Sensitive data, protected before AI.

Closehold finds, removes, or pseudonymizes sensitive data the moment it heads to an AI. In the browser, on the desktop, and in your own systems. The secret is never stored.

Draft a follow-up to [EMAIL_1] about the overdue invoice, account SSN [SSN_REDACTED].

chat.openai.com protected
What leaks today

Every prompt is an uncontrolled data export.

Your people paste customer records, source code, and credentials into AI tools every day. Your DLP never sees it, and you have no record it happened.

And it lands on three desks.

The CISO

Prove control, not just policy.

A payload-free audit trail of every crossing.

Security engineering

Deploy once, govern everywhere.

One policy engine across every surface.

Compliance

Evidence on demand.

Proof you can hand to auditors without exposing the data.

One engine. Every surface. One set of rules.

One engine on your machine. A browser prompt, a file, or an internal API call all get byte-identical decisions, with no cloud round trip to detect.

  1. 01Normalize

    Sees through obfuscation and encoding tricks before anything is checked.

  2. 02Detect

    Validators, checksums & AI models spot names, emails, SSNs, cards, API keys & secrets, even your own confidential terms.

  3. 03Classify

    Scores severity and flags high-risk combinations: name + SSN = critical.

  4. 04Protect

    Removes the value for good, or swaps it for a token that comes back. Either way the prompt still works and the message still sends.

  5. 05Record

    Logs the crossing as proof: the shape and flow, never the value.

Where your people work
  • Browser 24 AI sites · Chrome, Edge, Firefox
  • Desktop 10 native AI apps · Microsoft 365 Copilot included
  • Files 6 formats · docx, xlsx, pptx, pdf, csv, txt
  • Internal AI Your own gateway · any OpenAI- or Anthropic-compatible endpoint
CLOSEHOLD on your machine
What the AI receives

Draft a follow-up to [EMAIL_1] about the overdue invoice, account SSN [SSN_REDACTED].

The prompt still works. The secret never left.

One protection, everywhere it matters.

The prompt going out, the file attached, and the payload-free record both leave behind.

PROMPTS

Sensitive data never reaches the prompt.

Email about the invoice, SSN

Tap a bar to see what was caught.

FILES

The whole file goes. The sensitive values don’t.

ExposedThe file, as uploaded
NORTHWIND ROBOTICS, INC. Human Resources · Payroll & Benefits
CONFIDENTIAL
Employee Master RecordExport HR-4417
Contains SSN, banking, payment-card and work-authorization data. Do not share externally.
Personal
Full nameMarcus Webb
Date of birth03/14/1988
Social security no.512-84-9173
Home address4417 Cedar Hollow Ln, Austin, TX 78745
Personal emailm.webb88@gmail.com
Mobile(512) 555-0147
Emergency contactSara Webb
Employee IDNW-2291
Compensation & banking
Base salary$184,000
Card on file (T&E)4539 8842 1109 7365
Bank accountFrost Bank #000148802276
Routing114000093
401(k) accountFidelity Z-4471902
Direct depositActive · 100%
Benefits & work authorization
Work authorizationH-1B · Case WAC-21-55831
Health planPPO Gold · 2 dependents
Team compensation comparison
EmployeeBase salarySSNWork auth
Marcus Webb$184,000512-84-9173H-1B
Dana Ortiz$171,500447-19-6620U.S. citizen
Priya Nair$199,000623-40-1187L-2 EAD
ProtectedSent with Closehold running
NORTHWIND ROBOTICS, INC. Human Resources · Payroll & Benefits
CONFIDENTIAL
Employee Master RecordExport HR-4417
Contains SSN, banking, payment-card and work-authorization data. Do not share externally.
Personal
Full name[PERSON_1]
Date of birth[DOB_1]
Social security no.[SSN_REDACTED]
Home address[ADDRESS_1]
Personal email[EMAIL_1]
Mobile[PHONE_1]
Emergency contact[PERSON_2]
Employee IDNW-2291
Compensation & banking
Base salary[COMPENSATION_1]
Card on file (T&E)[CARD_REDACTED]
Bank account[BANK_ACCOUNT_REDACTED]
Routing[BANK_ACCOUNT_REDACTED]
401(k) account[BANK_ACCOUNT_REDACTED]
Direct depositActive · 100%
Benefits & work authorization
Work authorizationH-1B · Case [NATIONAL_ID_1]
Health planPPO Gold · 2 dependents
Team compensation comparison
EmployeeBase salarySSNWork auth
[PERSON_1][COMPENSATION_1][SSN_REDACTED]H-1B
[PERSON_3][COMPENSATION_2][SSN_REDACTED]U.S. citizen
[PERSON_4][COMPENSATION_3][SSN_REDACTED]L-2 EAD

22neutralized before the AI ever saw them

Redacted in place, so the file keeps its format, its structure, and everything in it that is not sensitive.

PROVENANCE

Proof without the payload.

Every crossing leaves a record of its shape and flow. The entity type, the action taken, the token reference. Never the value.

"entity": "us_ssn",
"action": "redact",
"raw_value_stored": false
OBSERVE

Every AI your organization touches.

Which AI tools your people reach, from which apps. Observed, never decrypted. No content, ever.

Deploy in an afternoon. Scale to the whole org.

Start with one team and a browser extension. Add surfaces as you go. The same policy runs on every one.

See what it runs on →
  1. 1 Install the app the engine runs on your machine
  2. 2 Add the extension it pairs itself
  3. 3 Protected from the first prompt

We protect your data by never holding it.

Detection runs entirely on your machine. We store salted hashes and token references, never the value itself.

Read the full trust center →

Runs locally

Detection needs no network. Prompts never leave the machine to be scanned.

Never stores the value

Audit and lineage carry salted hashes and token references. Nothing else.

Encrypted at rest

The vault and your term lists are AES-256-GCM, keyed to your OS keychain.

Identical everywhere

Same input, same policy, same result, on every surface.

The questions security teams ask first.

Do you see our prompts?

No. Detection runs locally on each machine, so prompts are scanned in place and never sent to us. Optional cloud features receive counts and classifications only.

Will it slow down our AI tools?

Protection adds well under a quarter-second on an ordinary laptop CPU (measured, not quoted), and it happens on-device, so there's no cloud round-trip in the critical path.

What about false positives?

Policies are boundary-aware and tunable: a value allowed for an internal model can be pseudonymized for a public one. Names, addresses and contact details are pseudonymized reversibly, so a cautious call on one of those never destroys the original.

Is pseudonymization reversible?

Yes. Pseudonymized values map to stable tokens and can be restored for trusted destinations. Credentials, SSNs and card numbers are not tokenized at all: they are removed for good, nothing is stored to restore them from, and the message still sends.

Can we self-host?

Yes. The gateway is self-hostable and OpenAI/Anthropic-compatible, and the engine runs entirely on your infrastructure. There is no required cloud dependency for protection.

Which AI tools are covered?

24 AI sites in the browser, including ChatGPT, Claude, Gemini and Microsoft Copilot with replies restored end to end. 10 native desktop apps, including Microsoft 365 Copilot across Word, Excel, PowerPoint, Outlook and Teams, with no admin rights. Perplexity through its desktop app, Claude Code and any OpenAI or Anthropic compatible endpoint for developers. Every surface carries its own grade in the coverage matrix.

Put Closehold between your people and every AI they touch.

You cannot train your way out of a distracted paste.

No raw data leaves your machine. Ever.