PMsquare

Services

Blogs

How Portal26 Solves GenAI Security Risks
RC Reynolds, February 17, 2025

At this point, everyone is aware of the DeepSeek craze. After becoming the most downloaded app in the world and making headlines for its remarkably low $6 million development cost. Users are eagerly testing its capabilities and many are impressed. But for organizations, this raises serious security concerns.

The biggest issue? All the data sent to DeepSeek goes straight to China, a country known for its advanced cyber capabilities and persistent threats to enterprise security. For CSOs, this isn’t just a hypothetical risk. It’s a real and immediate challenge.

What are the specific threats of viral AI applications like DeepSeek, and how can organizations protect themselves from them? Without a plan and the right tools in place organizations will always be a step behind this fast-changing market and risk employees inadvertently leaking data. That’s where Portal26’s advanced AI governance platform can help.

The AI platforms may change from month-to-month, but the types of security risks they pose are consistent. Portal26 helps identify and eliminate risks such as:

  • Data Leakage & Shadow AI: Employees may unknowingly or knowingly expose sensitive corporate data to external GenAI models, leading to compliance violations and IP loss.
  • Model Integrity & Trust: Open-source models can be manipulated or compromised, posing risks to organizations integrating them into workflows.
  • Regulatory Compliance: Emerging regulations require businesses to track, monitor, and audit GenAI usage to ensure data protection.
  • Insider Threats & Malicious Use: Without visibility, bad actors within an organization could leverage GenAI for unauthorized data extraction or adversarial AI attacks.

How Portal26 Mitigates GenAI Security Concerns

Portal26

Portal26 is a game-changing AI governance platform that gives organizations clear insight into their company’s GenAI usage. This visibility allows organizations to responsibly adopt Generative AI to enhance productivity, while strengthening security, reducing risk and enabling data informed investment decisions for their GenAI program.

What sets Portal26 apart is its seamless integration with existing security tools like Zscaler, Netskope, iBoss, Palo Alto, and more, they have yet to find a security solution they can’t connect with. Installation is quick and hassle-free, typically taking less than 90 minutes and often as fast as

30 minutes. There are no endpoint agents, browser plugins or proxies to deploy and there is zero impact on user experience and network latency.

High-level architecture of Portal26 integration

With fast deployment and integrations that leverage your existing network security investments, Portal26 empowers organizations to take control of their GenAI usage, minimizing security risks while maximizing their productivity gains.

Key Platform Features

Shadow AI Discovery

It starts with the Portal26 Shadow AI Discovery Engine that analyzes all of your web traffic and identifies those sites which utilize Generative AI models in real time and feeds them back to your secure web gateway or firewall so that your URL Category based policies are as complete and effective as possible. Because new Generative AI sites are constantly coming online and existing sites are adding GenAI capabilities, real world experience has shown that the static URL

Categorization lists from the major Secure Web Gateway and Firewall vendors miscategorize as many as half of all the GenAI sites their users are visiting.

Shadow AI Discovery - miscategorization of GenAI sites

For example, Portal26 Shadow AI Discovery customers have been aware of DeepSeek since January 7, 2025, almost three full weeks before any of the major security vendors classified the DeepSeek domain as Generative AI. While many organizations were scrambling on January 27th to figure out what potential risk exposure, they had due to DeepSeek, Portal26 customers were able to immediately quantify how much use had occurred as well as any potentially sensitive data that might have been exposed because of that use. The DeepSeek experience is not unique, one 500 user company has averaged 17 new uncategorized Gen AI sites per week over the eight weeks they’ve been using the Shadow AI Discovery service, which allows its small security team to focus on investigating and remediating GenAI related incidents instead of maintaining a complete list of sites, domains and URL’s which are GenAI related.

GenAI Prompt Analytics

Prompt Analytics - the state of GenAI use

In addition to Shadow AI Discovery, Portal26 provides a comprehensive Prompt Analytics capability that allows organizations to understand not only which GenAI sites their users are interacting with but can also analyze and report on the state of GenAI use including departmental data, user intent and the presence of sensitive data in user prompts. By saving the prompt data in its NIST FIPS-140-2 secure data vault, Portal26 enables complete forensic analysis during insider threat, data leakage investigations, control effectiveness testing and risk assessment after breach/vulnerability announcements from GenAI vendors.

Sensitive data detection engine flags prompts

Portal26’s AI driven sensitive data detection engine flags prompts that contain sensitive data such as PII, PHI, company IP and code. Once a sensitive data incident is identified a push notification can be generated to email or can automatically trigger the creation of an incident in ServiceNOW, ITSM, SOAR or SIEM platforms. In combination with ShadowAI Discovery, Portal26 Prompt Analytics gave security leaders the ability to instantly answer the question “Have we put any sensitive data into DeepSeek?” before the Secure Web Gateway and Firewall vendors had even categorized DeepSeek as Generative AI.

Conclusion

The explosion of GenAI tools like DeepSeek is just the beginning. As these models grow larger, more powerful, and widely adopted, organizations must stay ahead of the curve. The risks of data leakage, compliance failures, and security blind spots will only intensify as new AI platforms emerge, making visibility and governance non-negotiable.

Now is the time to act. By implementing a proactive platform like Portal26 for GenAI visibility and governance, companies can protect their sensitive data, enforce security policies, and ensure AI is used responsibly. Organizations that lack a comprehensive strategy to manage the risks from DeepSeek and future GenAI models will continue to fall behind and expose themselves to embarrassing and painful security breaches.

Reach out to PMsquare to learn how Portal26’s shadow AI and AI governance platform can protect your business from AI risks. If you are needing more hands-on support, explore PMsquare’s GenAI Assessment designed to provide business leaders with a holistic approach to developing, implementing, and securing AI workloads.

Be sure to subscribe to our newsletter for more PMsquare updates, articles, and insights delivered directly to your inbox.