Skip to content
PortEden

AI Gets Access.
You Keep Control.

The data firewall for AI.
Scope each agent to the data it needs.

Used at
Adobe
Red Hat
monday.com
Compass
OPPO
ZURU
Turing
Bland AI
LemonAdds
The Solution

A Smart Lock Between Agents and Your Data

Fine-grained control over what agents can see, what they can do, and what stays private.
If something goes wrong, you turn off access with one click.

The Agentic Workforce

Every Agent Gets Its Own Apps.
Each One Boxed In.

Work is splitting into fleets of narrow agents, some with a person in the loop and some running on their own. PortEden gives each agent its own identity, its own scoped apps, and a ceiling it cannot exceed. If one is ever tricked, the damage stays in its compartment.

Inbox-triage agent

Gmail
readlabel

Reads and sorts the inbox. Cannot send, forward, or delete.

๐Ÿฆž

Scheduling agent

Google CalendarGmail
read availabilitycreate eventdraft invite

Books meetings and drafts invites. Cannot read inbox threads.

Briefing agent

DriveGoogle Calendar
readsummarize

Reads files and events to prep briefings. Read-only, nothing leaves.

The firewall in action

Sensitive Data, Redacted Before It Reaches the AI

PortEden inspects every field. SSNs, payment data, DOBs, and other PII are masked at the boundary โ€” never sent.

Your data
GmailDriveCalendarOutlookSlackTeamsJiraConfluenceMonday.comAsanaLinearNotion
PortEdenRedact
Your AI
๐ŸฆžOpenClaw
Claude
Copilot
ChatGPT
GeminiGemini
Grok
Grok Bot
MuseMuse
PerplexityPerplexity
CursorCursor
LovableLovable
Base44Base44
Hermes AgentHermes
Safe
Sensitive
Redacted
In Practice

What AI Sees, Before and After

Without PortEden
jim@acme.com
RE: Contract renewal timeline
hr@yourco.com
RE: Budget Cuts, Confidential
sarah@bigcorp.com
Follow-up: Q3 deliverables
finance@yourco.com
Salary Review, Internal Only
tom@acme.com
Invoice #4521 attached
With PortEden
jim@acme.com
RE: Contract renewal timeline
sarah@bigcorp.com
Follow-up: Q3 deliverables
tom@acme.com
Invoice #4521 attached
Find your fit

How Teams Use PortEden

Partner integration

Build an agentic workflow fleet with WorkerKit.ai

One assistant holding the keys to everything is the easy way to start and the hard way to scale. What holds up is a fleet: a narrow agent per workflow, most of them running unattended, each reaching only the data its job actually needs.

WorkerKit is where those workers come from. It runs AI workers as background agents, each with its own instruction, memory, schedule, budget, and model, packaged as installable kits so an agentic workflow that used to take an afternoon of wiring takes about a minute. PortEden is the layer underneath: the grant each worker runs on, and the record of what it did with it.

WorkerKit runs the fleet

The workers

Kits, not flowcharts
Every worker arrives pre-instructed, pre-permissioned, and pre-scheduled for one job: triage, monitoring, follow-ups, reporting, research.
Runs without you
On demand, on a schedule, or on a signed webhook. A worker that needs an answer asks its question and resumes when you reply.
The right model per job
Cheap models scan, frontier models judge. Claude, ChatGPT, Gemini, and Grok all drive the same kit.
Results where people are
Each run closes with a short digest delivered to Slack, Teams, email, or a webhook, instead of waiting in a chat nobody opens.

PortEden scopes the data

The firewall

One identity per worker
Each worker holds its own access token. Narrow one grant or switch one worker off and the rest of the fleet keeps running.
Read-only until you say otherwise
Grants are made app by app, then narrowed with contact blocks, label and folder rules, domain limits, and time windows.
Redacted before the model sees it
Sensitive fields are masked at the boundary, so the text a worker reasons over never contained them in the first place.
Every tool call on the record
Which tool a worker called, whether it was allowed or denied, and what came back after redaction.

Scoping a fleet this way is not only a security control. A worker that pulls an entire mailbox into context answers worse than one that pulls the six messages its job calls for, and it burns more tokens doing it. The grant that keeps a worker out of data it has no business reading is the same grant that keeps its context small enough to be good at its job.

The fleet also meets the agents already on your desk. WorkerKit publishes connectors for Grok Bot and Meta Muse, so the agent you already talk to can dispatch background workers and read back their digests, while PortEden holds the line on what any of them can reach.

Frequently Asked Questions

What we redact, what we don't, and how rollback works.

PortEden sits between AI and your business tools as a data firewall. Every tool call AI makes (to read an email, search your calendar, list files) passes through PortEden's rules first. You decide what AI can see, what it can do, which contacts or projects are off-limits, and which actions are draft-only or read-only. Sensitive data is redacted before it reaches the AI, and every request is logged.

PortEden masks sensitive content in tool responses: SSNs, credit cards, passport numbers, API keys, and other secrets in emails, documents, and task comments. On top of that you can hide specific contacts, redact subject lines, strip attachments, or block projects matching a label. PortEden does not see your prompts to the AI or the AI's responses back to you. It inspects the tool calls in between, not your conversations.

Every connection has a one-click revoke. The token is invalidated immediately and any AI session using it stops working on the next request. You can also pause an entire integration, dial scope down to read-only, or roll back to a previous policy version. The audit log shows every tool call AI made before you cut access, so you can see exactly what was read or written.

PortEden works with Claude, ChatGPT, Microsoft Copilot, Google Gemini, Grok, and any client that speaks the open MCP and CLIs. The same access rules apply regardless of which AI is on the other side.

Email (Gmail, Outlook, Exchange), calendars (Google, Outlook), files (Google Drive, Docs, Sheets), team chat (Slack, Microsoft Teams), project tools (Jira, Linear, Asana, Monday, Notion, Confluence), and many other business tools. The same rule engine runs across all of them, so a policy you write for email applies the same way to your task tracker.

Built-in connectors are all-or-nothing. Grant Claude your inbox and Claude sees your inbox. PortEden adds a control layer in between: granular rules per user, per AI, and per project, plus an audit trail and a kill switch. If your security team needs to know what AI accessed last Tuesday they can, and if a contractor leaves, you revoke their AI's access without touching the underlying Google or Microsoft account.

Yes. Account-wide policies set the ceiling (block specific domains, disable services, cap visibility), and every user's tokens inherit them automatically. Policy Groups let you layer different profiles on top, so legal can see one rule set while engineering sees another. New tokens pick up the right policy on creation.

There's a free tier with the core firewall. Paid tiers add organization policies, higher rate limits, more functionality and longer audit retention. See the pricing page for current details.

Stop Sending Your Inbox to Someone Else's AI in the Clear.

Professionals

Solo or small team? Start free. Five minutes from sign-up to your first secured prompt.

Enterprise

Governance, fine-grained data access control, and PBAC across your ai providers.