Our engineers set up and run your first chatbot / LLM security scan. Get in touch

Stop sensitive data before it reaches AI

Penaxtra AI Guardrail scans your prompts and file attachments on your own device and holds back secrets, API keys, payment cards and personal data before they reach ChatGPT, Claude, Gemini and 150+ AI tools. Nothing is sent to us.

What it catches

A maintained detection library plus your own rules, applied the moment you send a prompt or attach a file.

Secrets and API keys

Cloud provider keys, tokens, database connection strings and private keys are caught before they land in a chat box. Unknown formats are flagged by entropy.

AWS, GCP, AzureGitHub, GitLabSlack, Stripe

Payment cards and personal data

Payment card numbers, national IDs, IBANs and phone numbers are validated with checksums to keep false positives low, then blocked or flagged by your policy.

Card numbersNational IDsIBAN and phone

Prompt injection and hidden text

Invisible unicode and hidden instructions that try to hijack an AI response are surfaced so you can review before you send.

Invisible charactersHidden intent

Files, not just prompts

PDF, Word, Excel and text attachments are read on your device and checked before they upload. Scanned-image files without a text layer cannot be read.

PDF and OfficeChecked before upload

How it works

The extension watches the send path on each AI site. When you press send or attach a file, it scans the content locally and steps in before anything leaves the page.

Block

Shows a warning with the findings and lets you send anyway if it is a false positive.

Hard block

Stops the message outright with no override. The right setting for high-risk data.

Warn

Never blocks. Shows a quiet notice so you stay aware without interruption.

Private by design

Detection runs entirely in your browser. Penaxtra never receives your prompt content or your files. Rule updates are delivered as signed data, not remote code, and anonymous usage metrics are off unless you turn them on.

For teams

Roll it out across your organisation with GPO or MDM, publish your own rule packs, enforce a policy fleet wide, and see which installs are protected. Enterprise deployment is available at [email protected].

Frequently asked questions

Does the extension send my prompts anywhere?

No. All scanning happens on your device. Your prompt text and file contents are never transmitted to Penaxtra or anyone else. Optional, aggregate usage counts are shared only if you turn them on.

Which AI sites does it protect?

ChatGPT, Claude, Gemini, Copilot, Perplexity and 150+ other AI chat, search, coding and productivity tools. Administrators can add their own internal AI sites.

What does it detect?

API keys and cloud credentials, payment card numbers, national IDs and other personal data, database connection strings, and hidden prompt-injection text. It scans typed prompts and attached PDF, Office and text files.

Can it catch everything?

It is a strong, best-effort control, not a guarantee. Detection can be incomplete, and some file types or upload paths may not be fully covered. You remain responsible for what you choose to share. See the extension privacy notice for details.

Is it free?

Yes. The extension is free for individuals. Teams can add centrally managed deployment, organisation rule packs and fleet reporting.

Add the guardrail to your browser

Free for Chrome and Firefox. Protection starts the moment it is installed.