For IT & security teams

Know what's going into AI —
without reading anyone's prompts.

A managed browser extension that blocks unapproved AI tools and tells you which categories of sensitive data are leaving: API keys, card numbers, health identifiers, source code. Classification happens on each device. The prompt itself never reaches us, and never reaches you.

From $8 per user / month · Chrome and Edge · Onboarding a first group of teams

You have an AI policy. You have no idea if it's followed.

A policy document tells people what they should do. It does not tell you that someone pasted a customer list into a free chatbot on Tuesday, or that half the engineering team is using a tool nobody has assessed. Most organisations discover their actual AI usage during an incident.

01

The tools change weekly

A blocklist written this quarter is stale by the next. New AI surfaces appear faster than anyone can review them.

02

The risk isn't the tool, it's the paste

An approved tool used carelessly leaks more than an unapproved one used sensibly. What matters is what goes into the box.

03

Monitoring usually means surveillance

Most answers to this involve collecting what employees type. That creates a new liability and a staff-relations problem.

Prompt text never leaves the device.

Detection runs in the browser. Only category names and counts are sent — never a fragment of what was typed. This is what a report actually contains:

What we receive

{ "tool": "chatgpt.com", "at": "2026-07-27T14:02:11Z", "categories": [{ "id": "credential.api_key", "count": 1 }], "severity": "critical", "action": "blocked", "user": "sam@yourcompany.com" }

No prompt. No excerpt. No "just the first 100 characters". Three independent mechanisms enforce it:

  • The classifier has no code path that returns matched text
  • The extension strips text-like fields before anything is queued
  • The server rejects the entire batch if a report carries prose, and logs it

The third exists because the first two run in software on your machines. If a future version ever tried to send prompts, the server refuses them.

A tool that collected prompts would be storing the exact data it was bought to protect — and becoming the breach it was meant to prevent. That is why this is the first thing on the page rather than a line in the privacy policy.

Block, warn, or watch — your call.

Enforces your approved list

Unapproved AI sites are blocked at the browser, with a page offering "request this tool" that files straight into your approval queue. The point is to route people into the process, not leave them at a dead end.

Warns before a bad paste

When something sensitive is detected, the person sees what was found and why — before it sends, in Block mode. Most leaks are carelessness, and a warning at the right moment prevents them.

Reports what's actually happening

A console with daily and monthly views: which tools, which data categories, who, and what was blocked. Full CSV export. A monthly digest lands in your inbox so nobody has to remember to log in.

What it can't do.

Every tool in this category has these limits. Most vendors leave you to discover them after signing.

Desktop apps
Not covered. A browser extension governs the browser — it cannot see a native app, a phone, or a direct API call. The console exports your blocklist as a domain list, hosts file and Chrome Enterprise policy so you can block those at the network and device layer. Those stop connections but cannot inspect content, so no category reporting comes from them.
Browsers
Chrome and Edge. No Firefox or Safari build.
Attribution
User and device are self-reported by the managed browser. The console flags one identity appearing from implausibly many devices, which is what a shared credential looks like — but this is attributed usage telemetry, not a forensic audit trail. If you need a record that survives a motivated insider, that is the Approval Tracker's job, not this one.
Site changes
AI sites redesign constantly. Detection uses per-site rules with a generic fallback, which keeps it working between breakages — but it needs maintenance, and that is part of what you are paying for.

Force-installed, or it isn't a control.

It installs through Chrome Enterprise policy via Google Workspace or Microsoft Intune, which makes it non-removable by the user. That is the only deployment path we support — an extension someone can uninstall is theatre. Rollout is an afternoon, and we recommend starting in Warn mode so you can see the picture before you start blocking.

Employees are told

A permanent badge on every AI site states that monitoring is active and what is and is not recorded. It is not configurable — written notice of electronic monitoring is a legal requirement in several jurisdictions, and a tool discovered by accident is one people route around.

The notice comes with it

We generate the written monitoring notice for your jurisdictions from the same engine behind our policy generator, so the compliance step is a deliverable rather than your problem.

It fails open

If our server is unreachable, the last known policy stays in force rather than the browser breaking. A security tool that stops people working gets uninstalled, and then protects nobody.

Per user, per month.

Billed monthly, cancel any time. Volume pricing below 100 seats is the same — we would rather you started small.

Standard
$8/user/mo
Up to 100 users
  • Blocking and warning
  • All sensitive-data categories
  • Admin console with CSV export
  • Monthly digest
  • Network/MDM blocklist export
Request access
With the Tracker
Bundle
Enforcement + approval record
  • Everything in Plus
  • Blocked tools file straight into the approval queue
  • Approved inventory drives the allowlist
  • One conversation, one invoice
Talk to us

Covered by the same 30-day money-back guarantee as our other plans
The bundle is the real product: the Tracker records what was approved, the Guard enforces it.

We're onboarding a first group of teams.

This is new and we are being honest about that: it is built and working, it is not yet running in dozens of companies. We are starting small so we can get the detection right against real traffic and cover the browsers and jurisdictions you actually have. Tell us your situation and we will reply personally, usually within two business days.

What teams ask first

No, and it is not possible to. Classification runs entirely in the browser on the employee's own machine, and only category names and counts are transmitted — "API key, 1", "email address, 3". The extension has no code path that returns matched text, the service worker strips text-like fields before queueing, and the server rejects any report carrying prose. A tool that collected prompts would be storing the very data it was bought to protect.
No. A browser extension governs the browser — it cannot see a native desktop app, a phone, or a direct API call, and nothing browser-based can. The console exports your blocklist as a domain list, a hosts file and a Chrome Enterprise policy so you can block those at the network and device layer. Those block connections but cannot inspect content, so no category reporting comes from them. We would rather say this now than have your security team find it in week two.
Yes, deliberately. A permanent badge appears on every AI site stating that monitoring is active and explaining exactly what is and is not recorded. It is not configurable. Written notice of electronic monitoring is a legal requirement in several jurisdictions — Connecticut and New York among them — and separately, a tool people discover by accident is a tool they route around.
Not when it is deployed properly. It installs through Chrome Enterprise policy via Google Workspace or Microsoft Intune, which makes it non-removable by the user. An extension someone can uninstall is not a control, so that deployment path is the only one we support.
Purview does inline DLP in Edge, and if you are already on the right M365 tier you may have a version of this. Three differences: we cover Chrome and every AI surface rather than Edge-first, deployment is an afternoon rather than a Purview rollout, and — the one that matters — we connect enforcement to an approval workflow and audit trail. Purview blocks. We can show an auditor who approved what, when, and on what basis.
Built and working, not yet widely deployed. We are onboarding a first group of teams now. If being early is a problem for you, that is a fair reason to wait — and we would rather you did than be disappointed.

Find out what's actually happening.

Two business days to a reply, and a real conversation about your environment.

Request early access