IP Library › Granted Patent US 12,587,529
Granted Patent B2
US 12,587,529 · App. 18/829,021 · Granted Mar 24, 2026

Methods and systems for security enhancement in artificial intelligence model interactions via automated injection and proxy server implementation

Inventors: Mathew Solnik (Dallas, TX); Samuel Kimama (Daly City, CA); Gil Spencer (Incline Village, NV); Jeffrey Dean Walter (San Antonio, TX)
Assignee: WitnessAI, Inc.
H04L63/10H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,587,529
App. No.
18/829,021
Filed
Sep 9, 2024
Granted
Mar 24, 2026
Kind
B2
Art Unit
2408
USPC
726/30
Abstract

The present technology relates to a computer-implemented method for enhancing enterprise-wide security when using Artificial intelligence (AI) models. Embodiments involve a JavaScript injection process facilitated by a proxy server. This process does not require manual installation as it is automatically injected during operation. The JavaScript injection process operates by intercepting unsecured AI input and output data provided by users interacting with AI websites. The input and output data are sent to a security Application Programming Interface (API) which applies an enterprise security policy to the data in real-time, thereby transforming unsecured input and output into secure data. Embodiments provide a robust framework for safe interaction with Artificial intelligence models while mitigating the risks associated with the transmission of sensitive information over the internet.

Claims (39)

1 . A computer-implemented method for securely using Artificial Intelligence (AI) models, the computer-implemented method comprising:

automatically injecting a security program, using a proxy server, the automatically injecting the security program embedding code into HTML content of a website enabling security for using Artificial Intelligence (AI) models and the security program being automatically injected and not requiring manual installation, the security program comprising:

intercepting unsecure AI input data from a user inputting data into an input field of the website;

sending the unsecure AI input data to a security Application Programming Interface (API), the security Application Programming Interface (API) enabling enforcing of an AI model input enterprise policy, the enforcing of the AI model input enterprise policy transforming the unsecure AI input data to secure AI input data by modifying the unsecure AI input data in real time;

intercepting unsecure AI output data in response to the secure AI input data being sent to a server of the website; and

sending the unsecure AI output data to the security Application Programming Interface (API), the security Application Programming Interface (API) enabling enforcing of an AI model output enterprise policy, the enforcing of the AI model output enterprise policy transforming the unsecure AI output data to secure AI output data by modifying the unsecure AI output data in real time.

2 . The computer-implemented method of claim 1 , wherein the modifying the unsecure AI input data in real time uses a hook procedure, the hook procedure intercepting an API call and altering the unsecure AI input data.

3 . The computer-implemented method of claim 1 , wherein the modifying the unsecure AI output data in real time uses a hook procedure, the hook procedure intercepting an API call and altering the unsecure AI output data.

4 . The computer-implemented method of claim 1 ,

wherein the modifying the unsecure AI input data in real time uses a hidden overlay, the hidden overlay being above a content layer of the website; and

further comprising displaying the secure AI input data to the user using the input field of the website and the hidden overlay.

5 . The computer-implemented method of claim 4 , wherein the modifying the unsecure AI input data in real time comprises redacting personal identifiable information (PII) according to the AI model input enterprise policy.

6 . The computer-implemented method of claim 1 ,

wherein the modifying the unsecure AI output data in real time uses a hidden underlay, the hidden underlay being below a content layer of the website; and

further comprising displaying the secure AI output data to the user using an output field of the website and the hidden underlay.

7 . The computer-implemented method of claim 6 , wherein the modifying the unsecure AI output data in real time comprises redacting AI output data according to the AI model output enterprise policy.

8 . The computer-implemented method of claim 1 , wherein the security program is a JavaScript injection process, the JavaScript injection process being live, in real time.

9 . The computer-implemented method of claim 1 , further comprising dynamically discovering a configuration for each website including:

comparing a website configuration to a prime library database; and

selecting the website configuration based on the comparing.

10 . The computer-implemented method of claim 1 , wherein the proxy server is configured to intercept and modify network traffic between the user and the server of the website.

11 . The computer-implemented method of claim 1 , wherein the security Application Programming Interface (API) is configured to audit the unsecure AI input data and the unsecure AI output data for compliance with enterprise security policies.

12 . The computer-implemented method of claim 1 , wherein the security program is configured to be updated automatically without user intervention.

13 . The computer-implemented method of claim 1 , wherein the proxy server is configured to log all interactions between the user and the server of the website for security auditing purposes.

14 . The computer-implemented method of claim 1 , wherein the security Application Programming Interface (API) is configured to detect and block malicious activities in real time.

15 . The computer-implemented method of claim 1 , wherein the security program is configured to provide real-time alerts to the user regarding potential security threats.

16 . The computer-implemented method of claim 1 , wherein the security Application Programming Interface (API) is configured to generate reports on a security status of AI input data and AI output data.

17 . The computer-implemented method of claim 1 , wherein the proxy server is configured to provide load balancing for handling multiple user requests simultaneously.

18 . The computer-implemented method of claim 1 , wherein the security Application Programming Interface (API) is configured to perform real-time data analysis for detecting anomalies in AI input data and AI output data.

19 . The computer-implemented method of claim 1 , wherein the security Application Programming Interface (API) is configured to provide real-time feedback to the user regarding a security status of AI input data and AI output data.

20 . The computer-implemented method of claim 1 , wherein the website is an Artificial Intelligence (AI) website.

21 . The computer-implemented method of claim 1 , wherein the modifying the unsecure AI input data in real time uses a hook procedure, the hook procedure intercepting an API call and altering the unsecure AI input data.

22 . The computer-implemented method of claim 1 , wherein the modifying the unsecure AI output data in real time uses a hook procedure, the hook procedure intercepting an API call and altering the unsecure AI output data.

23 . A computer-implemented method for securely using Artificial Intelligence (AI) models, the computer-implemented method comprising:

automatically injecting a JavaScript injection process, using a proxy server, the JavaScript injection process enabling enterprise-wide security for using Artificial Intelligence (AI) models and the JavaScript injection process being automatically injected and not requiring manual installation, the JavaScript injection process comprising:

intercepting unsecure AI input data, using the proxy server, from a user inputting data into an input field of an Artificial Intelligence (AI) website;

sending the unsecure AI input data to a security Application Programming Interface (API), the security Application Programming Interface (API) enabling enforcing of an AI input enterprise policy, the enforcing of the AI input enterprise policy transforming the unsecure AI input data to secure AI input data by modifying the unsecure AI input data in real time;

intercepting unsecure AI output data, using the proxy server, in response to the secure AI input data being sent to a server of the Artificial Intelligence (AI) website; and

sending the unsecure AI output data to the security Application Programming Interface (API), the security Application Programming Interface (API) enabling enforcing of an AI output enterprise policy, the enforcing of the AI output enterprise policy transforming the unsecure AI output data to secure AI output data by modifying the unsecure AI output data in real time.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 29, 2025
From: WALTER, JEFFREY DEAN
To: WITNESSAI, INC.
Reel/Frame 071871/0123 →
CORRECTIVE ASSIGNMENT TO CORRECT THE MISSPELLED ASSIGNEE NAME PREVIOUSLY RECORDED ON REEL 68575 FRAME 133. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jul 29, 2025
From: SOLNIK, MATHEW; KIMAMA, SAMUEL; SPENCER, GIL
To: WITNESSAI, INC.
Reel/Frame 072276/0587 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 12, 2024
From: SOLNIK, MATHEW; KIMAMA, SAMUEL; SPENCER, GIL
To: WITNESS AI, INC.
Reel/Frame 068575/0133 →
Continuity (1)
Related Publication 20260075055A1 · Mar 12, 2026
References Cited (23)
US 10728117B1 · Sharma · 2020 [cited by examiner]
US 12045610B1 · Myers et al. · 2024 [cited by applicant]
US 20070289010A1 · Thomas et al. · 2007 [cited by applicant]
US 20140123325A1 · Jung et al. · 2014 [cited by applicant]
US 20150381649A1 · Schultz et al. · 2015 [cited by applicant]
US 20170214708A1 · Gukai et al. · 2017 [cited by applicant]
US 20180248893A1 · Israel et al. · 2018 [cited by applicant]
US 20180367561A1 · Givental et al. · 2018 [cited by applicant]
US 20200372075A1 · Rogynskyy et al. · 2020 [cited by applicant]
US 20230084202A1 · Patil et al. · 2023 [cited by applicant]
US 20230370495A1 · Desai et al. · 2023 [cited by applicant]
US 20230418943A1 · Han et al. · 2023 [cited by applicant]
US 20240022603A1 · Melson et al. · 2024 [cited by applicant]
US 20240205237A1 · Tormasov et al. · 2024 [cited by applicant]
US 20240394400A1 · Smith · 2024 [cited by applicant]
US 20250005060A1 · Phiri et al. · 2025 [cited by applicant]
US 20250112963A1 · Kfir · 2025 [cited by examiner]
US 20250139367A1 · Manandise et al. · 2025 [cited by applicant]
US 20250148308A1 · Vinay et al. · 2025 [cited by applicant]
US 20250232190A1 · Baughman et al. · 2025 [cited by applicant]
US 20250267171A1 · Sharma et al. · 2025 [cited by applicant]
US 20250284805A1 · Hen et al. · 2025 [cited by applicant]
US 20250307418A1 · Spencer et al. · 2025 [cited by applicant]
Cited By (1)
US 12,675,579