- Prompt text and uploaded files, to detect sensitive data
- Non-sensitive metadata (surface, destination, app hint)
- Salted, one-way hashes and stable token references
- Policy decisions and the action taken (redact / pseudonymize / generalize)
Security you can verify, not just trust.
Closehold is built for the most sensitive data in your company. The whole design rests on one idea: we protect your data by never holding it. Here's exactly how that works.
Local-first
Core detection runs on each machine. Prompts and files are scanned in place.
Never stores raw values
The sensitive value is never written to a log, an audit event, or a lineage edge.
Encrypted at rest
Anything persisted is AES-GCM encrypted, backed by the OS keychain.
Deterministic
The same input and policy always produce the same result, provable from the trail.
What we process, and what we never touch.
- The raw sensitive value, ever, by default
- Your prompts, sent somewhere to be scanned
- Plaintext secrets in logs, audit events, or lineage
- Anything to a third party without your explicit configuration
Your data stays in your environment.
Detection, classification, and transformation all happen on the device or in your own infrastructure. There is no required cloud dependency for protection.
On-device & self-hosted
The browser extension hands prompts to the protection engine running locally on your machine; the extension itself holds no detection logic, by design. The desktop app hosts that same local engine; the gateway is self-hostable and OpenAI/Anthropic-compatible. Nothing sensitive leaves the boundary you control.
Optional cloud, payload-free
If you turn on hosted features (like a shared data-flow graph), they receive only de-identified signal (classifications, counts, and hashes), never raw values.
What's covered.
Protection in the browser and on the desktop, source by source.
| In the browser | Covered |
|---|---|
| ChatGPT | |
| Claude | |
| Gemini | |
| Microsoft Copilot | |
| DuckDuckGo AI | |
| Gemini AI Mode | |
| Grok | |
| DeepSeek | |
| Mistral | |
| Meta AI | |
| Poe | |
| Google AI Studio | |
| HuggingChat | |
| Cohere | |
| Replit | |
| Groq | |
| OpenRouter | |
| Pi | |
| Qwen | |
| Kimi | |
| Phind | |
| Reka | |
| Character.AI | |
| You.com | |
| File uploads (docx, xlsx, pptx, pdf, csv, txt) |
| On the desktop | Covered |
|---|---|
| ChatGPT | |
| Claude | |
| Perplexity | |
| Microsoft Copilot | |
| M365 Copilot | |
| Copilot in Word | |
| Copilot in Excel | |
| Copilot in PowerPoint | |
| Copilot in Outlook | |
| Copilot in Teams | |
| OpenAI API | |
| Anthropic API | |
| Claude Code | |
| Cursor | |
| VS Code + GitHub Copilot | |
| Server-side AI inside SaaS apps (e.g. Notion AI) |
Not listed means not covered. Native mobile apps are out of scope today.
Built to make compliance easier.
Never storing the raw value, and keeping processing local, removes the riskiest part of the data-handling equation.
SOC 2 Type II Coming soon
Formal attestation is underway. A signed DPA is available today.
GDPR & CCPA
Local processing and never storing raw values keeps sensitive data out of scope.
DPA on request
A data-processing agreement, or a completed security questionnaire.
Reviewing Closehold for your organization?
Bring your security questions to a 20-minute walkthrough; we'll show you exactly what crosses the boundary and what never does.
No raw data leaves your machine. Ever.