API Keys and Secrets Stay
On Your Machine.
Every day, developers paste API keys, database credentials, cloud secrets, and customer tokens into ChatGPT, Claude, and Copilot, without realizing it. Shield sits on your developers' machines and stops secrets from ever reaching an external AI model. No cloud. No vendor access. Just a local proxy that redacts sensitive data before it leaves your network.
Shield for DevTools is a local desktop application that stops API keys, database credentials, JWT tokens, cloud secrets, and customer identifiers from ever leaving your developers' machines, before that data reaches GitHub Copilot, ChatGPT, Claude, or any AI model. It runs on your existing machines, requires no cloud infrastructure, and helps DevTools companies meet SOC 2 and ISO 27001 requirements without changing how engineers use AI coding assistants.
The 2025 Stack Overflow Developer Survey of over 49,000 developers found that 84% are using or planning to use AI tools in their development workflow, up from 76% in 2024. More than half of professional developers use AI tools daily. Every prompt is a potential egress point for API keys, tokens, database credentials, and customer secrets.
Developers pasting config files, .env contents, debug logs, and error traces into AI assistants routinely expose live API keys, database passwords, cloud credentials, and internal infrastructure details. GitHub's secret scanning detected over 39 million secrets in 2024 alone, and AI prompts represent a new, unmonitored exfiltration vector that secret scanners in repos can't catch.
Shield runs locally on your developers' machines, no cloud processing, no vendor data access. API keys, database credentials, JWT tokens, and customer identifiers are redacted before they reach external AI providers. The redaction mapping stays on your machine, inside your organization's network boundary. Your secrets never leave your control.
Secrets in AI prompts are a SOC 2 and ISO 27001 compliance gap
When a developer pastes an API key, database connection string, or customer token into an AI prompt, that data leaves your security boundary and arrives at a third-party provider's servers. Under SOC 2 controls CC6.1 and CC6.6, organizations must implement logical access controls and external boundary protections, and that obligation doesn't disappear just because an engineer is using an AI coding assistant. Shield eliminates this vector entirely: secrets never leave your network, so they never create a compliance exposure.
Interactive Demo
What Secrets Look Like in AI Prompts
Three real-world scenarios where developers and support engineers send live secrets to AI models. Click each tab to see the raw prompt with exposed credentials, and how Shield redacts them before they leave your network.
Compliance
How Shield Maps to DevTools Security Standards
DevTools companies operate under SOC 2, ISO 27001, and OWASP LLM security standards. Shield's local proxy architecture provides a single technical control that supports compliance across all three, without adding cloud dependencies to your data governance scope.
| Framework | Scope | Key Requirement | How Shield Helps |
|---|---|---|---|
| SOC 2 | Service organization controls for DevTools/SaaS companies | CC6.1 and CC6.6 require logical access controls and external boundary protections. Organizations must prevent unauthorized disclosure of sensitive information, including secrets inadvertently sent to external services by employees. | Redacts API keys, tokens, and customer data before prompts reach external AI providers. Audit logs provide cryptographic proof of every redaction event, verifiable by SOC 2 auditors. |
| ISO 27001 | Information security management for technology organizations | Annex A controls A.5.15 (Access Control), A.8.8 (Management of Technical Vulnerabilities), and A.8.12 (Data Leakage Prevention) under ISO 27001:2022 require organizations to prevent unauthorized access and data leakage through technical controls. | Provides a technical control at the network boundary, secrets are intercepted and redacted before leaving the organization's information security perimeter, satisfying the data leakage prevention requirement. |
| OWASP LLM02 | Sensitive Information Disclosure in LLM applications | OWASP Top 10 for LLM Applications (2025) identifies Sensitive Information Disclosure as LLM02, the second most critical risk. Organizations must prevent PII, financial details, health records, confidential business data, security credentials, and legal documents from reaching LLM providers. | Directly addresses OWASP LLM02 by detecting and redacting secrets at the proxy layer, before they reach the LLM. Covers all OWASP-identified categories: PII, credentials, confidential business data, and internal infrastructure details. |
Architecture
Secrets Never Leave Your Developers' Machines
Shield runs as a local proxy on your developers' machines. When an engineer sends a prompt to Copilot, ChatGPT, or Claude, Shield intercepts it, detects and redacts all API keys, credentials, tokens, and internal identifiers, and only then forwards the clean prompt to the external LLM. The redaction mapping stays on your machine, inside your organization's network boundary.
Local Installation
Install Shield on any Mac, Windows, or Linux machine. No cloud infrastructure, no vendor data access, no secrets leave your network.
One Environment Variable
Set SHIELD_PROXY_URL and every AI call from that machine flows through Shield automatically. Zero code changes to your IDE, CLI tools, or CI/CD pipeline.
Tamper-Evident Audit Logs
Every redaction event is logged with a cryptographic hash. Prove to SOC 2 auditors and security teams exactly what secrets were caught and when.
Configurable Policies
Choose which secret types to redact, API keys, DB credentials, cloud secrets. Add custom patterns for your company's internal identifiers. Run in audit-only mode first to see what your team is pasting.
FAQ
Common Questions
Related Articles
Ready to Keep Your Secrets Off AI Servers?
Shield installs in minutes. Your team's API keys, database credentials, and customer tokens stay on your developers' machines, where SOC 2, ISO 27001, and your customers expect them to be.
Last updated: July 16, 2026