Technical specifications
Every capability, and every limit, on one page.
The reference for security architects and procurement. Anything marked Roadmap is built or planned but not offered today.
Specifications
The platform in detail.
- Browsers
- ChromeEdgeFirefoxManifest V3. The on-device model runs in Chrome and Edge; Firefox uses the deterministic layer.
- AI sites covered
- ChatGPTClaudeGeminiMicrosoft CopilotPerplexityDeepSeek
- Financial data
- IBANPayment cardDutch VAT (BTW)KvK number
- National identifiers
- BSNGerman Steuer-IDGerman SteuernummerEU national IDBIG number
- Personal data
- EmailPhoneIP addressDate of birthDutch postcode
- Secrets
- API keyGeneric secretPrivate keyJWTAWS keyGCP key
- Model classes
- Person namePostal addressHealth dataOrganisation-confidentialOn-device ONNX model, 13 MB.
- Other
- Source codeUninspectable content
- File types
- PDFDOCXXLSXPPTXCSVTXTMDJSON
- Policy actions
- AllowLogWarnRedactBlock
- Policy templates
- GDPR baselineFinancial (DORA-aligned)Government (strict EU residency)Education
- Channels
- BrowserGatewayDesktop MDM only
- Gateway providers
- Mistral EUAzure OpenAI EU EUOpenAIAnthropicDeepSeek
- Roles
- OwnerAdminSecurity engineerAnalystAuditorDPO
- Single sign-on
- Microsoft Entra ID RoadmapGoogle Workspace RoadmapOkta RoadmapKeycloak RoadmapGeneric OIDC RoadmapBuilt and dormant; offered after early access. SAML needs an external SAML-to-OIDC bridge.
- Shadow-AI discovery
- Discovery ingest API RoadmapRequires a DNS or metadata feed before it can report; not offered today.
- Desktop apps (MDM)
- ChatGPT DesktopClaude DesktopDeepSeek DesktopMicrosoft Copilot
- MDM outputs
- AppLocker policyDNS blocklistJamf profile
- Evidence export
- JSON packCSVPDF
- Cryptography
- Hash chainMerkle sealsEd25519 signaturesSalted one-way hashes
- Supply chain
- CycloneDX SBOMDependency audit gateContainer image scanningCRA incident workflow
- Interception
- NoneNo TLS interception, no root CA, no kernel driver, no per-app hooking. User mode and browser sandbox only.
Honest limits
What Deltawall does not do. Printed on purpose.
A security product that hides its limits hands them to the attacker. Ours are in the contract.
- No OCR.Scanned PDFs and images are flagged as uninspectable, not read. Your policy decides what happens to them.
- Redaction applies to typed prompts.The user presses send again after masking. A file that needs redaction is stopped, not rewritten.
- Desktop apps are governed, not intercepted.MDM policy bundles block or allow them. A Redact rule on the desktop channel returns an error; it never silently downgrades.
- The model runs in Chrome and Edge.Firefox enforces with the deterministic detector layer.
- Coverage is bounded to the listed AI sites.Six today: ChatGPT, Claude, Gemini, Microsoft Copilot, Perplexity and DeepSeek. The contract names them.
- It fails open.If the upload guard or the model errors or times out, the AI site keeps working. A broken scanner never breaks the workday.
- SSO is on the roadmap.Sign-in today is email and magic link. OIDC single sign-on is built but not yet offered.
- Shadow-AI discovery is on the roadmap.The ingest API exists; it needs a DNS or metadata feed before it can report anything, so we do not sell it yet.
Get started
See it stop real-looking data in a real browser.
A 30-minute technical walkthrough: a prompt redacted, a file stopped, the dashboard, and an evidence pack verified offline in front of you.
No slide deck. Synthetic data only.
