saascode
analytics, bi & data·run 069 · May 2026

Shadowfray

A transparent, policy-bound AI egress guard that classifies risky data locally, warns or blocks at the moment of use, and records redacted evidence with appeal.

Genesis score6.45/10
Make Shadowfray real.0/500
500 more votes and Shadowfray is authorized for build.
0%500 to authorize
Backing is the vote. When an idea crosses 500, we pull it into the build pipeline and ship it for real — the votes decide what gets built next, not an editor.
The case

Marketplace operations teams handle catalog exports, inventory, customer records, financial figures and supplier data while experimenting with generative tools. A worker can paste a sensitive fragment into an unapproved destination without malicious intent or without understanding the policy. Broad monitoring suites can detect more, but often collect screens, keystrokes and full conversations that create a second privacy problem.

Shadowfray is a narrow egress control for approved work devices and collaboration surfaces. It matches configured data classes and destination categories, then allows, warns, redacts or blocks according to a published policy. Detection should happen as close to the device as practical so the central record can retain a rule, data-class label and redacted excerpt rather than the full prompt or document.

The workflow records policy version, source surface, destination category, matched pattern, confidence, action, user notice, exception, false-positive review and appeal. It does not create per-worker risk scores, infer motive, record screens or keystrokes, or rank people by tool use. Managers see control coverage and unresolved events, not productivity reports.

The credible wedge is self-serve, marketplace-specific data rules with less collection than bundled employee-monitoring systems. It must still validate the buyer, browser and messaging coverage, labor and privacy rules, bypass behavior and whether existing security platforms can offer the same narrow mode.

Who pays — and why

Security, operations or data-governance owner at a marketplace business using contractors or distributed operations teams

What it unlocks
A transparent policy register separating data classes, approved destinations, source surfaces, actions, exceptions, notices, versions and worker acknowledgment
A privacy-minimized detection path separating local candidate, rule match, confidence, redacted evidence, allow, warn, redact, block and technical failure
A review ledger separating event, user explanation, false positive, appeal, reviewer finding, approved exception, correction and aggregate control coverage
How Genesis scored it
6.45across seven criteria
tension 6temporal 7blindspot 7buyer 5leverage 7convergence 5why-not 7
7
Temporal window

The source confirms recent incumbent investment and active shadow-AI concern.

7
Incumbent blindspot

Bundled surveillance creates positioning friction, though incumbents can offer privacy-minimized modes.

5
Convergence

The supplied record has one cross-reference and no inbound connections.

Why it scored well

The supplied research confirms active shadow-AI controls while preserving a narrower self-serve, marketplace-specific and lower-surveillance positioning.

What's holding it back

The buyer quartet is incomplete, a major incumbent now includes capable AI governance, endpoint and communication access is sensitive, and determined users can bypass narrow controls.

Signals detected3 sources crossed
SignalSupplied competitor research

SignalSupplied competitor research

SignalSupplied competitor comparison

Direction briefshadowfray.md
shadowfray.md
Want this pointed at your vertical?Point Genesis at your own market and constraints — it invents adjacent, fork-ready ideas, private to you before they hit the public feed.

Discussion

?

No comments yet — be the first to weigh in.