Free tools Windows power users keep installed
One-click scans. No signup required.
Protect company data used with generative AI by approving specific tools and use cases, setting clear rules for what employees may submit, limiting what connected systems expose, and monitoring for misuse or accidental disclosure. No “enterprise” label makes every workflow safe: check the exact product plan, contract, settings, integrations, and data involved.
Start with approved tools and use cases
Employees may reach generative AI through websites, company applications, APIs, browser extensions, or connected agents. Build an inventory of both sanctioned and observed services before setting rules; otherwise, a policy may cover only the obvious chat tool while missing other ways data can leave the organization.
For each tool, specify which tasks are permitted and what data categories they may involve. NIST’s Generative Artificial Intelligence Profile recommends acceptable-use policies tailored to generative AI, including the different risks of foundation models, fine-tuned systems, and AI embedded in other tools.
Use a simple risk framework that employees and managers can apply:
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
- Lower-risk work: brainstorming or summarizing public information, provided employees verify outputs and follow company rules.
- Controlled work: tasks involving internal information only in an approved service and account, with safeguards appropriate to the data and use case.
- Restricted work: processing secrets, credentials, regulated personal information, restricted customer records, or confidential content only when a documented exception authorizes the specific tool, account, purpose, and safeguards.
This is a policy-design approach, not a claim that one rule is a universal legal prohibition. NIST also recommends considering third-party privacy, intellectual-property, and information-security risks when procuring AI services.
Make data rules specific enough to follow
Classify information in plain language and give employees concrete examples. A workable policy should say both what is prohibited and what to do instead—for example, use synthetic or properly de-identified sample data for a demonstration, or request an approved workflow when a business task genuinely requires sensitive information.
A policy can include a short rule such as:
Use only company-approved AI tools and accounts. Do not submit credentials, secrets, restricted customer or employee records, regulated personal information, or confidential material unless an approved exception explicitly covers the tool, purpose, account, and required safeguards. Check outputs before relying on or sharing them, and report accidental disclosure promptly.
Rank #2
Thetis FIDO2 Security Key (USB-A, 2-Pack) - Hardware MFA & Passkey Access for Business, School ERP & Employee Accounts | Compatible with Windows, Google Workspace, Apple ID, Coinbase, Salesforce
- FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
- Universal Connectivity (USB-A ): Features a built-in USB-A connector—simply unfold the key and plug it into your compatible PC or laptop for seamless authentication on the go.
- Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
- Ultra-Durable & Portable: Featuring a rotating metal cover, this key is water, crush, and tamper-resistant. It fits easily on a keychain and requires no batteries or network connectivity.
- Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID, and NFC is NOT supported.
Define who can approve exceptions and how they are recorded. “Use good judgment” is not a substitute for a clear rule about which service and data combinations are allowed.
Evaluate the exact product, plan, and configuration
Do not choose a service based on a brand name or a general promise about enterprise security. Compare the terms and controls that apply to the organization’s actual plan, configuration, and use case. Vendor documentation describes available capabilities; it is not independent validation that a particular deployment is configured correctly.
| What to check | Questions for procurement and security |
|---|---|
| Training and data use | Are prompts and outputs used to train or improve models? Which terms govern this account and service? |
| Retention and deletion | What is retained, for how long, and how can the organization request deletion? Are special retention controls available only to eligible customers? |
| Identity and administration | Can administrators manage accounts and access centrally? Are identity integration and access policies suitable for the organization? |
| Processing location | Where may data be processed, and are region choices available for this product and plan? |
| Source-data protections | Can the service respect connected-source permissions, sensitivity labels, and data-loss-prevention controls in the intended configuration? |
| Audit and response | What audit records, retention options, legal-hold capabilities, and incident-response support are available? |
| Agents and suppliers | What separate terms, privacy notices, security documentation, and service commitments apply to agents or integrations? |
| Operational fit | What administrative effort and cost are required to maintain the controls? |
For example, OpenAI says business data is not used for training by default and describes encryption and retention controls for qualifying organizations; some retention controls depend on eligibility. Microsoft describes enterprise data protection for Copilot prompts and responses, while noting that controls vary by subscription. These are vendor statements, not guarantees that every plan or configuration has the same protections. Review the current product documentation, contract, and settings before approving a workflow.
Rank #3
- Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
- USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
- FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
- Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
- Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.
Fix access to connected company data
An AI assistant connected to company content may make information easier to find for people who already have permission to access it. That can amplify existing oversharing: the problem may be a broadly accessible file or repository, not a prompt sent to an AI system. Encryption does not correct excessive permissions.
- Review access to SharePoint sites, shared drives, code repositories, and other sources before enabling AI retrieval.
- Remove stale accounts and unnecessary group or individual access; grant only what each person needs.
- Apply sensitivity labels and data-loss-prevention or information-protection controls where the service and configuration support them.
- Test representative user accounts and scenarios to confirm that retrieval follows intended access boundaries.
Microsoft’s Purview documentation describes AI discovery and governance across supported Copilot experiences, connected enterprise AI apps, and AI apps detected through browser activity. Coverage depends on configuration and supported capabilities, so confirm what is actually visible and controlled in the organization’s environment. Microsoft also describes the use of existing permissions and labels in supported Purview scenarios.
Protect employee accounts and devices
Use managed company accounts for approved AI services and secure them as carefully as other systems that handle business information. Microsoft Entra guidance recommends phishing-resistant multifactor authentication for access to generative AI apps, device-compliance requirements, identity lifecycle automation, and additional protections for privileged users.
Rank #4
- FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
- Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
- USB TYPE C Connectivity & DONGLE Design: Designed for PCs, Macs, laptops, iPhones, and Android devices that utilize a USB-C port. Plug and stay, or carry it on a keychain. (Item Size: 0.73 x 0.60 x 0.30 inches)
- Enhanced MFA (FIDO2 & TOTP/HOTP): Strengthen your security with flexible options. Use the Manager App to access TOTP/HOTP features for accounts that do not yet support FIDO2.
- Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID. NFC functionality is not supported.
- Require multifactor authentication and use phishing-resistant methods where supported by the identity provider and policy.
- Apply conditional-access rules appropriate to the risk, including device-compliance requirements when feasible.
- Automate account provisioning and removal so access changes when employees join, change roles, or leave.
- Give administrators and other privileged users additional safeguards and restrict their access to what their roles require.
A FIDO2 security key is one possible physical method for phishing-resistant authentication, but compatibility depends on the organization’s identity provider and configuration.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Train staff, monitor activity, and prepare to respond
Training should show employees how to use approved tools safely, not just warn them that AI can create risk. Include examples of acceptable prompts, prohibited inputs, output-review expectations, and the exact way to report a suspected disclosure. NIST’s profile includes education, monitoring, and incident response among relevant generative AI risk-management practices.
Monitor access and relevant audit records for unusual use, configuration changes, and changes to permissions that could expose more information than intended. Microsoft recommends monitoring unusual activity and configuration changes. Set a response path before an incident occurs:
Best Value
- FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
- Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
- Universal Connectivity (USB-C, USB-A, & NFC): Designed for PCs, Macs, iPhones, and Android. For mobile use, simply unfold the key, align it with your phone’s NFC antenna, and hold for a few seconds to authenticate.
- Enhanced MFA (FIDO2 & TOTP/HOTP): Strengthen your security with flexible options. Use the Manager App to access TOTP/HOTP features for accounts that do not yet support FIDO2.
- Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID. NFC is supported only through mobile authentication, Not MacOS/windows.
- Assign a team or role to receive and triage reports.
- Preserve relevant records and determine what data, service, account, and recipients may have been involved.
- Contain the exposure where possible, such as revoking access or disabling an integration while it is assessed.
- Involve privacy, legal, security, and customer-response teams as appropriate, and follow applicable notification processes.
- Record the cause and update permissions, policy, training, or technical controls to reduce the chance of recurrence.
Assess each agent and integration separately
An agent connected to a host application may have separate data-handling terms. Microsoft explicitly advises users of agents in Copilot to check each agent’s privacy statement and terms of use to understand how it handles organizational data. Apply the same supplier due diligence to external AI services and integrations: review relevant security documentation, transparency information, service terms, and assurance material rather than assuming the host product’s protections automatically cover them.
Turn the policy into a recurring review
AI products, plan features, eligibility, and settings change. Assign owners to periodically recheck approved services, contracts, connected agents, permissions, and monitoring coverage. Reassess sooner when a product changes its terms or configuration, a new integration is introduced, or a use case begins handling a different class of information.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




