AI tools leak your data. Shield catches it before it leaves your machine.
Every time you use Claude Code, Cursor, Copilot, or any AI tool, sensitive information can slip into the prompt. API keys, .env files, database credentials, customer records, sent to external servers you don't control. Shield installs on your machine and catches it automatically, on every call, without anyone remembering to sanitise a prompt.
Detection is pattern-based and scoped to the filter packs you run: a tight net, tuned to your data, not a guarantee that nothing ever slips. What it matches is replaced before the request leaves, and every match is logged as evidence.
No cloud service. One install, every AI tool on that machine is protected. Subscribe to the app from $49.99/mo, or own the source outright with a scoped engagement.
Free 7-day trial. No card, no signupEvery tier, every feature. The download is the trial.
Your team uses AI every day, ChatGPT for drafting, Copilot for coding, Claude for analysis, Notion AI for notes. And every day someone accidentally includes customer data, financials, or internal documents in a prompt. The AI provider stores it. Your compliance team can't see it. Your security team can't stop it.
Asking your team to manually sanitize every prompt is asking them to stop shipping.
We work with your team, whether that's your CTO, compliance officer, IT director, or department head. If your organization is adopting AI and worried about what's leaking, we deploy with whoever owns that risk. Engineering handles the technical install; leadership gets the compliance evidence. Everyone stays in their lane.
[REDACTED:PHI_NAME_001]
[REDACTED:JWT_001]
...sanitized payload
Redacted tokens. Sanitized payloads. Matched PHI never sent in the clear.
Sarah Johnson
eyJhbGci...full_token
...full response
Real values. Full responses. Nothing hidden from the developer.
Belt and suspenders, plugin catches obvious leaks at the agent-loop boundary, gateway scrubs the wire. If one layer misses, the other catches.
Two ways to run Shield
Own the source outright, or subscribe to the app. Same binary either way.
Self-serve: download, subscribe, done. No engagement, no scoping call. Every tier runs free for 7 days. No card, no signup.
Anonymous download. 7-day full-feature trial, no card, no signup. The trial clock runs on your machine; the only server record is a deletable anonymous usage counter.
- ✓Tokenizing proxy for every covered tool
- ✓Secrets & PII filter packs
- ✓Codex, OpenAI, Hermes, Claude Code & CLI coverage
- ✓Local tamper-evident audit log
- ✓Anonymous trial: no account, no card
- ✓Everything in Core
- ✓Audit dashboard with per-tool visibility
- ✓Custom filter packs for your domain
- ✓Evidence export for SOC 2 / HIPAA programs
- ✓License panel with self-serve data deletion
- ✓Everything in Pro
- ✓IQ beta: AI-assisted detection filters
- ✓Managed configs (MDM) for fleet rollout
- ✓Team enforcement policies
- ✓Priority support
The Platform · what extends the app
Shield ships as one binary. The platform is what that binary grows into as you move up the tiers, Go interfaces, not registries. Compile-time safety, not runtime plugins.
Your data never touches our infrastructure
The gateway runs on your network. The audit log writes to your S3 with your encryption keys under your retention policy. There is no Shield cloud. There is no telemetry. Audit teams query their existing pipeline.
Let’s Build.
Submit your technical details and we will formulate a production scope, architectural dependencies, and exact model selection profiles.
Frequently Asked Questions
Everything you need to know about Shield