Sensitive data never reaches the prompt.
Tap a bar to see what was caught.
Closehold finds, removes, or pseudonymizes sensitive data the moment it heads to an AI. In the browser, on the desktop, and in your own systems. The secret is never stored.
Draft a follow-up to [EMAIL_1] about the overdue invoice, account SSN [SSN_REDACTED].
Your people paste customer records, source code, and credentials into AI tools every day. Your DLP never sees it, and you have no record it happened.
A payload-free audit trail of every crossing.
One policy engine across every surface.
Proof you can hand to auditors without exposing the data.
One engine on your machine. A browser prompt, a file, or an internal API call all get byte-identical decisions, with no cloud round trip to detect.
Sees through obfuscation and encoding tricks before anything is checked.
Validators, checksums & AI models spot names, emails, SSNs, cards, API keys & secrets, even your own confidential terms.
Scores severity and flags high-risk combinations: name + SSN = critical.
Removes the value for good, or swaps it for a token that comes back. Either way the prompt still works and the message still sends.
Logs the crossing as proof: the shape and flow, never the value.
Draft a follow-up to [EMAIL_1] about the overdue invoice, account SSN [SSN_REDACTED].
The prompt still works. The secret never left.
The prompt going out, the file attached, and the payload-free record both leave behind.
Tap a bar to see what was caught.
| Employee | Base salary | SSN | Work auth |
|---|---|---|---|
| Marcus Webb | $184,000 | 512-84-9173 | H-1B |
| Dana Ortiz | $171,500 | 447-19-6620 | U.S. citizen |
| Priya Nair | $199,000 | 623-40-1187 | L-2 EAD |
| Employee | Base salary | SSN | Work auth |
|---|---|---|---|
| [PERSON_1] | [COMPENSATION_1] | [SSN_REDACTED] | H-1B |
| [PERSON_3] | [COMPENSATION_2] | [SSN_REDACTED] | U.S. citizen |
| [PERSON_4] | [COMPENSATION_3] | [SSN_REDACTED] | L-2 EAD |
22neutralized before the AI ever saw them
Redacted in place, so the file keeps its format, its structure, and everything in it that is not sensitive.
Every crossing leaves a record of its shape and flow. The entity type, the action taken, the token reference. Never the value.
"entity": "us_ssn",
"action": "redact",
"raw_value_stored": false
Which AI tools your people reach, from which apps. Observed, never decrypted. No content, ever.
| ChatGPT | 1,204 | protected |
|---|---|---|
| Claude | 612 | protected |
| Microsoft 365 Copilot | 438 | protected |
| Gemini | 295 | protected |
| Perplexity | 168 | protected |
Start with one team and a browser extension. Add surfaces as you go. The same policy runs on every one.
See what it runs on →Detection runs entirely on your machine. We store salted hashes and token references, never the value itself.
Read the full trust center →Detection needs no network. Prompts never leave the machine to be scanned.
Audit and lineage carry salted hashes and token references. Nothing else.
The vault and your term lists are AES-256-GCM, keyed to your OS keychain.
Same input, same policy, same result, on every surface.
No. Detection runs locally on each machine, so prompts are scanned in place and never sent to us. Optional cloud features receive counts and classifications only.
Protection adds well under a quarter-second on an ordinary laptop CPU (measured, not quoted), and it happens on-device, so there's no cloud round-trip in the critical path.
Policies are boundary-aware and tunable: a value allowed for an internal model can be pseudonymized for a public one. Names, addresses and contact details are pseudonymized reversibly, so a cautious call on one of those never destroys the original.
Yes. Pseudonymized values map to stable tokens and can be restored for trusted destinations. Credentials, SSNs and card numbers are not tokenized at all: they are removed for good, nothing is stored to restore them from, and the message still sends.
Yes. The gateway is self-hostable and OpenAI/Anthropic-compatible, and the engine runs entirely on your infrastructure. There is no required cloud dependency for protection.
24 AI sites in the browser, including ChatGPT, Claude, Gemini and Microsoft Copilot with replies restored end to end. 10 native desktop apps, including Microsoft 365 Copilot across Word, Excel, PowerPoint, Outlook and Teams, with no admin rights. Perplexity through its desktop app, Claude Code and any OpenAI or Anthropic compatible endpoint for developers. Every surface carries its own grade in the coverage matrix.
You cannot train your way out of a distracted paste.
No raw data leaves your machine. Ever.