For your AI tools

LOCKE FOR MICROSOFT COPILOT

Run Microsoft Copilot across your tenant with a control at the device.

Microsoft Copilot is embedded throughout Microsoft 365 — Word, Outlook, Excel, Teams — and grounded in your organisation's own data through the Graph. That's its strength: it answers using your documents, your email, your chats. It also means Copilot operates over the broadest collection of sensitive material most organisations hold, all under one assistant.

Microsoft's own governance — Purview labels, tenant policies, audit logs — does serious work at the organisational layer, and it's the right tool for that layer. What it doesn't do is act at the moment of composition on the device, and it has no reach when the same employee opens ChatGPT or Claude in a browser tab outside the Microsoft boundary. Channel governance is not the same as content control, and an audit log of a prompt is a record that the sensitive data was already sent.

Locke adds the device-layer control that complements tenant governance rather than competing with it. Sensitive values are detected and masked before a prompt is submitted — inside the Microsoft 365 boundary and outside it — so the most regulated fields never enter a model context in the first place.

The risk with Microsoft Copilot

Microsoft Copilot reasons over your entire tenant — documents, email, Teams — so it touches your most sensitive data by design, and tenant-level controls govern the channel and produce audit records without preventing regulated fields from entering a prompt at the moment of composition.

How Locke helps

Locke adds a zero-knowledge, device-layer control that masks sensitive data before a prompt is sent — complementing Purview and tenant policy rather than replacing them. Locke — the Sonomos desktop app, coming soon — carries that control across Microsoft 365 and the non-Microsoft AI tools employees also use.

Keep using Microsoft Copilot — without the exposure

Locke runs entirely on your device. Sensitive data is detected and masked before any prompt is sent, so nothing confidential ever leaves your machine. Pricing for Locke, the desktop app, is coming soon; Canary is free and open source.