mtech labs ai
Eastbourne · UK
/ AI Consultancy / AI security perimeter

Saying yes to AI, without opening the door to shadow AI.

Purview controls what the data is. Defender for Cloud Apps controls where it's allowed to go. Neither closes the loop on its own — together, they're the clearest answer most tenants have to the governance question AI now makes urgent.

01/ Why two products, not one

The data plane and the app plane are different problems.

Purview handles what the data is. Defender for Cloud Apps handles where it's allowed to go. Both are needed the moment staff start pasting things into AI tools outside your tenancy — which is already happening.

What the data is

Purview — the data plane

Sensitivity labels, DLP, retention and auto-classification. Decides what material is confidential, where it's allowed to live, and how long it stays searchable. Controls the data at rest and in Microsoft-sanctioned flows.
Where it's allowed to go

Defender for Cloud Apps — the app plane

Discovers which AI apps your staff are actually using, governs the OAuth consents they've granted, and inspects or blocks the act of pasting sensitive content into ChatGPT, Claude or Gemini at the session layer.
02/ The loop that closes the door

A concrete example, start to finish.

A sensitivity-labelled document. A user opens ChatGPT and tries to paste it in. Here's what happens when the tandem is live — and why neither product can do it alone.

  1. Step 01

    A document is labelled

    Either by a user, or automatically by a Purview trained classifier — "Confidential · Client" sits in the document header and the file's metadata.

  2. Step 02

    A user opens ChatGPT

    Browser session, personal account, no tenant involvement. The kind of shadow-AI use most tenants can't see happening today.

  3. Step 03

    The session is inspected

    Defender for Cloud Apps reverse-proxies the session, reads the Purview label as the paste happens, and matches it against policy.

  4. Step 04

    The upload is blocked

    User sees a tenant-branded message explaining why. The paste doesn't reach ChatGPT's context window. Everything else in the session continues normally.

  5. Step 05

    The audit trail is written

    Who tried to upload what, when, to which AI app, and what policy caught it — filed alongside the rest of your security telemetry, ready for the regulator.

03/ What the tandem gives you

Four capabilities, one posture.

  1. Shadow AI discovery

    Defender for Cloud Apps scores 800+ generative AI apps on data handling, compliance posture and residency. An ongoing telemetry loop, not a one-off audit — new apps are surfaced the week they hit your network.

  2. Label-aware session control

    Purview sensitivity labels travel into session policies, so confidential content can be blocked from upload to ChatGPT, Claude, Gemini, Copilot and the long tail of consumer AI tools — without blocking the apps outright.

  3. OAuth & app-consent governance

    See which AI tools have been granted tenant-level permissions by staff via OAuth, score them on risk, and revoke or gate the ones that shouldn't be there. The bit most tenants have never audited.

  4. Regulator-ready audit trail

    Every block, every allow, every consent revocation — timestamped, attributed, exportable. The defensible answer when the auditor asks how AI is controlled.

/ Backed by

Delivered by M-Tech Labs with the compliance and security discipline of M-Tech Systems — Cyber Essentials certified, aligned to NCSC CAF 4.0 and progressing through the Assurix trustmark programme. Code is continuously scanned for quality and security with Aikido, with independent QA and penetration testing by Zoonou available where engagements call for it, and hosted on our own Nutanix / Fortinet platform — continuously pen-tested, current-version, UK-based. See secure development for the full picture.

Back to AI Consultancy
/ Start a conversation

Start with a readiness review.

We'll show you what your tenancy looks like to an LLM today — and what the tandem would block tomorrow.