
Sensitive prompt and document exposure guard
Reduce sensitive data exposure in employee AI use while keeping the tools employees already use.
- For
- Security, IT and compliance teams in regulated organizations whose employees send prompts and documents to third-party AI tools
- Solves
- Employees paste credentials, personal data and confidential documents into external AI tools, and administrators cannot see what leaves the organization.
- Delivers
- Flagged categories, synthetic replacements and tokenized values with a metadata-only admin view
- Built in
- about 4 weeks of creation time, MVP in 4 days
- Investment
- $12,000 for the MVP, $41,000 for the full product
- Run it
- Inside your business, or as part of your offer to clients
What it does
Reduce sensitive data exposure in employee AI use while keeping the tools employees already use.
- Scan prompts in real time for API keys, credentials and personal data.
- Scan uploaded contracts, spreadsheets and files before submission.
- Process scanned content locally in the browser.
- Report flagged categories to administrators without exposing content.
- Replace sensitive values with synthetic equivalents.
- Preserve original context and structure for the model.
- Reconstitute original data locally in the browser.
- Record prompts sent to third-party models for governance.
- Tokenize PHI, PCI and PII before prompts reach the model.
- Resolve tokens to real values only at execution.
- Hold real values in a secure vault outside logs.
- Record tokens, actions, timestamps and authorization events.
- Log token reveals with separate access control.
- Support existing agent frameworks with minimal integration.
- Compare the reviewed result with the recorded baseline and value assumptions.
- Export a versioned flagged categories, synthetic replacements and tokenized values record with source references and unresolved questions.
Everything these tools do, in one app
- Real-time sensitive data scanning Scans prompts and files as they are entered to detect API keys, credentials, and personal data before submission.Found in Sequirly
- Document upload scanning Checks uploaded contracts, spreadsheets, and other files for sensitive items before they are sent.Found in Sequirly
- Local browser processing Processes scanned content entirely in the browser so raw data never leaves the user's device.Found in Sequirly
- Metadata-only admin dashboard Reports flagged categories to administrators without exposing the actual content of prompts or files.Found in Sequirly
- Synthetic data replacement Replaces sensitive values with synthetic equivalents while preserving the original context and structure for the AI model.Found in PrivacyPal
- Local data reconstitution Restores original data in the browser so users see a natural experience while external services only see synthetic data.Found in PrivacyPal
- Prompt audit logs Records prompts sent to third-party models to provide governance visibility and identify high-risk activity.Found in PrivacyPal, Astra
- Browser extension deployment Installs as a browser extension that operates in real time between the user and the AI model without requiring internal LLM hosting.Found in PrivacyPal, Sequirly
- Pre-prompt tokenization Tokenizes sensitive data such as PHI, PCI, and PII before it reaches the model so raw values are never included in prompts.Found in Astra
- Token resolution at execution Resolves tokens to real values only at the moment of action, with real values held in a secure vault and not written to logs.Found in Astra
- Audit trail without raw data Records tokens, actions, timestamps, and authorization events without storing raw sensitive data.Found in Astra
- Agent framework compatibility Works with existing agent frameworks and requires minimal integration effort, advertised as two lines of code.Found in Astra
- Reveal logging Logs when a token is revealed while keeping the revealed value separate and access-controlled.Found in Astra
What goes in, what comes out
- Prompt samples
- Document types
- Policy categories
- Browser
- Agent configurations
AI drafts, people review. Source-linked assistant and administrator console.
- Flagged categories
- Synthetic replacements
- Tokenized values with a metadata-only admin view
How it works
The workflow
- InStart with
Prompt samples, document types, policy categories, browser and agent configurations
- 1
Confirm the buyer's problem and scope
- 2
Collect prompt samples
- 3
Document types
- 4
Policy categories
- 5
Browser and agent configurations
- 6
Then follow this sequence: 1
- OutFinish with
Flagged categories, synthetic replacements and tokenized values with a metadata-only admin view
AI does the heavy lifting, people stay in charge
Use AI to interpret permitted inputs, suggest structured mappings and generate candidate outputs for the stated scanning, replacement and tokenization modules. Use deterministic code for pattern matching, schema validation, hard constraints and reproducible tests. Review source-linked explanations and uncertainty before accepting results. Browser-local processing and a secure vault; final policy decisions and incident classification remain with security reviewers. A model suggestion is never a verified fact, professional decision or authorization to act.
What your team sees
Primary screens: Policy and category setup, Live prompt and document review, Admin exposure dashboard. Use a list of monitored sessions, a central review panel showing flagged categories and synthetic replacements, and a right-hand panel for policy rules, token vault status and audit events. Let reviewers compare original and synthetic context side by side where permitted. Display allowed, flagged, blocked and revealed states. Provide a metadata-only admin view with no raw content. Make the task-specific outcome flagged categories, synthetic replacements and tokenized values visible beside its evidence, review state and value baseline.
Accounts and administration
Policy ownership, category lists, user and group access, token vault status, reveal permissions, audit event retention, flagged-item review states, export logs and a rights record for supplied material. Add organization access boundaries, named reviewers, usage caps, data retention controls and explicit approval for external actions.
Integrations and data access
Employee browsers, existing agent frameworks, identity providers and permitted AI tool endpoints. Cloud policy storage, audit log export and security information and event management destinations. Start with file exchange and validate destination specifications before promising direct enforcement. Start with authorized file exchange. Validate current provider access, usage rights and schema behavior before promising a connector.
How we build it
We build with our own AI software development factory, so most implementations take days to a few weeks of creation time, not months. You see working software at every step, and exact timing depends on availability.
- 1
Scoping call
Day 1Thirty minutes on your process, your data and how you want to run it: for your own team, or for your clients. You get a fixed scope and price for the MVP.
- 2
MVP
4 daysOne buyer segment, one recurring use case; first modules: scan prompts in real time for API keys, credentials and personal data; scan uploaded contracts, spreadsheets and files before submission. Manual review in the loop. Built by our AI software factory.
- 3
Paid pilot
5 daysAccounts, roles, review states, audit trail and the first integration, hardened for two to three paying pilot customers.
- 4
Full product
10 daysSelf-serve onboarding, billing, monitoring and the wider integration set.
- 5
Run and improve
MonthlyWe host, monitor and improve it for a fixed monthly fee, or hand it over to your team. How the retainer works.
Why we start with an MVP
An MVP, or minimum viable product, is the smallest version that your users can actually work with. It is not a cheap version of the full solution. It is a test, built to answer the questions that decide whether the rest is worth building.
- Pick the riskiest assumption. Here: will security, IT and compliance teams in regulated organizations whose employees send prompts and documents to third-party AI tools use it to solve "employees paste credentials, personal data and confidential documents into external AI tools, and administrators cannot see what leaves the organization"?
- Build only what tests it. One team, one use case, a few core modules. People do the rest by hand for now.
- Run a paid pilot. Agree quality and outcome thresholds before the pilot using this measure: Flagged items per reviewed session and confirmed exposure incidents.
- Measure, then decide. Track flagged items per reviewed session and confirmed exposure incidents; accepted-output rate; material error rate; reviewer correction time; actual repeat purchase. Then expand, change course or stop, with evidence instead of opinions.
MVP scope for this solution. Pilot scope: One browser, one agent framework and one policy category set; final policy decisions and incident classification remain with security reviewers. Implement one approved input format, a bounded representative case set and the first two task modules: scan prompts in real time for API keys, credentials and personal data; scan uploaded contracts, spreadsheets and files before submission. Support the remaining modules with operator review: replace sensitive values with synthetic equivalents; tokenize PHI, PCI and PII before prompts reach the model. Include source references, corrections, basic organization access, approval states, export and value measurement. Use managed operator assistance for unresolved exceptions. The cost estimate covers this narrow prototype, not unrestricted multi-tenant scale, complex production integrations, specialist certification or physical operations.
After the MVP. Once paid pilots prove usefulness, automate repeatable reviewed steps and add one verified source integration. Expand supported browsers, agent frameworks and policy categories only after new evaluation cases pass. Build reusable customer configurations and recurring value reports around flagged categories, synthetic replacements and tokenized values. Retain the explicit scope boundary: One browser, one agent framework and one policy category set; final policy decisions and incident classification remain with security reviewers.
What the build depends on. Browser extension deployment, asynchronous scanning jobs, editable policy history, reviewer access and tested export formats. High-fidelity enforcement requires specialist security QA. Obtain representative authorized cases, baseline measurements, qualified reviewers and a buyer-side decision owner. Specific limitation: One browser, one agent framework and one policy category set; final policy decisions and incident classification remain with security reviewers.
Investment
A planning range to start the conversation, not a quote. You pay per phase, so you can stop after the MVP.
- Phase 1
MVP
One buyer segment, one recurring use case; first modules: scan prompts in real time for API keys, credentials and personal data; scan uploaded contracts, spreadsheets and files before submission. Manual review in the loop.
- Phase 2
Paid pilot
Accounts, roles, review states, audit trail and the first integration, hardened for two to three paying pilot customers.
- Phase 3
Full product
Self-serve onboarding, billing, monitoring and the wider integration set.
Indicative total, MVP to full product$41,000about 4 weeks of creation time · start with the MVP from $12,000
Running costs per month
A rough indication of monthly hosting and AI model costs once it is live, not tested. Real costs depend on usage, file sizes and the models chosen.
| Stage | Hosting and infrastructure | AI usage | Total per month |
|---|---|---|---|
| MVP and paid pilotabout 3 customers | $30–$60 | $60–$120 | $90–$180 |
| Full productabout 50 customers | $110–$210 | $530–$1,050 | $640–$1,260 |
Run it or resell it
For your own team
Security, IT and compliance teams in regulated organizations whose employees send prompts and documents to third-party AI tools run it inside the business: prompt samples, document types, policy categories, browser and agent configurations in, flagged categories, synthetic replacements and tokenized values with a metadata-only admin view out, reviewed by your people.
As part of your offer
Agencies, consultancies and software companies can offer it to their own clients under their brand. We build and maintain it; you sell and deliver it.
Your brand, or this one
Run it under your own brand, or start from this concept style.
- primary
#278c91 - accent
#c9546e - surface
#e4f0f1 - ink
#22201e
- Headings
- Manrope
- Text
- Manrope
- Voice
- Technical, direct, no hype
Selling it to your own clients: the go-to-market playbook
Pricing to test
Test a USD 300-1,500 fixed pilot for one defined browser and policy package. Offer a monthly production allowance after repeat demand. Quote complex agent framework or vault integrations separately. These are test prices, not market benchmarks. Package the initial sale as one bounded flagged categories, synthetic replacements and tokenized values record. Recurring fees must specify volume, review depth and integration support. For exchanges, test a disclosed coordination or successful-service fee rather than holding customer funds. Reprice only after measuring real delivery labor; platform-build cost is separate from a commercial pilot fee.
Message to test
Reduce sensitive data exposure in employee AI use while keeping the tools employees already use. Demonstrate a concrete flagged categories, synthetic replacements and tokenized values record using the buyer's approved example and show the baseline, corrections and actual delivery effort.
Where to find buyers
Security, IT and compliance teams in regulated organizations professional communities; specialist consultants serving this buyer; permissioned partner introductions; practical demonstrations at relevant trade or practitioner events.
Lead magnet
A reviewed sample flagged categories, synthetic replacements and tokenized values record from a small authorized input set, with a transparent calculation of flagged items per reviewed session and confirmed exposure incidents and no promised savings.
The first 30 days
- Week 1: interview five security, IT and compliance teams in regulated organizations and inspect a recent example of employees paste credentials, personal data and confidential documents into external AI tools.
- Week 2: prepare a consented or synthetic demonstration of the three task modules.
- Week 3: seek one bounded paid pilot with agreed baseline and acceptance criteria.
- Week 4: measure flagged items per reviewed session and confirmed exposure incidents, reviewer effort and repeat-purchase interest. This is a demand-validation plan, not a thirty-day full-product delivery promise.
Paid pilot
Agree quality and outcome thresholds before the pilot using this measure: Flagged items per reviewed session and confirmed exposure incidents. Continue only if the buyer accepts the actual output, the intended job outcome improves without unacceptable errors, and measured delivery cost fits willingness to pay. Revise or stop if access is unavailable, qualified review cannot be provided, or apparent savings disappear after corrections and support. Use held-out cases when comparing model quality; use a properly reviewed comparison design before making causal claims. Record missing cases and negative results alongside successful outputs.
Success metrics
Flagged items per reviewed session and confirmed exposure incidents; accepted-output rate; material error rate; reviewer correction time; actual repeat purchase.
Retention and expansion
Repeat the workflow when the buyer again needs flagged categories, synthetic replacements and tokenized values. Retain permissioned settings and reviewed examples, report realized value honestly, and sell increased volume or adjacent approved workflows only after contribution margin and quality remain acceptable.
Why clients would pick it
A reusable library of approved policy categories, replacement rules and review examples, together with reliable delivery for a narrow security niche. Build a permissioned library of representative task cases, reviewer corrections and verified operating constraints for security, IT and compliance teams in regulated organizations. Repeatable delivery and useful integrations matter more than access to a base model.
Alternatives and positioning
Sequirly, PrivacyPal and Astra. Compare this product with the buyer's present method on flagged items per reviewed session and confirmed exposure incidents. Offer a bounded paid workflow instead of claiming broad autonomous expertise. Market uniqueness and competitor coverage are not verified.
Main delivery costs
Scanning and replacement attempts, browser processing, vault storage, reviewer hours, client revision rounds and licensed source assets. Additional initial validation requires representative authorized sample preparation, buyer interviews, buyer-side evaluation and bounded validation of flagged categories, synthetic replacements and tokenized values. Track cost per accepted output, including correction work, unsuccessful cases and support.
Safeguards
Preserve employee privacy, source attribution, data classification accuracy and usage permissions. Security reviewers approve policy changes and incident scope. One browser, one agent framework and one policy category set; final policy decisions and incident classification remain with security reviewers. Keep all consequential actions under authorized human control and do not fabricate missing inputs, permissions, professional judgments or market evidence.