Your Clients' Data Stays on
Your Machines.
Traders, analysts, and customer service teams are using ChatGPT, Claude, and Copilot every day — pasting account numbers, portfolio positions, and customer SSNs into prompts. Shield sits on your firm's machines and stops financial data from ever reaching an external AI model. No cloud. No vendor access. Just a local proxy that redacts sensitive data before it leaves your network.
Any organization handling cardholder data must comply with PCI DSS 4.0.1 requirements. Sending card numbers, CVVs, or full magnetic stripe data to an external AI model creates an immediate compliance gap — cardholder data is leaving your controlled environment.
Financial services firms must navigate PCI DSS, GLBA, SOX, and state-level regulations like NYDFS Part 500. Each framework imposes data protection requirements that extend to how employees use AI tools with customer and proprietary data.
Shield runs locally on your machines — no cloud processing, no vendor data access. Customer records, trading algorithms, and internal models never reach external AI providers. The redaction mapping stays on your machine.
Financial data exposure through AI is a regulatory risk
When an employee pastes a customer's SSN, account number, or portfolio position into an AI prompt, that data leaves your controlled environment and arrives at an external provider's servers. Under PCI DSS, GLBA, SOX, and NYDFS Part 500, financial institutions are responsible for protecting customer nonpublic information — even when employees use third-party tools. Shield eliminates this vector entirely: sensitive financial data never leaves your network, so it never creates a compliance exposure.
Interactive Demo
What Financial Data Looks Like in AI Prompts
Three real-world scenarios where financial services employees send sensitive data to AI models. Click each tab to see the raw prompt with identifiable information — and how Shield redacts it before it leaves your network.
Compliance
How Shield Maps to Financial Regulations
Financial services firms operate under multiple overlapping regulatory frameworks. Shield's local proxy architecture provides a single technical control that supports compliance across PCI DSS, GLBA, SOX, and NYDFS Part 500 — without adding cloud dependencies to your audit scope.
| Framework | Scope | Key Requirement | How Shield Helps |
|---|---|---|---|
| PCI DSS 4.0.1 | Payment card data | Req. 3 — Protect stored cardholder data; Req. 4 — Encrypt transmission across open networks | Redacts PANs, CVVs, and track data before they reach external AI providers. Cardholder data never transmits across open networks in cleartext. |
| GLBA Safeguards Rule | Customer nonpublic personal information (NPI) | Design and implement safeguards to protect customer information against unauthorized access | Automatic detection and redaction of NPI — names, account numbers, SSNs, income data — before prompts leave your network. Acts as a technical compensating control. |
| Sarbanes-Oxley (SOX) | Financial reporting integrity | Section 404 — Management assessment of internal controls over financial reporting | Prevents accidental exposure of financial data, earnings projections, and material nonpublic information through AI prompts. Audit logging supports control documentation. |
| NYDFS Part 500 | Cybersecurity program for financial services | 500.11 — Third-party service provider security policy; 500.07 — Access controls | Ensures sensitive nonpublic information is redacted before transmission to AI providers (third-party services). Audit trail supports 500.06 documentation requirements. |
Architecture
Financial Data Never Leaves Your Network
Shield runs as a local proxy on your firm's machines. When a trader, analyst, or support agent sends a prompt to an AI model, Shield intercepts it — redacts all sensitive financial data — and only then forwards the clean prompt to the external LLM. The redaction mapping stays on your machine, inside your network boundary.
Local Installation
Install Shield on any Mac, Windows, or Linux machine. No cloud infrastructure, no vendor data access, no data leaves your network.
One Environment Variable
Set SHIELD_PROXY_URL and every AI call from that machine flows through Shield automatically. Zero code changes to your existing tools — Bloomberg, CRM, or internal platforms.
Full Audit Trail
Every redaction event is logged with a cryptographic hash. Prove to auditors and regulators exactly what data was caught and when — with tamper-evident integrity.
Configurable Policies
Choose which data categories to redact — PII, PCI, proprietary. Add custom patterns for your firm's internal account numbering schemes. Run in audit-only mode to validate coverage first.
FAQ
Common Questions
Ready to Lock Down Your Financial Data?
Shield installs in minutes. Your trading algorithms, client portfolios, and customer PII stay on your machines — where regulators and your compliance team expect them to be.