
Workforce AI security that discovers shadow AI use and stops data leaving for external models
Aona AI was founded in Sydney in 2023 by Bastien Cabirou, on the premise that enterprise AI adoption had outrun the governance around it: staff were pasting confidential material into consumer chat tools, and security teams had no record of it. The platform sits at the point of use rather than the network edge, combining a browser extension with Windows and macOS desktop agents and API integrations into sanctioned providers. From that vantage it records which AI applications each employee opens, when, and for what purpose, producing a usage inventory drawn from a catalogue the company says covers more than 10,000 tools, including the ones IT never approved.
Enforcement runs in the same path. Prompts are inspected before they leave the device, with personal data, intellectual property, and other classified material redacted or blocked outright, and requests to unapproved services routed into an approval workflow rather than simply failing. A coaching layer explains each decision to the employee at the moment it happens, which is aimed at changing behaviour rather than only logging it. What remains is an audit trail security and GRC teams can map onto GDPR, HIPAA, ISO 42001, and the EU AI Act. Aona holds SOC 2 Type II certification and raised a pre-seed round in 2025 backed by Antler, Tenity, and angel investors; how much prompt content is retained depends on the deployment architecture chosen.



