PII protection for every AI
Stop your team leaking
into AI.
Personal data in your team's prompts and documents becomes tokens like [EMAIL_1] before it reaches any AI, then it's restored in the reply. The model never sees raw data. Neither do we.
No card · 7-day free trial · nothing sensitive ever stored
Works everywhere
One shield. Every AI.
Every major model and chat tool, through one engine.
Six ways in
Switch it on in minutes.
Pick your model, copy the config, you're protected. The same redaction engine sits behind every route.
One base-URL change
Point any app, SDK or OpenAI-compatible CLI at the shield with your own provider key. It redacts, forwards to Claude, and restores the reply. BYOK or fully managed. Claude Code uses the plugin instead - card 06.
Paste one key
Paste your workspace key into the popup once - no gateway or provider setup - and the shield works right inside the AI you already use.
- Masks what you type in the chat box before you hit send, and restores the real reply in place
- Redacts whole documents before you upload them
- Works across Claude, ChatGPT, Gemini, Grok, DeepSeek, Copilot and more
One command
Add the shield to Claude as a connector. Any agent gets redact, detect_pii + coverage tools, on demand from chat. Tools you call - use the gateway or the plugin to redact automatically.
Files, format-preserving
Drop in a document - the shield strips PII and hands back the same file, layout intact. Scanned pages and images are read with OCR.
Your own systems, nothing to install
Everything above needs a config file on somebody's machine. This does not. Add your ATS, CRM or helpdesk in your dashboard and we hand you one web address to paste into Claude's Connectors screen. Claude talks to the shield; the shield talks to your system - so the records that come back are already [PERSON_1], and a token Claude sends back becomes the real value again on the way out, so lookups still work.
- Connect several systems and they arrive through one address, sharing one set of tokens - the same person is the same token everywhere
- Sign in with OAuth where the vendor supports it, so there is no key to go hunting for
- Works in claude.ai in the browser and in the desktop app. No developer, no config file
Local hooks, no key in flight
Claude Code must not go through the gateway - on a subscription it would send your claude.ai account token to it. The plugin redacts tool output on your machine before Claude sees it, and restores the real values before Claude writes to disk. Prompts and @-mentions containing PII are blocked, because Claude Code does not let a hook rewrite a prompt.
claude plugin marketplace add aerynquarmby/pii-shield-plugin
claude plugin install pii-shield@piishieldSee what's already leaked.
Leak Audit looks backwards - showing management exactly what personal data employees have already pasted into AI, per seat - encrypted to a key only your workspace holds. Then a daily monitor keeps watch automatically.
- Per-seat breakdown - who leaked what, and how often, by PII type.
- Encrypted per-tenant - values are sealed with AES-256-GCM; optional tenant-held end-to-end keys mean even PII Shield can't read them.
- Reveal is owner/admin-only and every reveal is written to an audit log.
- Automatic daily scan - Enterprise uses Anthropic's Compliance API; every plan can use the extension's history scan.
Zero-trust by design
We never see your data.
A shield nobody on the outside can see through - including us. Self-host it in your own cloud and we have zero operator access at all.
- Your prompts, messages or documents
- Raw personal data we could read - names, emails, IDs, cards, IBANs, IPs (Leak Audit keeps only ciphertext sealed to your key)
- The token↔value map (in memory for the request, then gone, unless you switch on restoring redacted documents - then it is sealed to your key and we still cannot read it)
- Counts of PII masked, by type - logs are counts-only
- Timestamp, model, status - for usage & billing
- Encrypted at rest with AES-256-GCM; self-host for full isolation
Built for organisations
One shield, every level.
From the whole platform down to a single seat - everyone sees exactly what they should, and nothing they shouldn't.
Cross-tenant health
The platform view: fleet-wide status and usage across every company - counts only, never a byte of PII.
Your own dashboard
Each company is an isolated tenant with its own seats, coverage rules, custom terms, billing and Leak Audit.
Scoped view
Every seat gets its own key and a view scoped to just their own activity - protected the moment they start typing.
Simple pricing
A fraction of your AI bill.
Pick a term and your seats - see exactly what you'll pay. Longer commitments save more. You keep your own model billing; you only pay for the shield.
Every surface is on every plan — gateway, extension, MCP, connectors, documents and the CLI plugin. A plan buys requests and how many of your own systems you can connect, not features.
Prefer usage-based? ~$0.90 per 1,000 requests.
Ready in a day
Give your team AI
without giving away your data.
Create a free workspace, get your key, and shield every AI your team touches.
Start free →