off, because code routinely contains words like password or KEY=.

Capabilities

Everything below exists in the product today. Administrators use it from the web dashboard.

DLP

DLP for AI use

Checks prompts before they reach an AI platform, with these default rules:

  • Personal data such as email addresses (warn)
  • Thai national ID numbers that pass the checksum and credit card numbers that pass Luhn (block)
  • Real API keys, passwords and tokens (block)
  • Prompt injection and company-confidential information in a sensitive context (block)

Administrators can add their own keyword or regex rules.

Policy

Central policy

Set whether each rule warns or blocks, and allowlist cases the organisation accepts. The same rules apply to the browser extension and to requests through the gateway. The allowlist never unblocks real values such as secret keys or national ID numbers.

Audit Log

Audit log and reports

Records AI usage events and check results in time order, searchable by role and exportable as CSV. Key administrator actions, such as exporting a report or changing permissions, are logged too.

RBAC

Role- and team-based access

Open dashboard menus per role and per team (RBAC). Employees see only their own usage; administrators see the whole organisation.

SSO

Secure sign-in

The ClickNext team signs in with SSO through Microsoft, Google or ClickNext. Customer accounts sign in with email and password.

AI Gateway

An AI gateway for team tools

Administrators can issue each user a ClickNext API key that works with OpenAI-compatible and Anthropic Messages APIs, so it works with tools such as Claude Code, Cursor, OpenCode and common SDKs. Keys reach models from several providers, such as OpenAI, Anthropic, Google Gemini and DeepSeek, as each key allows. Provider keys are stored encrypted at the gateway.

Cost

AI cost control

Every request through the gateway is metered in tokens and priced at the provider's rates. Administrators see cost per person and per key, and set token or spending quotas per key that reset monthly or weekly.

Policy page

A policy employees can read

The DLP policy page (in Thai) explains what passes, what gets a warning and what is blocked. Employees can acknowledge it and report a block they think is wrong.

AI platforms the extension supports (13)

The ClickNext AI Security Monitor extension for Google Chrome checks prompts before they are sent on these platforms.

  • ChatGPTchatgpt.com
  • Claudeclaude.ai
  • Geminigemini.google.com
  • Copilotcopilot.microsoft.com
  • DeepSeekchat.deepseek.com
  • Perplexityperplexity.ai
  • Grokgrok.com
  • Mistralchat.mistral.ai
  • Poepoe.com
  • HuggingFace Chathuggingface.co/chat
  • NotebookLMnotebooklm.google.com
  • Google AI Studioaistudio.google.com
  • Meta AImeta.ai

Counted from the platforms the current extension version (2.19.9) supports. Other tools connected through the Gateway API, such as the ClickNext Agent app, appear in the same overview.

Who it is for

  • IT and information security teams who want to see AI use across the organisation and set rules in one place instead of machine by machine
  • Governance and internal audit who need a trail of AI use with context
  • Software teams who use AI tools through an API and want central keys with quotas and cost reports
  • Leadership who want teams to use AI fully while the organisation still sees usage, and the cost of AI calls through the gateway per person

Detecting personal data before it leaves, deciding by policy and keeping an audit log help support PDPA compliance (Thailand's Personal Data Protection Act).

Frequently asked questions

What is an AI Security Gateway?

An AI Security Gateway sits between users and AI services. It shows how AI is used, checks sensitive data before it leaves, decides by the organisation's policy and records events for later review. ClickNext AI Security Gateway covers both AI used in the browser, through a browser extension, and models called through an API.

Is ClickNext AI Security Gateway made by a Thai company?

Yes. It is built by ClickNext (ClickNext Co., Ltd., บริษัท คลิกเน็กซ์ จำกัด), a Thai software company with its office in Ratchathewi, Bangkok. The dashboard is in Thai, and the product introduction page is available in Thai, English and Indonesian.

How is this different from letting employees use ChatGPT or Claude directly?

Employees keep using the same tools. What changes is that prompts are checked before they are sent: a prompt with block-level data, such as a real key or a valid national ID number, is stopped before it leaves the machine, and IT sees an overview of AI use with a record to look back on, without having to ask each person.

What does it detect, and what gets blocked?

The default rules cover personal data, Thai national ID numbers, credit card numbers, keys and secrets, company-confidential information and prompt injection. Email addresses get a warning. National ID numbers that pass the checksum, card numbers that pass Luhn, real keys or secrets, prompt injection and company-confidential information in a sensitive context are blocked. A word like password with no real value after it is not blocked. Administrators can change levels and add rules.

What if a normal prompt is blocked by mistake?

Employees can report it on the DLP policy page at clicknexttest.biz/DLP.html. Administrators review it and can adjust the rule or allowlist that text. The allowlist never unblocks real values such as secret keys, national ID numbers or prompt injection.

Which AI platforms are supported?

The current browser extension supports 13 platforms: ChatGPT, Claude, Gemini, Copilot, DeepSeek, Perplexity, Grok, Mistral, Poe, HuggingFace Chat, NotebookLM, Google AI Studio and Meta AI. Tools or apps that call models through the Gateway API appear in the same overview.

Can we connect coding tools or internal apps through an API?

Yes. ClickNext API keys work with OpenAI-compatible and Anthropic Messages APIs, so they work with tools such as Claude Code, Cursor, OpenCode and common SDKs. Every request is checked against the DLP rules and logged, with tokens and cost counted per key. On the API channel the check result is logged for administrators, but the request is not cut off.

How does it help with the PDPA?

Detecting personal data before it leaves, deciding by policy and keeping an audit log help support PDPA compliance. The system is not a legal certification; the organisation still needs its own personal-data policies and processes.

Who can see what?

Access depends on role and team. Employees see only their own usage, administrators see the whole organisation, and key administrator actions, such as exporting a report or changing permissions, are logged. What the extension collects is described in the privacy policy at clicknexttest.biz/privacy.

How can we control AI costs?

Every request that calls a model through the gateway is metered in tokens and priced at the provider's rates. Administrators see cost per person and per key, and set token or spending quotas per key that reset monthly or weekly.

How do we roll it out?

Employees use the ClickNext AI Security Monitor extension in Google Chrome and administrators use the web dashboard. IT can point the extension at the organisation's gateway through Chrome policy (managed policy). For rollout details for your organisation, contact ClickNext through www.clicknext.com.

Start seeing and governing your organisation's AI use

Administrators sign in to see the overview and manage what their role allows. Employees can read the DLP policy without signing in.