Skip to main content
Interactive Artifacts

Purfect Labs Learning Center

Self-guided interactive artifacts on AI infrastructure, security, workflows, and the platform that connects them. No fluff, just working concepts you can click through, score yourself on, and compare side by side.

How Shield Works

Interactive Guide

An interactive walkthrough of Shield's architecture: proxy flow, filter packs, threat model, and tamper-evident audit trail. Tab through each layer of the security stack.

5 min readExplore →

Shield vs. The Alternatives

Comparison Guide

Feature-by-feature comparison matrix: Shield vs. WAFs, prompt guardrails, and manual processes. Expandable rows, live code comparison, and alternative deep dives with pros/cons.

8 min readExplore →

Secret Detection: Entropy vs. Regex

Interactive Guide

Live entropy calculator and regex comparison tool. Learn why entropy analysis catches custom tokens, encoded credentials, and novel secrets that regex patterns miss entirely.

6 min readExplore →

Prompt Injection vs. Data Exfiltration

Interactive Guide

Interactive threat scenarios and attack surface comparison. See how injection manipulates model behavior while exfiltration leaks sensitive data, and how Shield blocks both in one proxy.

7 min readExplore →

Enterprise Compliance: SOC 2, HIPAA, GDPR, ISO 27001

Interactive Guide

Interactive guide mapping Shield's architecture to major compliance frameworks. See exactly which controls Shield satisfies with specific clause references and evidence mappings.

7 min readExplore →

LLM Data Exposure: The Hidden Supply Chain

Interactive Map

Interactive map of the AI supply chain. Click each node to see what leaks at every layer and toggle Shield on/off to see how local redaction closes every gap.

6 min readExplore →

LLM Security Checklist: 10 Things You're Missing

Checklist

Interactive checklist covering the 10 most common LLM security gaps, from secret detection and compliance scope to incident response planning.

6 min readExplore →

LLM Data Redaction: What Gets Caught and What Doesn't

Sandbox

Interactive redaction sandbox, paste any text and toggle Shield's four filter packs to see exactly what gets caught. Every match comes with an explanation.

7 min readExplore →

AI Training Data Risks: How Your Prompts Become Training Data

Interactive Guide

Interactive data flow simulator, toggle Shield on/off to see exactly what sensitive data reaches LLM training pipelines. Provider policy explorer included.

6 min readExplore →

MCP Security: When AI Agents Have Tool Access

Interactive Guide

Interactive threat model explorer for Model Context Protocol security. Map attack vectors across tool impersonation, parameter injection, and credential exposure.

7 min readExplore →

AI Incident Response: What to Do When a Prompt Leaks

Interactive Guide

Interactive incident response guide for AI data breaches, explore three real-world scenarios, walk through a five-phase response timeline.

7 min readExplore →

Why Your WAF Can't See Inside LLM Requests

Technical Deep Dive

Interactive guide showing the architectural gap between network-layer WAF inspection and application-layer AI threats. Side-by-side threat coverage comparison.

7 min readExplore →

Self-Hosted AI vs. API-Based AI: Security Comparison

Comparison Guide

Architectural comparison of self-hosted and API-based AI deployments. Threat model tabs, interactive decision matrix, and security gap analysis.

7 min readExplore →

AI Red Teaming: How to Test Your LLM Defenses

Interactive Guide

Interactive guide to AI red teaming, systematically test your LLM applications for prompt injection, data exfiltration, and supply chain vulnerabilities.

8 min readExplore →

AI Prompt Sanitization Playground

Playground

Paste any prompt and watch Shield's redaction engine catch PII, secrets, PHI, and payment data in real time. Toggle filter categories, see highlighted matches.

5 min readExplore →

LLM API Key Management: The Security Checklist

Checklist

Interactive checklist covering 10 critical API key management practices, hardcoded keys, missing rotation, shared credentials, zero audit trail. Score your team's key hygiene.

5 min readExplore →

SOC 2 for AI: What Auditors Actually Check

Interactive Guide

Interactive walkthrough of the five Trust Services Criteria for AI systems. OWASP LLM Top 10 mapping, audit readiness checklist, and evidence collection guidance.

7 min readExplore →

Shield for Telecommunications: CPNI & CALEA Compliance

Interactive Guide

Three-scenario redaction sandbox for telecom: customer support with CPNI, network operations with device identifiers, and billing disputes with payment data. Compliance mapping for CPNI, CALEA, FCC 2024 breach rules, GDPR, NIST CSF, and ISO 27001:2022.

7 min readExplore →

AI Agent Identity & Access Management

Interactive Guide

Learn how to securely authenticate and authorize AI agents. Covers OAuth2 service accounts, OWASP LLM08 Excessive Agency, NIST AI RMF governance, and practical patterns for agent-to-API access control.

7 min readExplore →

AI Data Classification: Protect Sensitive Data Before It Reaches LLMs

Interactive Guide

Learn how to classify data for AI use, public, internal, confidential, and restricted. Interactive classification tool, data-type matrix, and self-assessment for enterprise teams sending data to ChatGPT, Claude, and other LLMs.

6 min readExplore →

AI Data Loss Prevention: What Traditional DLP Misses

Interactive Guide

Traditional DLP tools catch structured data in databases and email, but they're blind to unstructured AI prompts containing PII, secrets, and confidential business data. Learn how AI-aware DLP closes the gap.

6 min readExplore →

AI Data Residency & Sovereignty, Where Your AI Data Lives

Interactive Guide

Your AI prompts cross borders you didn't know existed. Learn how data residency laws (GDPR, PIPL, DPDP Act, LGPD) affect where your AI data is stored and processed, and how to keep sensitive data within your jurisdiction.

6 min readExplore →

AI Governance Frameworks: NIST: ISO, EU AI Act & OWASP

Comparison Guide

Compare the four major AI governance frameworks, NIST AI RMF, ISO 42001, EU AI Act, and OWASP Top 10 for LLM, and assess which apply to your organization. Interactive framework comparison with applicability assessment.

7 min readExplore →

AI Provider Data Handling: OpenAI vs. Anthropic vs. Google

Comparison Guide

Compare how OpenAI, Anthropic, and Google handle your prompts and data. What they log, what they train on, and how to lock it down, before your data leaves your machine.

6 min readExplore →

LLM Firewall: What It Is and Why You Need One

Technical Deep Dive

An LLM firewall inspects, modifies, and blocks prompts and responses between your applications and AI models like ChatGPT, Claude, and Copilot. Learn how it differs from a WAF, what threats it stops, and how to deploy one.

7 min readExplore →

On-Prem vs. Cloud AI Security, Deployment Trade-offs

Comparison Guide

Compare on-premises vs cloud AI deployment: data sovereignty, compliance, latency, cost, and control. See how a local security gateway gives you cloud convenience with on-prem data protection.

7 min readExplore →

AI Data Redaction Patterns: PII, PHI, PCI & Secrets

Technical Deep Dive

How data redaction actually works: the regex patterns, entropy detection, and machine learning approaches that catch PII, PHI, PCI, and secrets before they reach ChatGPT, Claude, or Copilot.

6 min readExplore →

Shield for DevTools: Protect API Keys, Tokens & Secrets

Industry Guide

Stop API keys, tokens, database credentials, and customer secrets from reaching ChatGPT, Claude, Copilot, or any AI model. Shield keeps your secrets on your machine, SOC 2 and ISO 27001-ready for DevTools teams.

7 min readExplore →

Shield for Automotive: Secure AI for Manufacturing, Autonomous Driving & Connected Vehicles

Industry Guide

Protect VINs, GPS traces, firmware builds, calibration parameters, supplier contracts, and connected-vehicle customer data before they reach ChatGPT, Claude, Copilot, or any AI model. Shield keeps automotive data on your machines, ISO/SAE 21434, UN R155, TISAX, GDPR, CCPA-ready.

7 min readExplore →

Shield for E-Commerce: Protect Customer Data Before It Reaches AI

Industry Guide

Stop customer PII, payment card data, and order details from reaching ChatGPT, Claude, or any AI model. Shield keeps e-commerce customer data on your machines, PCI DSS, GDPR, CCPA-ready.

7 min readExplore →

Shield for Education: Secure AI for K-12, Higher Ed & EdTech

Industry Guide

Protect student records, grades, IEP data, and directory information before they reach ChatGPT, Claude, Copilot, or any AI model. Shield keeps student data on your machines, FERPA, COPPA, PPRA-ready.

7 min readExplore →

Shield for Energy & Utilities, Secure AI for Grid, SCADA & NERC CIP

Industry Guide

Protect grid telemetry, SCADA configurations, control system data, and NERC CIP audit materials before they reach ChatGPT, Claude, Copilot, or any AI model. Shield keeps your operational data on your machines.

7 min readExplore →

Shield for Financial Services: Secure AI for Banks, Trading & Fintech

Industry Guide

Protect customer data, payment information, and proprietary models before they reach ChatGPT, Claude, Copilot, or any AI model. Shield keeps financial data on your machines, PCI DSS, GLBA, SOX-ready.

7 min readExplore →

Shield for Government & Defense, Secure AI for CUI, ITAR & Classified Workflows

Industry Guide

Stop controlled unclassified information (CUI), ITAR technical data, and procurement-sensitive documents from reaching ChatGPT, Claude, Copilot, or any AI model. Shield keeps government data on your machines.

7 min readExplore →

Shield for Healthcare AI: HIPAA-Compliant AI Security

Industry Guide

Protect patient data before it reaches ChatGPT, Claude, or any AI model. Shield stops PHI, medical records, and insurance IDs from ever leaving your hospital's network.

7 min readExplore →

Shield for Insurance: Protect Policyholder Data Before It Reaches AI

Industry Guide

Stop policyholder PII, medical records, financial data, and claims information from reaching ChatGPT, Claude, or any AI model. Shield keeps insurance data on your machines, HIPAA, GLBA, NAIC AI Principles-ready.

7 min readExplore →

Shield for Legal Tech: Protect Attorney-Client Privilege in AI Workflows

Industry Guide

Stop confidential case data, client names, and settlement details from reaching ChatGPT, Claude, or any AI model. Shield keeps attorney-client privileged information on your firm's machines.

7 min readExplore →

Shield for Manufacturing: Secure AI for Trade Secrets, CUI & Industrial Data

Industry Guide

Protect manufacturing trade secrets, CUI, ITAR-controlled technical data, and supplier contracts before they reach ChatGPT, Claude, Copilot, or any AI model. Shield keeps proprietary industrial data on your machines.

7 min readExplore →

Shield for SaaS Startups: Protect Customer Data, Pass Security Reviews

Industry Guide

Keep customer PII, API keys, and internal architecture docs out of AI prompts. Pass enterprise security questionnaires and protect your SOC 2, ISO 27001, and GDPR posture, without slowing down your team.

7 min readExplore →

Shield vs. Building In-House: Cost Comparison Calculator

Calculator

Compare the real cost of building an AI data security solution in-house versus deploying Shield. Interactive calculator covers engineering, infrastructure, compliance, and maintenance, estimate your total cost of ownership.

5 min readExplore →

The Real Cost of an AI Data Leak

Calculator

Interactive cost calculator, estimate the financial impact of an AI prompt leak based on your company size, industry, and the data types you send to LLMs.

5 min readExplore →

Shadow AI Risk Estimator

Risk Calculator

Interactive risk calculator, estimate your organization's shadow AI exposure in 2 minutes. See your risk score, data leak probability, and estimated annual cost.

5 min readExplore →

AI Security Policy Generator: Custom Policy in 3 Minutes

Policy Generator

Interactive policy builder, answer 6 questions and get a complete, framework-mapped AI security policy. 8 sections, ready for your next security audit.

5 min readExplore →

AI Security Maturity Model: Where Is Your Organization?

Self-Assessment

Self-assessment across 5 dimensions, governance, visibility, data protection, threat detection, and compliance. 10 questions, 3 minutes.

3 min quizExplore →

AI Security Risk Assessment

Self-Assessment

6 questions. 2 minutes. Score your AI pipeline's security posture and get a personalized Shield tier recommendation. No email required.

2 min quizExplore →

Build vs. Buy AI Security, Decision Framework

Decision Framework

Interactive scorecard across six dimensions: time, engineering capacity, compliance, cost, maintenance, and strategic fit. Rate your organization and get a clear build/hybrid/buy recommendation.

5 min readExplore →

AI Compliance Readiness Checklist: SOC 2, HIPAA, GDPR & More

Checklist

Self-assessment checklist covering SOC 2, HIPAA, GDPR, ISO 27001, PCI DSS, and NIST AI RMF controls. Check off your AI compliance readiness and get an instant score across every framework.

7 min readExplore →

AI Tool Inventory & Risk Mapper

Self-Assessment

Build an inventory of every AI tool your team uses. Categorize by type, data sensitivity, integration depth, and user scope, then get a weighted risk score and prioritized mitigation plan for each one.

5 min readExplore →

AI Vendor Security Questionnaire: Custom Assessment in 3 Minutes

Assessment

Select your compliance frameworks, AI tool type, and data sensitivity to generate a tailored 40+ question security questionnaire for evaluating any AI vendor. Covers data handling, encryption, access controls, incident response, and compliance certifications.

5 min readExplore →

LLM Logging: The Security Blind Spot, What AI Providers Store About Your Prompts

Interactive Guide

Compare what OpenAI, Anthropic, Google, and Microsoft log from your prompts, training policies, retention windows, and compliance gaps. Learn how to keep sensitive data off provider servers with local-first redaction.

7 min readExplore →

Blockchain Primitives for AI Infrastructure, ZK Proofs, Merkle Trees, DIDs & Smart Contracts

Architecture Deep Dive

Architecture deep dive into four cryptographic building blocks for trustworthy AI: verifiable inference with ZK proofs, data provenance with Merkle trees, on-chain governance with smart contracts, and agent identity with W3C DIDs and Verifiable Credentials.

8 min readExplore →

Shield for Pharma & Life Sciences, Clinical Trials, R&D & Regulatory

Industry Guide

Protect clinical trial data, drug discovery IP, and regulatory documents before they reach any AI model. Interactive redaction scenarios for clinical operations, medicinal chemistry, and FDA submissions.

6 min readExplore →

Shield for Media & Entertainment, Studios, Production & Talent

Industry Guide

Protect scripts, talent contracts, and pre-release footage before they reach any AI model. Interactive redaction scenarios for script development, talent negotiations, and pre-release marketing.

6 min readExplore →

Shield for Non-Profits: Secure AI for Charities, Foundations & NGOs

Industry Guide

Protect donor records, grant proposals, and client case files before they reach any AI model. Interactive redaction scenarios for grant writing, donor management, and client services.

7 min readExplore →

Shield for Accounting & Tax, Secure AI for CPAs, Tax Prep & Audit

Industry Guide

Protect client tax returns, SSNs, bank account numbers, and confidential financial data before they reach ChatGPT, Claude, Copilot, or any AI model. Shield keeps taxpayer data on your machines, IRS Pub 1075, GLBA, FTC Safeguards-ready.

7 min readExplore →

Shield for Real Estate: Secure AI for Agents, Brokers & Property Managers

Industry Guide

Protect mortgage applications, SSNs, tenant screening data, and confidential transaction documents before they reach ChatGPT, Claude, Copilot, or any AI model. Shield keeps client data on your machines, GLBA, FTC Safeguards, FCRA, RESPA-ready.

7 min readExplore →

Shield for Transportation & Logistics, Secure AI for Freight, Fleet & Supply Chain

Industry Guide

Protect shipment manifests, driver PII, cargo declarations, and supply chain partner data before they reach ChatGPT, Claude, Copilot, or any AI model. Shield keeps logistics data on your machines, TSA, C-TPAT, FMCSA-ready.

7 min readExplore →

Shield for Hospitality: Secure AI for Hotels, Resorts & Travel

Industry Guide

Protect guest PII, credit card data, loyalty program records, and event contracts before they reach ChatGPT, Claude, Copilot, or any AI model. Shield keeps guest data on your machines, PCI DSS, GDPR, CCPA-ready.

7 min readExplore →